
IBIZA Express Delivery Integration Security & Risk Analysis
wordpress.org/plugins/ibiza-express-delivery-integrationAutomate e-commerce orders with official IBIZA platform for WooCommerce. Send your order to IBIZA system and syc your package statuses.
Is IBIZA Express Delivery Integration Safe to Use in 2026?
Generally Safe
Score 92/100IBIZA Express Delivery Integration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ibiza-express-delivery-integration" v1.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by having a small attack surface and a single AJAX handler which appears to have a nonce check, although capability checks are absent. The plugin also avoids dangerous functions, file operations, and the inclusion of bundled libraries. SQL queries show a reasonable effort towards prepared statements, and a majority of output is properly escaped.
However, concerns arise from the taint analysis, which identified one flow with an unsanitized path at a high severity. This is a significant concern as it suggests a potential for attackers to inject malicious data that is not properly handled, potentially leading to various vulnerabilities depending on how this unsanitized data is used. The absence of capability checks on the AJAX handler is also a weakness, as it means that any authenticated user, regardless of their role or permissions, could potentially interact with this handler, increasing the risk if the handler itself performs sensitive operations.
The plugin's vulnerability history is a notable strength, showing zero known CVEs. This indicates a lack of publicly disclosed security flaws, which is generally a positive sign. However, this should not be taken as a guarantee of complete security, especially given the high-severity taint flow identified in the static analysis. The overall conclusion is that while the plugin is not riddled with obvious vulnerabilities and has a clean history, the high-severity unsanitized path flow and lack of capability checks warrant careful attention and potential remediation.
Key Concerns
- High severity unsanitized path in taint analysis
- AJAX handler lacks capability checks
- SQL queries: 33% not using prepared statements
- Output escaping: 33% not properly escaped
IBIZA Express Delivery Integration Security Vulnerabilities
IBIZA Express Delivery Integration Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
IBIZA Express Delivery Integration Attack Surface
AJAX Handlers 1
WordPress Hooks 8
Maintenance & Trust
IBIZA Express Delivery Integration Maintenance & Trust
Maintenance Signals
Community Trust
IBIZA Express Delivery Integration Alternatives
Smart COD for WooCommerce
wc-smart-cod
All the COD restrictions and extra fees you'll ever need, in a single plugin.
Claudio Sanches – Correios for WooCommerce
woocommerce-correios
Integration between the Correios and WooCommerce
Print Invoice & Delivery Notes for WooCommerce
woocommerce-delivery-notes
Create and print PDF invoices, delivery notes and receipts for your WooCommerce orders. Choose your document format from multiple templates.
Order Delivery Date for WooCommerce
order-delivery-date-for-woocommerce
Let customers choose delivery dates & times on checkout. Simplify delivery management by blocking holidays & setting max deliveries per day.
Shiprocket
shiprocket
Auto Sync your Woocommerce store orders & ship them at lowest shipping rates. Automate your shipping, save time & money.
IBIZA Express Delivery Integration Developer Profile
1 plugin · 0 total installs
How We Detect IBIZA Express Delivery Integration
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ibiza-express-delivery-integration/assets/js/send-to-api.jsHTML / DOM Fingerprints
data-order-idclass="button send-to-api"ibiza_ajax_params