
Inpost International Security & Risk Analysis
wordpress.org/plugins/inpost-internationalInPost International is the official free InPost app for international delivery services.
Is Inpost International Safe to Use in 2026?
Generally Safe
Score 100/100Inpost International has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'inpost-international' plugin v1.0.9 demonstrates a generally good security posture with several strengths. Notably, it utilizes prepared statements for all its SQL queries, a critical security best practice that significantly mitigates SQL injection risks. Furthermore, the vast majority of its output is properly escaped, reducing the likelihood of cross-site scripting (XSS) vulnerabilities. The plugin has no recorded historical vulnerabilities, which is a positive indicator of its development team's attention to security.
However, there are a few areas that warrant attention. The presence of an AJAX handler without authentication checks represents a direct entry point that could potentially be exploited by unauthenticated users. While taint analysis found no critical or high severity issues, the existence of four flows with unsanitized paths suggests a potential for indirect vulnerabilities if input from these flows is not carefully handled later in the execution chain. The plugin also makes external HTTP requests, which can be a vector for various attacks if not properly secured and validated.
In conclusion, while the 'inpost-international' plugin benefits from strong SQL and output sanitization practices and a clean vulnerability history, the unprotected AJAX endpoint and the presence of unsanitized paths are notable weaknesses. Addressing these specific concerns would further solidify the plugin's security.
Key Concerns
- Unprotected AJAX handler
- Flows with unsanitized paths
- External HTTP requests
Inpost International Security Vulnerabilities
Inpost International Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Inpost International Attack Surface
AJAX Handlers 5
Shortcodes 1
WordPress Hooks 37
Maintenance & Trust
Inpost International Maintenance & Trust
Maintenance Signals
Community Trust
Inpost International Alternatives
InPost PL
inpost-for-woocommerce
InPost PL dla WooCommerce to dedykowana wtyczka do integracji, stworzona z myślą o małych i średnich firmach, które chcą w szybki i wygodny sposób zin …
MyParcel
woocommerce-myparcel
Export your WooCommerce orders to MyParcel (www.myparcel.nl) and print labels directly from the WooCommerce admin
Inpost Paczkomaty
inpost-paczkomaty
Umożliwia dodanie Paczkomaty Inpost jako forma dostawy produktów. Zawiera mapkę gdzie można wybrać paczkomat w którym chce się odebrać przesyłkę.
TrackShip for WooCommerce
trackship-for-woocommerce
TrackShip auto-tracks orders, adds a branded tracking experience to your store and handles all customer touchpoints from shipping to delivery
Apaczka: integracja z WooCommerce
apaczka-pl
Zarządzaj wysyłkami różnych kurierów w jednym miejscu
Inpost International Developer Profile
2 plugins · 300 total installs
How We Detect Inpost International
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/inpost-international/build/inpost-frontend.css/wp-content/plugins/inpost-international/build/inpost-frontend.js/wp-content/plugins/inpost-international/build/inpost-backend.css/wp-content/plugins/inpost-international/build/inpost-backend.js/wp-content/plugins/inpost-international/build/inpost-frontend.js/wp-content/plugins/inpost-international/build/inpost-backend.jsinpost-international/build/inpost-frontend.css?ver=inpost-international/build/inpost-frontend.js?ver=inpost-international/build/inpost-backend.css?ver=inpost-international/build/inpost-backend.js?ver=HTML / DOM Fingerprints
inpost-locker-finder-wrapperinpost-locker-finderinpost-locker-finder-iframedata-inpost-map-settingsdata-inpost-api-endpointinpost_intl_maps/wp-json/inpost-international/v1/maps/settings