
Wanderlust HOP Envios Security & Risk Analysis
wordpress.org/plugins/integrar-hop-con-wooCon este plugin vas a poder obtener costos de envio para WooCommerce utilizando la API publica de HOP Envios.
Is Wanderlust HOP Envios Safe to Use in 2026?
Generally Safe
Score 100/100Wanderlust HOP Envios has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'integrar-hop-con-woo' v2.0.4 exhibits a concerning security posture primarily due to a significant number of unprotected entry points. All 14 identified AJAX handlers lack authentication checks, presenting a wide attack surface where any authenticated user, regardless of role, could potentially trigger malicious actions. While the code signals do not show direct dangerous functions or unsanitized path flows from taint analysis, the absence of capability checks and nonce verification on these AJAX handlers is a major weakness.
The plugin's SQL queries are handled securely with prepared statements, and there's a moderate level of output escaping. However, the 23 file operations and 7 external HTTP requests, without clear context on their handling, could represent indirect vectors if not properly validated. The lack of any recorded vulnerability history suggests a lack of past exploitation or discovery, which could be interpreted positively as a sign of stable code, or negatively as potentially undiscovered issues given the current significant security gaps.
In conclusion, while the plugin demonstrates good practices in database interaction and some output handling, the pervasive lack of authentication and authorization on its AJAX endpoints is a critical flaw. This significantly elevates the risk of unauthorized actions and potential privilege escalation. The absence of nonce checks on AJAX handlers further compounds this risk. The vulnerability history is a neutral factor at this point, but the identified code issues require immediate attention.
Key Concerns
- AJAX handlers without auth checks
- AJAX handlers without nonce checks
- AJAX handlers without capability checks
- Moderate output escaping issues
Wanderlust HOP Envios Security Vulnerabilities
Wanderlust HOP Envios Code Analysis
Output Escaping
Data Flow Analysis
Wanderlust HOP Envios Attack Surface
AJAX Handlers 14
WordPress Hooks 31
Scheduled Events 1
Maintenance & Trust
Wanderlust HOP Envios Maintenance & Trust
Maintenance Signals
Community Trust
Wanderlust HOP Envios Alternatives
Printful Integration for WooCommerce
printful-shipping-for-woocommerce
Grow your store with the top print-on-demand dropshipping plugin
WC Hide Shipping Methods
wc-hide-shipping-methods
This plugin automatically hides all other shipping methods when "Free Shipping" is available, while allowing you to retain "Local Picku …
USPS Simple Shipping for Woocommerce
woo-usps-simple-shipping
USPS Simple provides real-time USPS domestic rates.
Shipping Live Rates and Access Points for UPS for WooCommerce
flexible-shipping-ups
Provide auto-calculated UPS rates and Access Point options. Easy 5-minute setup. Show real prices and nearest pickup points at WooCommerce checkout.
Gelato Integration for WooCommerce
gelato-integration-for-woocommerce
Sell globally, print locally with 100+ production hubs in 32 countries
Wanderlust HOP Envios Developer Profile
6 plugins · 2K total installs
How We Detect Wanderlust HOP Envios
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/integrar-hop-con-woo/assets/css/admin.cssHTML / DOM Fingerprints
tracking_provider_fieldcustom_tracking_provider_fieldcustom_tracking_link_fieldid="tracking_provider"id="custom_tracking_provider"id="tracking_number"id="custom_tracking_link"id="date_shipped"wc_enqueue_js