Kitgenix Order Tracking for WooCommerce Security & Risk Analysis

wordpress.org/plugins/kitgenix-order-tracking-for-woocommerce

Add multi-shipment tracking to WooCommerce orders, show tracking in customer emails, and provide a public “Track Your Order” page.

10 active installs v1.0.5 PHP 8.1+ WP 6.0+ Updated Feb 19, 2026
emailsshipmentsshippingtrackingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Kitgenix Order Tracking for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Kitgenix Order Tracking for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin "kitgenix-order-tracking-for-woocommerce" v1.0.5 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, the use of prepared statements for all SQL queries, and a significant percentage of properly escaped output are all positive indicators. Furthermore, the presence of nonce and capability checks, alongside the lack of external HTTP requests and file operations, suggests a developer mindful of common security pitfalls. The zero known CVEs and no recorded vulnerabilities in its history are also very encouraging, implying a history of secure development and diligent maintenance.

However, there are minor areas for attention. While the total number of entry points is low and none are reported as unprotected, a deeper dive into the single AJAX handler and the shortcode's implementation would be beneficial to ensure absolute certainty regarding authorization and input sanitization. The 79% proper output escaping, while good, indicates that roughly 21% of outputs might be vulnerable to cross-site scripting (XSS) if the data originates from untrusted sources. This is the most tangible risk identified within the code analysis. Overall, the plugin appears to be well-secured, with potential for minor improvements rather than critical vulnerabilities.

Key Concerns

  • Potentially unescaped output (21%)
Vulnerabilities
None known

Kitgenix Order Tracking for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Kitgenix Order Tracking for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
70
260 escaped
Nonce Checks
4
Capability Checks
9
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

79% escaped330 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
<Analytics> (includes\Admin\Analytics.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Kitgenix Order Tracking for WooCommerce Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_kitgenix_order_tracking_for_woocommerce_get_order_itemsincludes\Admin\Order_Meta_Box.php:28

Shortcodes 1

[kitgenix_tracking_form] includes\Frontend\Shortcodes.php:47
WordPress Hooks 20
actionadmin_menuincludes\Admin\Analytics.php:51
actionadmin_enqueue_scriptsincludes\Admin\Analytics.php:52
actionadd_meta_boxesincludes\Admin\Order_Meta_Box.php:19
actionwoocommerce_process_shop_order_metaincludes\Admin\Order_Meta_Box.php:22
actionadmin_enqueue_scriptsincludes\Admin\Order_Meta_Box.php:24
actionadmin_footerincludes\Admin\Order_Meta_Box.php:25
actionwoocommerce_email_after_order_tableincludes\Emails\Email_Hooks.php:26
actionwoocommerce_email_before_order_tableincludes\Emails\Email_Hooks.php:35
actionwoocommerce_order_status_partially-shippedincludes\Emails\Email_Hooks.php:42
actionwp_enqueue_scriptsincludes\Frontend\Shortcodes.php:48
actionbefore_woocommerce_initincludes\Plugin.php:30
actioninitincludes\Plugin.php:55
filterwc_order_statusesincludes\Plugin.php:56
filterwoocommerce_email_classesincludes\Plugin.php:57
actionadmin_headkitgenix-order-tracking-for-woocommerce.php:92
actionadmin_menukitgenix-order-tracking-for-woocommerce.php:110
actionadmin_enqueue_scriptskitgenix-order-tracking-for-woocommerce.php:475
actionadmin_initkitgenix-order-tracking-for-woocommerce.php:493
actionbefore_woocommerce_initkitgenix-order-tracking-for-woocommerce.php:546
actionplugins_loadedkitgenix-order-tracking-for-woocommerce.php:559
Maintenance & Trust

Kitgenix Order Tracking for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 19, 2026
PHP min version8.1
Downloads391

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Kitgenix Order Tracking for WooCommerce Developer Profile

Kitgenix

5 plugins · 310 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Kitgenix Order Tracking for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kitgenix-order-tracking-for-woocommerce/assets/css/styles.css/wp-content/plugins/kitgenix-order-tracking-for-woocommerce/assets/js/frontend.js
Script Paths
/wp-content/plugins/kitgenix-order-tracking-for-woocommerce/assets/js/frontend.js
Version Parameters
kitgenix-order-tracking-for-woocommerce/assets/css/styles.css?ver=kitgenix-order-tracking-for-woocommerce/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
kitgenix-order-tracking-container
Data Attributes
data-kitgenix-order-tracking
JS Globals
window.KitgenixOrderTrackingConfig
FAQ

Frequently Asked Questions about Kitgenix Order Tracking for WooCommerce