
Local Delivery Drivers for WooCommerce Security & Risk Analysis
wordpress.org/plugins/local-delivery-drivers-for-woocommerceImprove the way you deliver, manage drivers, assign drivers to orders, send WhatsApp, SMS, and email notifications, route planning, navigation & more!
Is Local Delivery Drivers for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100Local Delivery Drivers for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "local-delivery-drivers-for-woocommerce" plugin exhibits a mixed security posture. While it generally demonstrates good practices such as a high percentage of prepared SQL statements and properly escaped output, significant concerns arise from its attack surface. The plugin exposes two AJAX handlers, both of which lack authentication checks, presenting a direct pathway for unauthorized actions. Furthermore, the taint analysis revealed one high-severity flow with unsanitized paths, indicating a potential for exploitable vulnerabilities if data from these unauthenticated AJAX endpoints is involved.
The vulnerability history shows one past high-severity CVE, specifically related to missing authorization. This, combined with the current unauthenticated AJAX endpoints, suggests a recurring pattern of authorization bypass issues. The presence of a bundled Freemius library also warrants attention, as outdated bundled libraries can introduce their own security risks.
In conclusion, despite good general coding practices in many areas, the plugin's unprotected AJAX endpoints and the history of authorization vulnerabilities create a notable risk. While there are no currently unpatched CVEs, the potential for immediate exploitation due to the exposed AJAX handlers and the past high-severity vulnerability related to authorization are significant weaknesses that require immediate attention.
Key Concerns
- AJAX handlers without auth checks
- High severity taint flow (unsanitized paths)
- Past high severity CVE (missing authorization)
- Bundled library (Freemius v1.0)
Local Delivery Drivers for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Local Delivery Drivers for WooCommerce <= 1.9.0 - Missing Authorization to Driver Account Takeover
Local Delivery Drivers for WooCommerce Release Timeline
Local Delivery Drivers for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Local Delivery Drivers for WooCommerce Attack Surface
AJAX Handlers 2
WordPress Hooks 39
Maintenance & Trust
Local Delivery Drivers for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Local Delivery Drivers for WooCommerce Alternatives
Woot
woot-ro
Unified shipping solution for WooCommerce. Integrates all popular couriers in Romania with real-time pricing and pickup point selection.
Uber Direct Integration
uber-direct-delivery-integration
Offer instant or scheduled delivery from your WooCommerce store with real-time quotes and Uber Direct integration
NCM API
ncm-api
Connect WooCommerce orders with Nepal Can Move and manage delivery operations directly from WordPress.
UDW Delivery – Uber Direct for WooCommerce
udwdelivery
Delivery service for WooCommerce integrating with Uber Direct API.
Delivery Drivers Manager
delivery-drivers-manager
Let your staff or third-party logistics companies manage your delivery drivers with a front-hand mobile-friendly dashboard.
Local Delivery Drivers for WooCommerce Developer Profile
8 plugins · 3K total installs
How We Detect Local Delivery Drivers for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/local-delivery-drivers-for-woocommerce/assets/css/lddfw-admin.css/wp-content/plugins/local-delivery-drivers-for-woocommerce/assets/css/lddfw-style.css/wp-content/plugins/local-delivery-drivers-for-woocommerce/assets/js/lddfw-admin.js/wp-content/plugins/local-delivery-drivers-for-woocommerce/assets/js/lddfw-script.js/wp-content/plugins/local-delivery-drivers-for-woocommerce/freemius/start.phplocal-delivery-drivers-for-woocommerce/assets/css/lddfw-admin.css?ver=local-delivery-drivers-for-woocommerce/assets/css/lddfw-style.css?ver=local-delivery-drivers-for-woocommerce/assets/js/lddfw-admin.js?ver=local-delivery-drivers-for-woocommerce/assets/js/lddfw-script.js?ver=HTML / DOM Fingerprints
lddfw_premium-featurelddfw_premium-feature-contentlddfw_titlepremium_feature_titlelddfw_content-subtitlelddfw_lightboxlddfw_lightbox_wraplddfw_lightbox_close+2 moreCurrently plugin version.Start at version 1.0.0 and use SemVer - https://semver.orgDefine delivery driver page id.Define plugin folder name.+12 moredata-icon="star"data-prefix="fas"lddfw_fs