Logistiex Fulfillment Security & Risk Analysis

wordpress.org/plugins/logistiex-fulfillment

Short Description: A powerful plugin offering seamless end-to-end fulfillment services. Description: We provide a technology-backed integration with a …

0 active installs v2.0.0 PHP 7.4+ WP 6.4+ Updated Mar 2, 2026
fulfillmentlogisticswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Logistiex Fulfillment Safe to Use in 2026?

Generally Safe

Score 100/100

Logistiex Fulfillment has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin "logistiex-fulfillment" v2.0.0 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any known CVEs and the clean taint analysis indicate a diligent approach to secure coding practices. The code analysis reveals that all SQL queries are properly prepared, and all output is correctly escaped, which are crucial for preventing common web vulnerabilities like SQL injection and cross-site scripting (XSS). The lack of file operations and absence of dangerous functions further contribute to a secure baseline.

However, there are areas that warrant attention. The presence of 0 nonce checks and 0 capability checks across all entry points (AJAX, REST API, shortcodes) is a significant concern. While the static analysis reports 0 unprotected entry points, the absence of these fundamental WordPress security mechanisms means that even if authenticated users access these features, their actions might not be properly authorized or protected against CSRF attacks. The 4 external HTTP requests also present a potential vector for vulnerabilities if not handled with extreme care, although their nature is not specified.

In conclusion, while the plugin benefits from a clean vulnerability history and good practices in SQL and output handling, the complete lack of nonce and capability checks on its entry points represents a notable weakness. This oversight could expose the plugin to security risks that are not immediately apparent from the absence of known CVEs or critical taint flows. Therefore, while the overall picture is positive, addressing the missing authorization and nonce checks is highly recommended.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
Vulnerabilities
None known

Logistiex Fulfillment Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Logistiex Fulfillment Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
18 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

100% escaped18 total outputs
Attack Surface

Logistiex Fulfillment Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_enqueue_scriptsfrontend\index.php:33
actionwoocommerce_new_orderlogistiex-fulfillment.php:46
actionwoocommerce_update_orderlogistiex-fulfillment.php:50
actionlogistiex_fulfillment_send_debounced_order_to_webhooklogistiex-fulfillment.php:53
actionsave_post_productlogistiex-fulfillment.php:56
actionadmin_menulogistiex-fulfillment.php:59
actionwoocommerce_order_details_after_order_tablelogistiex-fulfillment.php:62
actionwp_enqueue_scriptstrackingPage\index.php:27

Scheduled Events 1

logistiex_fulfillment_send_debounced_order_to_webhook
Maintenance & Trust

Logistiex Fulfillment Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMar 2, 2026
PHP min version7.4
Downloads912

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Logistiex Fulfillment Developer Profile

Noetic LogistieX

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Logistiex Fulfillment

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/logistiex-fulfillment/styles.css/wp-content/plugins/logistiex-fulfillment/script.js/wp-content/plugins/logistiex-fulfillment/assets/WhiteFontLogistiex.png
Script Paths
/wp-content/plugins/logistiex-fulfillment/script.js
Version Parameters
logistiex-fulfillment/styles.css?ver=2.0.0logistiex-fulfillment/script.js?ver=2.0.0

HTML / DOM Fingerprints

CSS Classes
loader
Data Attributes
id="homeDiv"id="loaderDiv"id="heading"id="startedButton"id="defaultIcon"id="settingIcon"
JS Globals
var storeUrl
FAQ

Frequently Asked Questions about Logistiex Fulfillment