
Moova Security & Risk Analysis
wordpress.org/plugins/moova-for-woocommercePlugin to connect Moova's Shipping services with WooCommerce
Is Moova Safe to Use in 2026?
Generally Safe
Score 100/100Moova has a strong security track record. Known vulnerabilities have been patched promptly.
The moova-for-woocommerce plugin version 7.3 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and a high percentage of properly escaped output. The absence of dangerous functions and external HTTP requests is also commendable. However, a significant concern arises from the large attack surface, particularly the 6 AJAX handlers that lack authentication checks. This oversight presents a substantial risk of unauthorized access and potential manipulation of plugin functionalities. The presence of one known medium-severity Cross-site Scripting (XSS) vulnerability in its history, although currently patched, indicates a past weakness that warrants continued vigilance. While the plugin has no currently unpatched vulnerabilities and a low number of taint flows, the unprotected AJAX endpoints are a critical area that could be exploited to introduce new vulnerabilities.
Key Concerns
- 6 AJAX handlers without auth checks
- 1 medium severity vulnerability in history
Moova Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Moova for WooCommerce <= 3.5 - Reflected Cross-Site Scripting
Moova Code Analysis
Output Escaping
Data Flow Analysis
Moova Attack Surface
AJAX Handlers 6
Shortcodes 2
WordPress Hooks 27
Maintenance & Trust
Moova Maintenance & Trust
Maintenance Signals
Community Trust
Moova Alternatives
DrEnvio for WooCommerce
drenvio-for-woocommerce
Permite que tus clientes coticen por más de 10 paqueterías desde el checkout de tu tienda y con esto aumenta tu conversión.
Emissary for Woocommerce
emissary-for-woocommerce
El software esencial de logística para su negocio. Muestre costos de envío variables en función de la dirección de su tienda y la dirección del client …
Shiptastic for WooCommerce
shiptastic-for-woocommerce
Shiptastic for WooCommerce is your all-in-one shipping and fulfillment solution for WooCommerce.
SEUR Oficial
seur
Add SEUR shipping method to WooCommerce. The SEUR plugin for WooCommerce allows you to manage your order dispatches in a fast and easy way
SuperFrete
superfrete
Integração com a plataforma SuperFrete para WooCommerce.
Moova Developer Profile
1 plugin · 10 total installs
How We Detect Moova
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/moova-for-woocommerce/assets/css/settings.css/wp-content/plugins/moova-for-woocommerce/assets/css/rate.css/wp-content/plugins/moova-for-woocommerce/assets/js/orders.min.js/wp-content/plugins/moova-for-woocommerce/assets/js/settings.js/wp-content/plugins/moova-for-woocommerce/assets/js/rate.js/wp-content/plugins/moova-for-woocommerce/assets/css/settings.css/wp-content/plugins/moova-for-woocommerce/assets/css/rate.css/wp-content/plugins/moova-for-woocommerce/assets/js/orders.min.js/wp-content/plugins/moova-for-woocommerce/assets/js/settings.js/wp-content/plugins/moova-for-woocommerce/assets/js/rate.jsHTML / DOM Fingerprints
wc-moova-settings-csswc-moova-rate-csswc-moova-orders-jswc-moova-settings-jswc-moova-rating-js