
Moovin Delivery Security & Risk Analysis
wordpress.org/plugins/moovin-deliveryPlugin para entregas de paquetes con Moovin Costa Rica en Woocommerce.
Is Moovin Delivery Safe to Use in 2026?
Generally Safe
Score 92/100Moovin Delivery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "moovin-delivery" v1.0.24 plugin exhibits a significant security posture concern due to its extensive unprotected entry points. All 13 identified AJAX handlers lack authentication checks, creating a wide attack surface where unauthenticated users could potentially interact with sensitive plugin functionality. Furthermore, the taint analysis revealed two high-severity flows with unsanitized paths, indicating a potential for attackers to exploit these vulnerabilities if they can trigger them. While the plugin shows good practices in using prepared statements for SQL queries (69%) and proper output escaping (78%), these strengths are overshadowed by the critical absence of authorization on its primary interaction mechanisms.
The vulnerability history for "moovin-delivery" is clean, with no recorded CVEs. This suggests that while it may have been subject to less scrutiny or has not yet been found to have exploitable public vulnerabilities, the static analysis findings are critical and should be addressed immediately. The lack of nonce and capability checks on AJAX actions is a direct invitation for common WordPress vulnerabilities like Cross-Site Request Forgery (CSRF) and unauthorized data manipulation. The presence of bundled libraries like DataTables and Select2, without specific version information, also introduces a potential risk if these libraries are outdated and contain known vulnerabilities.
In conclusion, the "moovin-delivery" plugin has some positive aspects regarding database and output handling. However, the core security design is fundamentally flawed by the lack of authentication on its AJAX endpoints and the identified high-severity taint flows. These issues present a clear and present danger to WordPress sites using this plugin, and immediate remediation is strongly advised to prevent potential security breaches.
Key Concerns
- 13 unprotected AJAX handlers
- 2 high severity taint flows
- 0 nonce checks on AJAX
- 0 capability checks
- Bundled libraries (potential risk)
Moovin Delivery Security Vulnerabilities
Moovin Delivery Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Moovin Delivery Attack Surface
AJAX Handlers 13
WordPress Hooks 33
Scheduled Events 3
Maintenance & Trust
Moovin Delivery Maintenance & Trust
Maintenance Signals
Community Trust
Moovin Delivery Alternatives
Envíos Coordinadora Woocommerce (Oficial) – WordPress plugin
coordinadora
Con nuestro plugin para envíos crea guías, imprime etiquetas y sigue tus envíos. Gratis para clientes con acuerdo comercial vigente con Coordinadora.
eCommerce Shipping Dashboard by UPS for WooCommerce
ecommerce-shipping-dashboard-by-ups-for-woocommerce
Connect your WooCommerce Store to all the UPS Services you require and manage your orders, shipments and labels in your Shipping Dashboard.
Bob Go smart shipping solution for WooCommerce
uafrica-shipping
Smart shipping and order management solution in South Africa
QCode – Departamentos y Ciudades de Colombia para Woocommerce
wc-departamentos-y-ciudades-colombia
Plugin para mostrar el campo departamento y ciudad como listas de selección. Compatible con el plugin de Coordinadora.
g-FFL Cockpit
g-ffl-cockpit
Built by a FFL, for FFL's. Automate inventory synchronization and order fulfillment with multiple distributors.
Moovin Delivery Developer Profile
1 plugin · 10 total installs
How We Detect Moovin Delivery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/moovin-delivery/admin/js/moovin-delivery-admin.js/wp-content/plugins/moovin-delivery/admin/css/moovin-delivery-admin.css/wp-content/plugins/moovin-delivery/public/css/moovin-delivery-public.css/wp-content/plugins/moovin-delivery/public/js/moovin-delivery-public.js/wp-content/plugins/moovin-delivery/admin/js/moovin-delivery-admin.js/wp-content/plugins/moovin-delivery/public/js/moovin-delivery-public.jsmoovin-delivery/admin/js/moovin-delivery-admin.js?ver=moovin-delivery/admin/css/moovin-delivery-admin.css?ver=moovin-delivery/public/css/moovin-delivery-public.css?ver=moovin-delivery/public/js/moovin-delivery-public.js?ver=HTML / DOM Fingerprints
moovin-delivery-admin-configdata-moovin-id