Moovin Delivery Security & Risk Analysis

wordpress.org/plugins/moovin-delivery

Plugin para entregas de paquetes con Moovin Costa Rica en Woocommerce.

10 active installs v1.0.24 PHP 5.6+ WP 4.9+ Updated Aug 29, 2024
entregasenviosfulfillmentmoovinrecolecciones
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Moovin Delivery Safe to Use in 2026?

Generally Safe

Score 92/100

Moovin Delivery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "moovin-delivery" v1.0.24 plugin exhibits a significant security posture concern due to its extensive unprotected entry points. All 13 identified AJAX handlers lack authentication checks, creating a wide attack surface where unauthenticated users could potentially interact with sensitive plugin functionality. Furthermore, the taint analysis revealed two high-severity flows with unsanitized paths, indicating a potential for attackers to exploit these vulnerabilities if they can trigger them. While the plugin shows good practices in using prepared statements for SQL queries (69%) and proper output escaping (78%), these strengths are overshadowed by the critical absence of authorization on its primary interaction mechanisms.

The vulnerability history for "moovin-delivery" is clean, with no recorded CVEs. This suggests that while it may have been subject to less scrutiny or has not yet been found to have exploitable public vulnerabilities, the static analysis findings are critical and should be addressed immediately. The lack of nonce and capability checks on AJAX actions is a direct invitation for common WordPress vulnerabilities like Cross-Site Request Forgery (CSRF) and unauthorized data manipulation. The presence of bundled libraries like DataTables and Select2, without specific version information, also introduces a potential risk if these libraries are outdated and contain known vulnerabilities.

In conclusion, the "moovin-delivery" plugin has some positive aspects regarding database and output handling. However, the core security design is fundamentally flawed by the lack of authentication on its AJAX endpoints and the identified high-severity taint flows. These issues present a clear and present danger to WordPress sites using this plugin, and immediate remediation is strongly advised to prevent potential security breaches.

Key Concerns

  • 13 unprotected AJAX handlers
  • 2 high severity taint flows
  • 0 nonce checks on AJAX
  • 0 capability checks
  • Bundled libraries (potential risk)
Vulnerabilities
None known

Moovin Delivery Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Moovin Delivery Code Analysis

Dangerous Functions
0
Raw SQL Queries
43
95 prepared
Unescaped Output
75
260 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
26
Bundled Libraries
2

Bundled Libraries

DataTablesSelect2

SQL Query Safety

69% prepared138 total queries

Output Escaping

78% escaped335 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
moovin_delivery_addresses (public\class-moovin-delivery-public.php:1512)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
13 unprotected

Moovin Delivery Attack Surface

Entry Points13
Unprotected13

AJAX Handlers 13

authwp_ajax_moovin_lib_handlerincludes\class-moovin-delivery.php:162
authwp_ajax_moovin_check_shipping_methodincludes\class-moovin-delivery.php:207
noprivwp_ajax_moovin_check_shipping_methodincludes\class-moovin-delivery.php:208
authwp_ajax_moovin_address_insertincludes\class-moovin-delivery.php:210
noprivwp_ajax_moovin_address_insertincludes\class-moovin-delivery.php:211
authwp_ajax_moovin_address_getincludes\class-moovin-delivery.php:213
noprivwp_ajax_moovin_address_getincludes\class-moovin-delivery.php:214
authwp_ajax_moovin_zones_coverage_getincludes\class-moovin-delivery.php:216
noprivwp_ajax_moovin_zones_coverage_getincludes\class-moovin-delivery.php:217
authwp_ajax_moovin_address_removeincludes\class-moovin-delivery.php:219
noprivwp_ajax_moovin_address_removeincludes\class-moovin-delivery.php:220
authwp_ajax_moovin_address_clearincludes\class-moovin-delivery.php:222
noprivwp_ajax_moovin_address_clearincludes\class-moovin-delivery.php:223
WordPress Hooks 33
actionplugins_loadedincludes\class-moovin-delivery.php:143
actionadmin_enqueue_scriptsincludes\class-moovin-delivery.php:156
actionadmin_enqueue_scriptsincludes\class-moovin-delivery.php:157
actionadmin_menuincludes\class-moovin-delivery.php:159
filtercron_schedulesincludes\class-moovin-delivery.php:165
actionisa_add_every_three_minutesincludes\class-moovin-delivery.php:166
actionwp_enqueue_scriptsincludes\class-moovin-delivery.php:180
actionwp_enqueue_scriptsincludes\class-moovin-delivery.php:181
actionwoocommerce_after_checkout_billing_formincludes\class-moovin-delivery.php:184
actionwoocommerce_after_checkout_shipping_formincludes\class-moovin-delivery.php:185
actionwoocommerce_review_order_after_shippingincludes\class-moovin-delivery.php:187
actionwoocommerce_after_shipping_calculatorincludes\class-moovin-delivery.php:188
actionwoocommerce_before_checkout_validationincludes\class-moovin-delivery.php:191
actionwoocommerce_after_checkout_validationincludes\class-moovin-delivery.php:192
actionwoocommerce_checkout_processincludes\class-moovin-delivery.php:194
filterwoocommerce_billing_fieldsincludes\class-moovin-delivery.php:196
filterwoocommerce_shipping_fieldsincludes\class-moovin-delivery.php:197
actionwoocommerce_thankyouincludes\class-moovin-delivery.php:198
actionwoocommerce_checkout_order_processedincludes\class-moovin-delivery.php:199
filterwoocommerce_package_ratesincludes\class-moovin-delivery.php:201
filterwoocommerce_checkout_update_order_reviewincludes\class-moovin-delivery.php:202
filterwoocommerce_ship_to_different_address_checkedincludes\class-moovin-delivery.php:203
filterwoocommerce_default_address_fieldsincludes\class-moovin-delivery.php:204
actionwp_loginincludes\class-moovin-delivery.php:225
filtercron_schedulesincludes\class-moovin-delivery.php:228
actionisa_add_every_three_minutesincludes\class-moovin-delivery.php:229
actionplugins_loadedincludes\class-moovin-delivery.php:232
actionwoocommerce_shipping_initmoovin-shipping-express.php:49
actionwoocommerce_shipping_methodsmoovin-shipping-express.php:50
actionplugins_loadedmoovin-shipping-express.php:54
actionwoocommerce_shipping_initmoovin-shipping.php:50
actionwoocommerce_shipping_methodsmoovin-shipping.php:51
actionplugins_loadedmoovin-shipping.php:56

Scheduled Events 3

isa_add_every_three_minutes
isa_add_every_three_minutes
isa_add_every_three_minutes
Maintenance & Trust

Moovin Delivery Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedAug 29, 2024
PHP min version5.6
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Moovin Delivery Developer Profile

Javier Hernández M

1 plugin · 10 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Moovin Delivery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/moovin-delivery/admin/js/moovin-delivery-admin.js/wp-content/plugins/moovin-delivery/admin/css/moovin-delivery-admin.css/wp-content/plugins/moovin-delivery/public/css/moovin-delivery-public.css/wp-content/plugins/moovin-delivery/public/js/moovin-delivery-public.js
Script Paths
/wp-content/plugins/moovin-delivery/admin/js/moovin-delivery-admin.js/wp-content/plugins/moovin-delivery/public/js/moovin-delivery-public.js
Version Parameters
moovin-delivery/admin/js/moovin-delivery-admin.js?ver=moovin-delivery/admin/css/moovin-delivery-admin.css?ver=moovin-delivery/public/css/moovin-delivery-public.css?ver=moovin-delivery/public/js/moovin-delivery-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
moovin-delivery-admin-config
Data Attributes
data-moovin-id
FAQ

Frequently Asked Questions about Moovin Delivery