
NCM API Security & Risk Analysis
wordpress.org/plugins/ncm-apiConnect WooCommerce orders with Nepal Can Move and manage delivery operations directly from WordPress.
Is NCM API Safe to Use in 2026?
Generally Safe
Score 100/100NCM API has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'ncm-api' v1.0.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any identified attack surface entry points without authentication checks, coupled with a high percentage of properly escaped output and the presence of at least one nonce check, are positive indicators. The plugin also has a clean vulnerability history with no recorded CVEs, suggesting a lack of previously exploited weaknesses.
However, a significant concern arises from the presence of a single SQL query that does not utilize prepared statements. While this is a single instance, it represents a potential vulnerability to SQL injection if the data used in the query is not rigorously sanitized before reaching the database. The analysis of external HTTP requests also warrants attention, as 8 such requests could potentially be exploited if the target endpoints are compromised or if data is not handled securely during these communications.
In conclusion, 'ncm-api' v1.0.0 demonstrates good development practices in many areas, particularly concerning its attack surface and output escaping. The lack of historical vulnerabilities is reassuring. The primary weakness identified is the non-prepared SQL query, which, despite being isolated, poses a tangible risk. Careful review and potential remediation of this SQL query are recommended to further enhance the plugin's security.
Key Concerns
- SQL query not using prepared statements
NCM API Security Vulnerabilities
NCM API Release Timeline
NCM API Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
NCM API Attack Surface
WordPress Hooks 16
Maintenance & Trust
NCM API Maintenance & Trust
Maintenance Signals
Community Trust
NCM API Alternatives
Local Delivery Drivers for WooCommerce
local-delivery-drivers-for-woocommerce
Improve the way you deliver, manage drivers, assign drivers to orders, send WhatsApp, SMS, and email notifications, route planning, navigation & more!
Woot
woot-ro
Unified shipping solution for WooCommerce. Integrates all popular couriers in Romania with real-time pricing and pickup point selection.
Uber Direct Integration
uber-direct-delivery-integration
Offer instant or scheduled delivery from your WooCommerce store with real-time quotes and Uber Direct integration
UDW Delivery – Uber Direct for WooCommerce
udwdelivery
Delivery service for WooCommerce integrating with Uber Direct API.
Gobuddy – The smart delivery solution
gobuddy-the-smart-delivery-solution
The official Gobuddy plugin for WooCommerce
NCM API Developer Profile
1 plugin · 40 total installs
How We Detect NCM API
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ncm-api/admin/css/ncm-api-admin.css/wp-content/plugins/ncm-api/assets/css/bootstrap.min.css/wp-content/plugins/ncm-api/assets/css/datatables.min.css/wp-content/plugins/ncm-api/assets/css/sweetalert.css/wp-content/plugins/ncm-api/assets/fontawesome/css/all.css/wp-content/plugins/ncm-api/assets/js/bootstrap.bundle.min.js/wp-content/plugins/ncm-api/assets/js/jquery.dataTables.min.js/wp-content/plugins/ncm-api/assets/js/jquery.validate.min.js+2 more/wp-content/plugins/ncm-api/admin/js/ncm-api-admin.jsncm-api/admin/css/ncm-api-admin.css?ver=ncm-api/assets/css/bootstrap.min.css?ver=ncm-api/assets/css/datatables.min.css?ver=ncm-api/assets/css/sweetalert.css?ver=ncm-api/assets/fontawesome/css/all.css?ver=ncm-api/assets/js/bootstrap.bundle.min.js?ver=ncm-api/assets/js/jquery.dataTables.min.js?ver=ncm-api/assets/js/jquery.validate.min.js?ver=ncm-api/assets/js/sweetalert.min.js?ver=ncm-api/admin/js/ncm-api-admin.js?ver=HTML / DOM Fingerprints
ncm-api-settingsncm-orders-listnon-ncm-orders-listNCM_API_VERSIONNCM_API_PLUGIN_URINCM_API_PLUGIN_PATH