
Shipping for Nova Poshta Security & Risk Analysis
wordpress.org/plugins/nova-poshta-ttnДоставка на відділення, поштомат та адресу (з автопошуком вулиць). Створення ТТН. Найзручніший плагін.
Is Shipping for Nova Poshta Safe to Use in 2026?
Generally Safe
Score 98/100Shipping for Nova Poshta has a strong security track record. Known vulnerabilities have been patched promptly.
The "nova-poshta-ttn" plugin version 1.19.8 presents a mixed security posture. While it shows positive signs like using prepared statements for a majority of its SQL queries and performing some output escaping, significant concerns arise from its attack surface and taint analysis. The plugin exposes a substantial number of AJAX handlers (19) with no authentication checks, creating a broad entry point for potential attackers. Furthermore, taint analysis reveals 11 flows with unsanitized paths, including 4 designated as high severity, indicating a real risk of data manipulation or unauthorized access if these flows can be triggered by user-supplied input. The history of a previously disclosed high-severity SQL injection vulnerability, though currently patched, reinforces the importance of vigilance regarding input sanitization.
Key Concerns
- Large attack surface without authentication
- High severity taint flows
- Unescaped output
- Raw SQL without prepare (1 of 66)
- Nonce checks present but insufficient
- Bundled library (Select2)
Shipping for Nova Poshta Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Shipping for Nova Poshta plugin for WordPress <= 1.19.6 - Unauthenticated SQL Injection
Shipping for Nova Poshta Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Shipping for Nova Poshta Attack Surface
AJAX Handlers 19
WordPress Hooks 91
Maintenance & Trust
Shipping for Nova Poshta Maintenance & Trust
Maintenance Signals
Community Trust
Shipping for Nova Poshta Alternatives
Woo NovaPoshta. Электронная накладная
nova-poshta-declarations
Новая почта электронные накладные. Вывод электронных накладных в заказе (woocommerce).
Morkva UA Shipping
morkva-ua-shipping
Нова Пошта по Україні та закордон, Укрпошта по Україні та закордон. Rozetka Delivery. Зручне створення ТТН. Друк ТТН. Сумісний з іншими плагінами.
WC Ukraine Shipping – Integration of Nova Poshta and Ukrposhta for WooCommerce
wc-ukr-shipping
Connect Nova Poshta, Ukrposhta, Meest or international delivery services with your store. Create labels, track orders and calculate rates in one place …
Shipping of Nova Poshta for WooCommerce
wc-nova-poshta-for-shop
Підключення служби доставки Нова Пошта до Вашого сайту (WooCommerce)
Shipping via Nova Poshta for WooCommerce
woo-nova-poshta-shipping
This plugin add ukrainian shipping method "Nova Poshta" to Woocommerce.
Shipping for Nova Poshta Developer Profile
14 plugins · 3K total installs
How We Detect Shipping for Nova Poshta
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nova-poshta-ttn/assets/css/nova-poshta-admin.css/wp-content/plugins/nova-poshta-ttn/assets/css/nova-poshta-frontend.css/wp-content/plugins/nova-poshta-ttn/assets/js/nova-poshta-admin.js/wp-content/plugins/nova-poshta-ttn/assets/js/nova-poshta-frontend.js/wp-content/plugins/nova-poshta-ttn/assets/js/nova-poshta-checkout.js/wp-content/plugins/nova-poshta-ttn/assets/js/nova-poshta-admin.js/wp-content/plugins/nova-poshta-ttn/assets/js/nova-poshta-frontend.js/wp-content/plugins/nova-poshta-ttn/assets/js/nova-poshta-checkout.jsnova-poshta-ttn/assets/css/nova-poshta-admin.css?ver=nova-poshta-ttn/assets/css/nova-poshta-frontend.css?ver=nova-poshta-ttn/assets/js/nova-poshta-admin.js?ver=nova-poshta-ttn/assets/js/nova-poshta-frontend.js?ver=nova-poshta-ttn/assets/js/nova-poshta-checkout.js?ver=HTML / DOM Fingerprints
mrkvnplastupdatemrkvnpajaxupdatenpcitylinpwhlidata-np-city-refdata-np-warehouse-refnpdata_fetchwh