
NowPost Click & Collect Security & Risk Analysis
wordpress.org/plugins/nowpost-click-collectFlexible pickup-point delivery for WooCommerce stores, reducing failed deliveries and improving customer satisfaction.
Is NowPost Click & Collect Safe to Use in 2026?
Generally Safe
Score 100/100NowPost Click & Collect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'nowpost-click-collect' v0.0.1 plugin exhibits a concerning security posture primarily due to its unprotected AJAX endpoints and the presence of a dangerous function. While the plugin demonstrates good practices in SQL query preparation and output escaping, the lack of authentication checks on its two AJAX handlers creates a significant attack surface. Any user, authenticated or not, can trigger these handlers, potentially leading to unintended actions or information disclosure if the internal logic is vulnerable. The use of the `unserialize` function, especially without strong input validation or sanitization, is a critical risk, as it can lead to Remote Code Execution (RCE) if malicious serialized data is provided.
Despite the absence of recorded historical vulnerabilities, this does not guarantee future safety. The current code analysis reveals clear and present dangers. The lack of capability checks on the AJAX endpoints further exacerbates the risk. While the plugin has a small attack surface, the unprotected nature of these entry points, combined with the `unserialize` function, makes it a prime target. The plugin's strengths lie in its SQL and output handling, but these are overshadowed by the critical vulnerabilities introduced by the unprotected AJAX and the `unserialize` function.
Key Concerns
- Unprotected AJAX handlers
- Dangerous function: unserialize
- Missing capability checks on AJAX
NowPost Click & Collect Security Vulnerabilities
NowPost Click & Collect Code Analysis
Dangerous Functions Found
Output Escaping
NowPost Click & Collect Attack Surface
AJAX Handlers 2
WordPress Hooks 23
Maintenance & Trust
NowPost Click & Collect Maintenance & Trust
Maintenance Signals
Community Trust
NowPost Click & Collect Alternatives
Shiprocket
shiprocket
Auto Sync your Woocommerce store orders & ship them at lowest shipping rates. Automate your shipping, save time & money.
Bijak
bijak
Add smart freight shipping to WooCommerce with live rate estimates and order integration via the Bijak API.
CODPartner
codpartner
A Platform that covers all logistics needs for COD e-commerce sellers.
Do Deliver Orders
do-deliver-orders
Streamline WooCommerce order delivery with Do Deliver integration. Note: This plugin connects to a third-partyr external service (Do Deliver).
Express One Shipment
express-one-shipment
WooCommerce integration with Express One Pickup Point and Home Delivery shipping services.
NowPost Click & Collect Developer Profile
1 plugin · 0 total installs
How We Detect NowPost Click & Collect
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nowpost-click-collect/assets/nowpost.css/wp-content/plugins/nowpost-click-collect/assets/nowpost-widget.iife.js/wp-content/plugins/nowpost-click-collect/assets/nowpost.js/wp-content/plugins/nowpost-click-collect/assets/nowpost-hide-free.css/wp-content/plugins/nowpost-click-collect/assets/nowpost-hide-free.js/wp-content/plugins/nowpost-click-collect/assets/nowpost.js/wp-content/plugins/nowpost-click-collect/assets/nowpost-widget.iife.js/wp-content/plugins/nowpost-click-collect/assets/nowpost-hide-free.jsnowpost-click-collect/assets/nowpost.css?ver=nowpost-click-collect/assets/nowpost-widget.iife.js?ver=nowpost-click-collect/assets/nowpost.js?ver=nowpost-click-collect/assets/nowpost-hide-free.css?ver=nowpost-click-collect/assets/nowpost-hide-free.js?ver=HTML / DOM Fingerprints
nowpost_pudo_uinowpost_opennowpost_chosenid="nowpost_pickup"id="nowpost_pudo_ui"id="nowpost_open"id="nowpost_chosen"NowPostPudo