
Plugin Ongkos Kirim JNE Tiki Sicepat Wahana J&T POS for Woocommerce Security & Risk Analysis
wordpress.org/plugins/ongkoskirim-idOngkosKirim.id merupakan plugin ongkos kirim woocommerce dengan fitur terkomplit dan ekspedisi terlengkap, meliputi JNE, TIKI, POS, J&T, Sicepat, …
Is Plugin Ongkos Kirim JNE Tiki Sicepat Wahana J&T POS for Woocommerce Safe to Use in 2026?
Use With Caution
Score 63/100Plugin Ongkos Kirim JNE Tiki Sicepat Wahana J&T POS for Woocommerce has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The ongkoskirim-id plugin v1.0.6 exhibits a concerning security posture, primarily due to a significant lack of authorization checks on its entry points. All 6 identified AJAX handlers are exposed without any authentication or capability checks, creating a wide attack surface for unauthenticated users. While the plugin does not appear to use dangerous functions or raw SQL queries, the high percentage of improperly escaped output (87%) is a notable weakness that could lead to cross-site scripting (XSS) vulnerabilities. The taint analysis, while showing no critical or high-severity flows, does indicate 5 flows with unsanitized paths, which, combined with the lack of output escaping, warrants attention. Furthermore, the plugin has a history of known vulnerabilities, including one currently unpatched medium-severity CVE. This suggests a pattern of security oversights, with missing authorization being a recurring issue. Despite the absence of raw SQL and dangerous functions, the numerous unprotected AJAX endpoints, poor output escaping, and past vulnerability history make this plugin a moderate to high risk.
Key Concerns
- Unprotected AJAX handlers
- Unescaped output
- Unpatched CVE
- Flows with unsanitized paths
- Missing capability checks
Plugin Ongkos Kirim JNE Tiki Sicepat Wahana J&T POS for Woocommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Ongkoskirim.id <= 1.0.6 - Missing Authorization
Plugin Ongkos Kirim JNE Tiki Sicepat Wahana J&T POS for Woocommerce Code Analysis
Output Escaping
Data Flow Analysis
Plugin Ongkos Kirim JNE Tiki Sicepat Wahana J&T POS for Woocommerce Attack Surface
AJAX Handlers 6
WordPress Hooks 21
Maintenance & Trust
Plugin Ongkos Kirim JNE Tiki Sicepat Wahana J&T POS for Woocommerce Maintenance & Trust
Maintenance Signals
Community Trust
Plugin Ongkos Kirim JNE Tiki Sicepat Wahana J&T POS for Woocommerce Alternatives
Epeken All Kurir for Woocommerce
epeken-all-kurir
Epeken All Kurir is a wordpress plugin for woocommerce to enable shipping method featuring many shipping companies for Indonesia e-commerce.
AgenWebsite Shipping – Plugin Ongkos Kirim & Generate Resi Otomatis Semua Kurir Indonesia
woocommerce-jne
Otomatisasi pengiriman WooCommerce dengan kurir terpercaya Indonesia. Tarif real-time, pelacakan instan, cetak resi otomatis - tanpa hitung manual!
JNE Shipping
jne-shipping
Plugin JNE Shipping Indonesia yang khusus untuk diintegrasikan dengan plugin WP-Ecommerce.
JNE Shipping – Plugin Ongkos Kirim Resmi Untuk WooCommerce
jne-shipping-official
Plugin pengiriman JNE resmi untuk WooCommerce di Indonesia. Menyediakan tarif real-time, pembuatan AWB, dan pelacakan pengiriman.
Weight Based Shipping Table Rate for WooCommerce – Flexible Shipping
flexible-shipping
Weight based shipping methods for WooCommerce. Flexible shipping with table rate rules by cart weight and order value. Accurate rates at checkout.
Plugin Ongkos Kirim JNE Tiki Sicepat Wahana J&T POS for Woocommerce Developer Profile
1 plugin · 2K total installs
How We Detect Plugin Ongkos Kirim JNE Tiki Sicepat Wahana J&T POS for Woocommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ongkoskirim-id/admin/css/ongkoskirim-id-welcome-style.css/wp-content/plugins/ongkoskirim-id/admin/css/ongkoskirim-id-welcome-responsive.css/wp-content/plugins/ongkoskirim-id/admin/css/ongkoskirim-id-admin.css/wp-content/plugins/ongkoskirim-id/admin/js/ongkoskirim-id-admin.jsongkoskirim-id-admin.css?ver=ongkoskirim-id-admin.js?ver=ongkoskirim-id-welcome-style.css?ver=ongkoskirim-id-welcome-responsive.css?ver=HTML / DOM Fingerprints
data-urldata-licensedata-toggledata-target