
Parcel2Go Shipping Security & Risk Analysis
wordpress.org/plugins/parcel2go-shippingCreate shipments from WooCommerce admin via the Parcel2Go API: get quotes, book services, and pay.
Is Parcel2Go Shipping Safe to Use in 2026?
Generally Safe
Score 100/100Parcel2Go Shipping has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "parcel2go-shipping" v2.0.1 plugin exhibits a generally strong security posture based on static analysis, with good practices observed in SQL query handling and output escaping. The absence of known vulnerabilities (CVEs) and a clean vulnerability history further contribute to this positive assessment, suggesting a well-maintained and secure codebase.
However, the plugin presents a notable area of concern regarding its REST API. A significant portion of its REST API routes (12 out of 25) lack permission callbacks, creating an exposed attack surface that could potentially be exploited by unauthenticated users. While taint analysis shows no critical or high-severity flows, this lack of authentication on several entry points represents a tangible risk that should not be overlooked.
In conclusion, while the plugin demonstrates commendable security hygiene in many areas, the unprotected REST API routes are a significant weakness. This could allow for unauthorized data access or manipulation if these routes perform sensitive actions. Prioritizing the implementation of proper permission checks for all REST API endpoints is crucial to mitigate this identified risk.
Key Concerns
- Unprotected REST API endpoints
Parcel2Go Shipping Security Vulnerabilities
Parcel2Go Shipping Code Analysis
Output Escaping
Parcel2Go Shipping Attack Surface
REST API Routes 25
WordPress Hooks 23
Maintenance & Trust
Parcel2Go Shipping Maintenance & Trust
Maintenance Signals
Community Trust
Parcel2Go Shipping Alternatives
WooCommerce Shipping
woocommerce-shipping
A free shipping plugin for US merchants to print discounted shipping labels and compare live label rates directly from your WooCommerce dashboard.
The Courier Guy Shipping for WooCommerce
the-courier-guy
This is the official WooCommerce extension to ship products using The Courier Guy.
PostNL for WooCommerce
woo-postnl
The official PostNL plugin allows you to automate your e-commerce order process. Covering shipping services from PostNL Netherlands and Belgium.
Easyship WooCommerce Shipping Rates
easyship-woocommerce-shipping-rates
Easyship for WooCommerce saves you time and money with live courier rates, seamless checkout, automated taxes & duties, and shipping label creation.
Local Delivery Drivers for WooCommerce
local-delivery-drivers-for-woocommerce
Improve the way you deliver, manage drivers, assign drivers to orders, send WhatsApp, SMS, and email notifications, route planning, navigation & more!
Parcel2Go Shipping Developer Profile
1 plugin · 100 total installs
How We Detect Parcel2Go Shipping
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/parcel2go-shipping/public/couriers/wp-content/plugins/parcel2go-shipping/build/index.css/wp-content/plugins/parcel2go-shipping/build/index.js/wp-content/plugins/parcel2go-shipping/build/index.jsparcel2go-shipping/build/index.css?ver=parcel2go-shipping/build/index.js?ver=HTML / DOM Fingerprints
p2g-order-cardparcel2go-shipping-settings<!-- Parcel2Go Shipping Meta Box --><!-- Order card for Parcel2Go Shipping -->data-order-iddata-p2g-tracking-urldata-p2g-booking-urlparcel2go_shipping_optionsparcel2go_shipping_config/wp-json/parcel2go-shipping/v1/orders/wp-json/parcel2go-shipping/v1/quotes/wp-json/parcel2go-shipping/v1/countries/wp-json/parcel2go-shipping/v1/dropshops/wp-json/parcel2go-shipping/v1/checkout/wp-json/parcel2go-shipping/v1/payment/wp-json/parcel2go-shipping/v1/settings