
ParcelWILL (Formerly ParcelPanel) – Shipment Tracking, Tracking & Order Tracking for WooCommerce Security & Risk Analysis
wordpress.org/plugins/parcelpanelFree Plan Available. Order Tracking, Shipment Tracking. The best WooCommerce Order Tracker for Track Order Status & Delivery Notifications
Is ParcelWILL (Formerly ParcelPanel) – Shipment Tracking, Tracking & Order Tracking for WooCommerce Safe to Use in 2026?
Generally Safe
Score 96/100ParcelWILL (Formerly ParcelPanel) – Shipment Tracking, Tracking & Order Tracking for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The Parcel Panel plugin, version 4.5.5, presents a mixed security posture. On the positive side, it demonstrates good practices in several areas, including a high percentage of SQL queries using prepared statements and properly escaped output. The use of nonces and capability checks is also present. However, significant concerns arise from the substantial attack surface exposed through AJAX handlers, with more than half of them lacking authentication checks. Furthermore, the taint analysis revealed four high-severity flows with unsanitized paths, indicating potential for attackers to exploit these vulnerabilities. The plugin's vulnerability history is also a notable weakness, with two known CVEs, including a past critical SQL injection and cross-site scripting vulnerability. While these are currently unpatched, the recurrence of these vulnerability types suggests a persistent risk in how user input is handled. Overall, while the plugin employs some strong security measures, the critical issues in its attack surface management and input sanitization, coupled with its vulnerability history, necessitate a cautious approach.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized taint flows
- Past critical SQL injection CVE
- Past XSS CVE
ParcelWILL (Formerly ParcelPanel) – Shipment Tracking, Tracking & Order Tracking for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
ParcelPanel <= 4.3.2 - Reflected Cross-Site Scripting
Shipment Tracking, Tracking, and Order Tracking for WooCommerce – ParcelPanel (Free to install) <= 3.8.2 - Authenticated (Subscriber+) SQL Injection
ParcelWILL (Formerly ParcelPanel) – Shipment Tracking, Tracking & Order Tracking for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
ParcelWILL (Formerly ParcelPanel) – Shipment Tracking, Tracking & Order Tracking for WooCommerce Attack Surface
AJAX Handlers 21
Shortcodes 1
WordPress Hooks 100
Scheduled Events 1
Maintenance & Trust
ParcelWILL (Formerly ParcelPanel) – Shipment Tracking, Tracking & Order Tracking for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
ParcelWILL (Formerly ParcelPanel) – Shipment Tracking, Tracking & Order Tracking for WooCommerce Alternatives
Orders Tracking for WooCommerce
woo-orders-tracking
Easily import/manage your tracking numbers, add tracking numbers to PayPal and send email notifications to customers.
TrackShip for WooCommerce
trackship-for-woocommerce
TrackShip auto-tracks orders, adds a branded tracking experience to your store and handles all customer touchpoints from shipping to delivery
Advanced Shipment Tracking for WooCommerce
woo-advanced-shipment-tracking
Add shipment tracking info to WooCommerce orders, send tracking numbers to customers via email, and let them track deliveries from My Account.
WPCargo Track & Trace
wpcargo
WPCargo is a track & trace system for courier, courier script, parcel, balikbayan system, shipment and transportation management system, ideal sol …
AfterShip Tracking – All-In-One WooCommerce Order Tracking (Free plan available)
aftership-woocommerce-tracking
Track orders in one place. shipment tracking, automated notifications, order lookup, branded tracking page, delivery day prediction
ParcelWILL (Formerly ParcelPanel) – Shipment Tracking, Tracking & Order Tracking for WooCommerce Developer Profile
1 plugin · 8K total installs
How We Detect ParcelWILL (Formerly ParcelPanel) – Shipment Tracking, Tracking & Order Tracking for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/parcelpanel/assets/css/parcelpanel-tracking-public.css/wp-content/plugins/parcelpanel/assets/js/parcelpanel-tracking-public.js/wp-content/plugins/parcelpanel/assets/js/parcelpanel-tracking-public.jsparcelpanel/style.css?ver=parcelpanel/script.js?ver=HTML / DOM Fingerprints
pp-track-page-warppp-main-contentpp-track-statuspp-tracking-history-wrappp-detail-contentpp-detail-content-item<!-- Begin Parcel Panel --><!-- End Parcel Panel -->data-parcelpanel-iddata-tracking-numberparcelPanel/wp-json/parcelpanel/v1/trackings/wp-json/parcelpanel/v1/product/message/wp-json/parcelpanel/v1/product/add/wp-json/parcelpanel/v1/product/del/wp-json/parcelpanel/v1/product/get[parcelpanel-tracking-form][parcelpanel-tracking-details]