Pargo Smart Logistics Solutions Security & Risk Analysis

wordpress.org/plugins/pargo

Pargo now offers Home Delivery and Click & Collect through our latest plugin update, giving your customers even more freedom when choosing their p …

300 active installs v3.5.10 PHP 7.4+ WP 5.8+ Updated Feb 3, 2026
couriercourier-appcourier-servicedeliveryorder-delivery
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Pargo Smart Logistics Solutions Safe to Use in 2026?

Generally Safe

Score 100/100

Pargo Smart Logistics Solutions has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "pargo" plugin v3.5.10 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, exclusively using prepared statements for SQL queries, and having no recorded vulnerability history. This suggests a developer who is generally aware of common security pitfalls.

However, there are significant concerns regarding its attack surface. The plugin exposes four AJAX handlers, all of which lack authentication checks. This is a critical oversight, as it allows any unauthenticated user to trigger these actions, potentially leading to unintended consequences or exploitation. Furthermore, the taint analysis reveals five flows with unsanitized paths, indicating potential for injection vulnerabilities if these paths are ever exposed to user-controlled input without proper sanitization. While the current taint analysis didn't flag critical or high severity issues, the presence of unsanitized paths is a strong indicator of risk.

Despite the lack of known CVEs, the identified weaknesses in the attack surface and taint analysis present a considerable risk. The absence of authentication on AJAX handlers is a clear vulnerability that should be addressed immediately. The plugin's strengths lie in its database handling and lack of past exploits, but these are overshadowed by the easily exploitable entry points that are currently unprotected.

Key Concerns

  • AJAX handlers without auth checks
  • Flows with unsanitized paths
  • Low number of capability checks relative to entry points
Vulnerabilities
None known

Pargo Smart Logistics Solutions Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Pargo Smart Logistics Solutions Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
14 escaped
Nonce Checks
1
Capability Checks
10
File Operations
7
External Requests
2
Bundled Libraries
0

Output Escaping

74% escaped19 total outputs
Data Flows
5 unsanitized

Data Flow Analysis

6 flows5 with unsanitized paths
submit (src\Includes\Analytics.php:19)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Pargo Smart Logistics Solutions Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

authwp_ajax_woocommerce_shipping_zone_methods_save_settingssrc\Includes\Pargo.php:156
authwp_ajax_pargo_rating_notice_dismisssrc\Includes\Pargo.php:164
authwp_ajax_set_pick_up_pointsrc\Includes\Pargo.php:178
noprivwp_ajax_set_pick_up_pointsrc\Includes\Pargo.php:179
WordPress Hooks 47
actionplugins_loadedsrc\Includes\Pargo.php:129
filterwoocommerce_shipping_methodssrc\Includes\Pargo.php:144
filterwoocommerce_order_data_store_cpt_get_orders_querysrc\Includes\Pargo.php:145
actionwoocommerce_shipping_initsrc\Includes\Pargo.php:147
actionrest_api_initsrc\Includes\Pargo.php:148
actionplugins_loadedsrc\Includes\Pargo.php:149
filterscript_loader_tagsrc\Includes\Pargo.php:151
filterwoocommerce_admin_billing_fieldssrc\Includes\Pargo.php:152
filterwoocommerce_admin_shipping_fieldssrc\Includes\Pargo.php:153
filterwoocommerce_order_actionssrc\Includes\Pargo.php:154
actionadmin_enqueue_scriptssrc\Includes\Pargo.php:157
actionadmin_enqueue_scriptssrc\Includes\Pargo.php:158
actionadmin_menusrc\Includes\Pargo.php:159
actionwoocommerce_admin_order_data_after_billing_addresssrc\Includes\Pargo.php:160
actionsave_postsrc\Includes\Pargo.php:161
actionwoocommerce_order_action_pargo_submit_pargo_ordersrc\Includes\Pargo.php:162
actionadmin_noticessrc\Includes\Pargo.php:163
actionwoocommerce_order_status_changedsrc\Includes\Pargo.php:180
actionwc_ajax_update_shipping_methodsrc\Includes\Pargo.php:181
actionwc_ajax_nopriv_update_shipping_methodsrc\Includes\Pargo.php:182
actionwc_ajax_update_order_reviewsrc\Includes\Pargo.php:183
actionwc_ajax_nopriv_update_order_reviewsrc\Includes\Pargo.php:184
actionwpsrc\Includes\Pargo.php:185
actionwoocommerce_sanitize_additional_fieldsrc\Includes\Pargo.php:188
actionwoocommerce_validate_suburb_fieldsrc\Includes\Pargo.php:189
filterwoocommerce_default_address_fieldssrc\Includes\Pargo.php:191
filterwoocommerce_my_account_my_address_formatted_addresssrc\Includes\Pargo.php:192
filterwoocommerce_order_formatted_billing_addresssrc\Includes\Pargo.php:193
filterwoocommerce_order_formatted_shipping_addresssrc\Includes\Pargo.php:194
filterwoocommerce_formatted_address_replacementssrc\Includes\Pargo.php:195
filterwoocommerce_localisation_address_formatssrc\Includes\Pargo.php:196
filterwoocommerce_cart_shipping_method_full_labelsrc\Includes\Pargo.php:199
filterwoocommerce_checkout_fieldssrc\Includes\Pargo.php:200
filterwoocommerce_is_rest_api_requestsrc\Includes\Pargo.php:201
filterwoocommerce_package_ratessrc\Includes\Pargo.php:202
actionwp_enqueue_scriptssrc\Includes\Pargo.php:206
actionwp_enqueue_scriptssrc\Includes\Pargo.php:207
actionwoocommerce_checkout_processsrc\Includes\Pargo.php:208
actionrest_api_initsrc\Includes\Pargo.php:209
actionwoocommerce_after_shipping_calculatorsrc\Includes\Pargo.php:210
actionwoocommerce_before_cart_totalssrc\Includes\Pargo.php:211
actionwoocommerce_review_order_before_submitsrc\Includes\Pargo.php:212
actionwoocommerce_new_ordersrc\Includes\Pargo.php:213
actionwoocommerce_after_checkout_validationsrc\Includes\Pargo.php:214
actionwoocommerce_order_status_completedsrc\Includes\Pargo.php:215
actionwoocommerce_order_details_after_customer_detailssrc\Includes\Pargo.php:216
actionwoocommerce_checkout_update_order_metasrc\PargoPublic\Pargo_Public.php:593
Maintenance & Trust

Pargo Smart Logistics Solutions Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 3, 2026
PHP min version7.4
Downloads23K

Community Trust

Rating56/100
Number of ratings6
Active installs300
Developer Profile

Pargo Smart Logistics Solutions Developer Profile

Pargo

1 plugin · 300 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Pargo Smart Logistics Solutions

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pargo/pargo-admin.css/wp-content/plugins/pargo/pargo-public.css/wp-content/plugins/pargo/pargo-admin.js/wp-content/plugins/pargo/pargo-public.js/wp-content/plugins/pargo/pargo-checkout.js/wp-content/plugins/pargo/pargo-admin-init.js
Script Paths
/wp-content/plugins/pargo/pargo-admin.js/wp-content/plugins/pargo/pargo-public.js/wp-content/plugins/pargo/pargo-checkout.js/wp-content/plugins/pargo/pargo-admin-init.js
Version Parameters
pargo-admin.css?ver=pargo-public.css?ver=pargo-admin.js?ver=pargo-public.js?ver=pargo-checkout.js?ver=pargo-admin-init.js?ver=

HTML / DOM Fingerprints

CSS Classes
pargo-checkout-field-wrapperpargo-checkout-field-selectpargo-shipping-method-title
HTML Comments
<!-- Pargo Admin API --><!-- Pargo Public API --><!-- Pargo Checkout --><!-- Pargo Shipping -->
Data Attributes
data-pargo-api-urldata-pargo-keydata-pargo-methoddata-pargo-point-selector
JS Globals
pargo_checkout_paramsPargoAdmin
REST Endpoints
/wp-json/pargo/v1/locations/wp-json/pargo/v1/shipping_methods
Shortcode Output
[pargo_checkout_location_selector]
FAQ

Frequently Asked Questions about Pargo Smart Logistics Solutions