
افزونه حمل و نقل ووکامرس | پست پیشتاز، تیپاکس و پیک موتوری Security & Risk Analysis
wordpress.org/plugins/persian-woocommerce-shippingارسال مرسوله های ووکامرس از طریق پست پیشتاز، تسپاکس و پیک موتوری با محاسبه خودکار تعرفه
Is افزونه حمل و نقل ووکامرس | پست پیشتاز، تیپاکس و پیک موتوری Safe to Use in 2026?
Generally Safe
Score 99/100افزونه حمل و نقل ووکامرس | پست پیشتاز، تیپاکس و پیک موتوری has a strong security track record. Known vulnerabilities have been patched promptly.
The Persian WooCommerce Shipping plugin v4.4.1 presents a mixed security posture. While it demonstrates some good practices such as a high percentage of prepared SQL statements and properly escaped output, significant concerns arise from its attack surface. A notable number of AJAX handlers (5 out of 8) and a REST API route lack authentication or permission checks, creating potential entry points for unauthorized actions. The presence of a `create_function` usage is also a red flag, as this is considered a dangerous function in PHP and can be a vector for code injection if not handled with extreme care. Taint analysis did not reveal critical or high severity flows, which is a positive indicator, however, the 5 analyzed flows all involved unsanitized paths, suggesting potential risks that may not have reached critical levels in this analysis but warrant attention.
The plugin's vulnerability history, despite having one medium-severity CVE in the past related to Cross-site Scripting, shows that there are currently no unpatched vulnerabilities. This indicates that past issues have been addressed. However, the presence of even one CVE, especially a medium one, highlights the importance of robust security practices. The overall conclusion is that while the plugin has addressed past issues and shows some good coding habits, the significant number of unprotected entry points and the use of a dangerous function represent areas of notable risk that should be prioritized for remediation.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API route
- Use of dangerous function (create_function)
- Flows with unsanitized paths
- SQL queries without prepared statements
- Low number of nonce checks
- Low number of capability checks
افزونه حمل و نقل ووکامرس | پست پیشتاز، تیپاکس و پیک موتوری Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
persian-woocommerce-shipping <= 4.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
افزونه حمل و نقل ووکامرس | پست پیشتاز، تیپاکس و پیک موتوری Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
افزونه حمل و نقل ووکامرس | پست پیشتاز، تیپاکس و پیک موتوری Attack Surface
AJAX Handlers 8
REST API Routes 1
Shortcodes 1
WordPress Hooks 104
Scheduled Events 1
Maintenance & Trust
افزونه حمل و نقل ووکامرس | پست پیشتاز، تیپاکس و پیک موتوری Maintenance & Trust
Maintenance Signals
Community Trust
افزونه حمل و نقل ووکامرس | پست پیشتاز، تیپاکس و پیک موتوری Alternatives
AWSA Shipping – Advanced Shipping for Woocommerce and Dokan
awsa-shipping
روش های حمل و نقل با تنظیمات پیشرفته
ووکامرس فارسی
persian-woocommerce
بسته ووکامرس فارسی به راحتی سیستم فروشگاه ساز ووکامرس را فارسی می کند و امکانات جدید متناسب با ایران را به ووکامرس اضافه میکند.
افزونه پیامک ووکامرس Persian WooCommerce SMS
persian-woocommerce-sms
افزونه کامل و حرفه ای برای اطلاع رسانی پیامکی سفارشات و رویداد های محصولات ووکامرس
Zify Gateway
zify-gateway
افزونه درگاه پرداخت زیفای برای ووکامرس
پارسی دیت – Parsi Date
wp-parsidate
Persian date support for WordPress
افزونه حمل و نقل ووکامرس | پست پیشتاز، تیپاکس و پیک موتوری Developer Profile
10 plugins · 27K total installs
How We Detect افزونه حمل و نقل ووکامرس | پست پیشتاز، تیپاکس و پیک موتوری
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/persian-woocommerce-shipping/assets/css/admin.csspersian-woocommerce-shipping/assets/css/admin.css?ver=HTML / DOM Fingerprints
data-pws-pro-url