Pidex Security & Risk Analysis

wordpress.org/plugins/pidex

Pidex enables you to send a parcel booking request to Pidex directly from your WooCommerce orders or automatically after checkout.

0 active installs v1.0.1 PHP 7.4+ WP 5.8+ Updated Aug 7, 2023
couriere-commercepidexpidex-parcel-bookingpidex-parcel-tracker
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Pidex Safe to Use in 2026?

Generally Safe

Score 85/100

Pidex has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "pidex" v1.0.1 plugin demonstrates a strong security posture based on the provided static analysis. All identified entry points, including AJAX handlers and shortcodes, appear to be protected with either nonce or capability checks, which is a significant positive. The code also adheres to secure practices by using prepared statements for all SQL queries and properly escaping all output, indicating a good understanding of fundamental web security principles. The absence of file operations and critical taint analysis findings further reinforces this.

However, there are a couple of areas that warrant attention. The presence of 9 AJAX handlers, while seemingly protected, represents a moderately sized attack surface. More importantly, the lack of any recorded vulnerability history, while seemingly positive, could also indicate insufficient historical analysis or a plugin that hasn't been thoroughly tested over time. A truly robust security assessment would typically involve deeper taint analysis to ensure no subtle vulnerabilities exist, even with the current positive findings.

In conclusion, "pidex" v1.0.1 exhibits a commendable level of security, with robust input validation and output sanitization. The primary areas for cautious consideration are the management of its attack surface and the confidence derived from its clean historical vulnerability record. While the current data is reassuring, continuous monitoring and more in-depth security testing are always advisable for any WordPress plugin.

Key Concerns

  • 9 AJAX handlers with capability checks is good
  • 0 REST API routes without permission callbacks
  • 1 shortcode without obvious issues
  • 0 cron events
  • 0 unprotected entry points
  • 0 dangerous functions found
  • 100% SQL queries use prepared statements
  • 100% output properly escaped
  • 0 file operations
  • 5 external HTTP requests
  • 8 nonce checks present
  • 0 capability checks identified
  • Select2 bundled library
  • 0 taint flows with unsanitized paths
  • 0 critical severity taint flows
  • 0 high severity taint flows
  • 0 known CVEs
  • 0 currently unpatched vulnerabilities
Vulnerabilities
None known

Pidex Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Pidex Release Timeline

v1.0.1Current
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Pidex Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
3 prepared
Unescaped Output
0
95 escaped
Nonce Checks
8
Capability Checks
0
File Operations
0
External Requests
5
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

100% prepared3 total queries

Output Escaping

100% escaped95 total outputs
Attack Surface

Pidex Attack Surface

Entry Points10
Unprotected0

AJAX Handlers 9

authwp_ajax_pidex_verify_merchant_idincludes/Ajax.php:57
authwp_ajax_pidex_submit_settingsincludes/Ajax.php:58
authwp_ajax_pidex_fetch_merchant_cityincludes/Ajax.php:63
authwp_ajax_pidex_fetch_citiesincludes/Ajax.php:64
authwp_ajax_pidex_fetch_zonesincludes/Ajax.php:65
authwp_ajax_pidex_fetch_delivery_typesincludes/Ajax.php:66
authwp_ajax_pidex_place_order_metabox_formincludes/Ajax.php:67
authwp_ajax_pidex_submit_trackingincludes/Ajax.php:68
noprivwp_ajax_pidex_submit_trackingincludes/Ajax.php:69

Shortcodes 1

[pidex_tracker] includes/Frontend/PidexTrackerShortcode.php:25
WordPress Hooks 11
actionplugins_loadedPidex.php:84
actionwoocommerce_thankyouPidex.php:105
actionactivated_pluginPidex.php:109
actionadmin_enqueue_scriptsPidex.php:187
actionadmin_enqueue_scriptsPidex.php:192
actionadmin_menuincludes/Admin/Menu.php:42
actionadd_meta_boxesincludes/Admin/PidexPlaceOrderMetabox.php:38
actionadmin_enqueue_scriptsincludes/Assets.php:29
actionwp_enqueue_scriptsincludes/Assets.php:31
actioninitincludes/PidexOrderStatusShippedToPidex.php:32
filterwc_order_statusesincludes/PidexOrderStatusShippedToPidex.php:33
Maintenance & Trust

Pidex Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedAug 7, 2023
PHP min version7.4
Downloads737

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Pidex Developer Profile

Pidex Infosys

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Pidex

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pidex/assets/css/admin-menu-style.css/wp-content/plugins/pidex/assets/css/pidex-admin-style.css/wp-content/plugins/pidex/assets/css/pidex-woocommerce-order-status-style.css/wp-content/plugins/pidex/assets/js/pidex-admin-script.js/wp-content/plugins/pidex/assets/js/pidex-frontend-script.js
Script Paths
/wp-content/plugins/pidex/assets/js/pidex-admin-script.js/wp-content/plugins/pidex/assets/js/pidex-frontend-script.js
Version Parameters
pidex/assets/css/admin-menu-style.css?ver=pidex/assets/css/pidex-admin-style.css?ver=pidex/assets/css/pidex-woocommerce-order-status-style.css?ver=pidex/assets/js/pidex-admin-script.js?ver=pidex/assets/js/pidex-frontend-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
pidex-admin-menupidex-woocommerce-order-status-badge
HTML Comments
<!-- Add WooCommerce Status Badge Style --><!-- Add Admin Menu Style --><!-- Load admin classes. --><!-- Load Frontend classes. -->+1 more
Data Attributes
data-pidex-nonce
JS Globals
pidex_data
Shortcode Output
[pidex_tracker]
FAQ

Frequently Asked Questions about Pidex