PKT1 Centro de envios Security & Risk Analysis

wordpress.org/plugins/pkt1-centro-de-envios

Calcule tarifas de envio en tiempo real con los principales agentes de paqueteria regionales y mundiales

40 active installs v1.2.5 PHP 7.0.33+ WP 4.0+ Updated Aug 21, 2025
chileenviosmexicoregioneswoocommerce
99
A · Safe
CVEs total1
Unpatched0
Last CVEDec 19, 2024
Safety Verdict

Is PKT1 Centro de envios Safe to Use in 2026?

Generally Safe

Score 99/100

PKT1 Centro de envios has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Dec 19, 2024Updated 7mo ago
Risk Assessment

The "pkt1-centro-de-envios" plugin v1.2.5 exhibits a mixed security posture. While it demonstrates good practices in areas like using prepared statements for SQL queries and a high percentage of properly escaped output, significant concerns remain. The presence of two unprotected AJAX handlers presents a substantial attack surface, allowing unauthenticated users to potentially trigger plugin functionality. Furthermore, the use of the `unserialize` function is a critical risk, as it can lead to Remote Code Execution if not handled with extreme care and input validation, especially when dealing with user-controlled data. The taint analysis showing unsanitized paths, although not reaching critical or high severity in this scan, is a strong indicator of potential vulnerabilities in data handling.

The plugin's vulnerability history, though currently showing no unpatched CVEs, reveals a past medium-severity Cross-Site Scripting (XSS) vulnerability. This pattern suggests that the plugin has had issues with improper input neutralization in the past, which aligns with the identified potential for unsanitized paths in the taint analysis. While the current version has addressed past vulnerabilities, the remaining unprotected entry points and the use of `unserialize` indicate a need for further security hardening. The plugin has some strengths in secure SQL handling and output escaping, but the risks associated with its entry points and dangerous function usage are noteworthy.

Key Concerns

  • Unprotected AJAX handlers
  • Use of unserialize function
  • Flows with unsanitized paths
  • Past medium severity CVE (XSS)
Vulnerabilities
1

PKT1 Centro de envios Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-11806medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

PKT1 Centro de envios <= 1.2.1 - Reflected Cross-Site Scripting

Dec 19, 2024 Patched in 1.2.2 (43d)
Code Analysis
Analyzed Mar 16, 2026

PKT1 Centro de envios Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
17
80 escaped
Nonce Checks
1
Capability Checks
1
File Operations
14
External Requests
10
Bundled Libraries
0

Dangerous Functions Found

unserializereturn unserialize($_SESSION[$session_name]);classes\Pkt1.php:44

Output Escaping

82% escaped97 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
pkt1_settings_page_callback (views\admin\settings_page.php:8)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

PKT1 Centro de envios Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_pkt1_checksaldo_ajax_actionpkt1_root.php:75
authwp_ajax_pkt1_checksaldo_ajax_actionpkt1_root.php:76

Shortcodes 1

[pkt1] pkt1_root.php:116
WordPress Hooks 27
actionadmin_enqueue_scriptspkt1_root.php:53
actionwp_enqueue_scriptspkt1_root.php:62
actioninitpkt1_root.php:106
actioninitpkt1_root.php:107
actionwppkt1_root.php:108
actionadmin_menupkt1_root.php:109
actionadmin_post_pkt1_save_settings_fieldpkt1_root.php:110
actionwoocommerce_shipping_initpkt1_root.php:684
filterwoocommerce_shipping_methodspkt1_root.php:690
filterwoocommerce_shipping_calculator_enable_postcodepkt1_root.php:715
filterwoocommerce_cart_shipping_method_full_labelpkt1_root.php:903
actionwoocommerce_order_status_processingpkt1_root.php:1475
actionwoocommerce_order_status_completedpkt1_root.php:1476
filtermanage_edit-shop_order_columnspkt1_root.php:1480
actionmanage_shop_order_posts_custom_columnpkt1_root.php:1499
actionadmin_footerpkt1_root.php:1684
actionwp_footerpkt1_root.php:1699
filterwoocommerce_default_address_fieldspkt1_root.php:1701
actionwoocommerce_after_checkout_validationpkt1_root.php:1731
filterwoocommerce_checkout_fieldspkt1_root.php:1756
filterwoocommerce_default_address_fieldspkt1_root.php:2020
filterwoocommerce_citiespkt1_root.php:2056
filterwoocommerce_statespkt1_root.php:2086
filterwoocommerce_package_ratespkt1_root.php:2113
filterwoocommerce_shipping_chosen_methodpkt1_root.php:2122
actionwoocommerce_checkout_update_order_reviewpkt1_root.php:2125
filterwoocommerce_cart_shipping_packagespkt1_root.php:2153
Maintenance & Trust

PKT1 Centro de envios Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 21, 2025
PHP min version7.0.33
Downloads6K

Community Trust

Rating100/100
Number of ratings1
Active installs40
Developer Profile

PKT1 Centro de envios Developer Profile

carlosfrancopkt1

1 plugin · 40 total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
43 days
View full developer profile
Detection Fingerprints

How We Detect PKT1 Centro de envios

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pkt1-centro-de-envios/assets/css/style.css/wp-content/plugins/pkt1-centro-de-envios/assets/js/main.js/wp-content/plugins/pkt1-centro-de-envios/assets/js/ajax.js
Script Paths
/wp-content/plugins/pkt1-centro-de-envios/assets/js/main.js/wp-content/plugins/pkt1-centro-de-envios/assets/js/ajax.js
Version Parameters
/wp-content/plugins/pkt1-centro-de-envios/assets/js/main.js?ver=/wp-content/plugins/pkt1-centro-de-envios/assets/js/ajax.js?ver=/wp-content/plugins/pkt1-centro-de-envios/assets/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
pkt1-logo
HTML Comments
<!-- Daniel Higuera 2025/08/19 --><!-- evitamos Co2 --><!-- llega a mas lugares --><!-- PKT1 Centro de Envíos -->+1 more
Data Attributes
data-tabdata-tab-content
JS Globals
pkt1_ajax_urlpkt1_core_params
Shortcode Output
[pkt1][pkt1_products]
FAQ

Frequently Asked Questions about PKT1 Centro de envios