
Portugal VASP Expresso Kios network for WooCommerce Security & Risk Analysis
wordpress.org/plugins/portugal-vasp-kios-woocommerceLets you deliver on the VASP Expresso Kios network of partners in Portugal. This is not a shipping method. This is an add-on for any WooCommerce shipp …
Is Portugal VASP Expresso Kios network for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Portugal VASP Expresso Kios network for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "portugal-vasp-kios-woocommerce" plugin v3.1 exhibits a generally good security posture based on the provided static analysis. The plugin demonstrates strong practices by avoiding dangerous functions, performing a reasonable percentage of SQL queries using prepared statements, and properly escaping a high majority of output. Furthermore, the absence of file operations and external HTTP requests are positive indicators. The plugin's attack surface appears minimal, with no identified AJAX handlers, REST API routes, or shortcodes that are unprotected. The vulnerability history is also a significant strength, showing zero known CVEs, which suggests a well-maintained and secure codebase over time.
However, there are notable areas for improvement. The presence of 0 capability checks and 0 nonce checks across all entry points is a critical concern. This means that even though the number of entry points is low, any functionality exposed through these points lacks essential authorization and integrity checks. The taint analysis revealing one flow with unsanitized paths, while not classified as critical or high severity, warrants attention. This could indicate a potential for vulnerabilities if the data within this flow is not handled with extreme care by other security measures not apparent in this report or if the sanitization is incomplete.
In conclusion, the plugin has a solid foundation with good coding practices in place for SQL and output handling, and a commendable history of security. The major weakness lies in the complete lack of capability and nonce checks on its entry points, which significantly increases the risk of unauthorized access or manipulation. Addressing these missing security checks should be a priority to further harden the plugin.
Key Concerns
- No capability checks present
- No nonce checks present
- Flow with unsanitized paths detected
- SQL queries not fully prepared
- Output not fully escaped
Portugal VASP Expresso Kios network for WooCommerce Security Vulnerabilities
Portugal VASP Expresso Kios network for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Portugal VASP Expresso Kios network for WooCommerce Attack Surface
WordPress Hooks 23
Scheduled Events 1
Maintenance & Trust
Portugal VASP Expresso Kios network for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Portugal VASP Expresso Kios network for WooCommerce Alternatives
CDEKDelivery
cdekdelivery
Integration with CDEK delivery for your WooCommerce store.
Flat Rate per State/Country/Region for WooCommerce
flat-rate-per-countryregion-for-woocommerce
This plugin allows you to set a flat delivery rate per States, Countries or World Regions on WooCommerce.
Amadast Shipping افزونه حمل و نقل |ماشین حساب ارسال پست و تیپاکس و چاپار | پس کرایه |تنظیمات ارسال رایگان
amadast-shipping-wp
A plugin that calculates shipping prices online with various sending methods.
Shipping Additional Days for WooCommerce
woo-shipping-additional-days
Allows you to set additional days to your delivery date into Products and Shipping Classes.
Kwik Delivery for Woocommerce
kwik-delivery-for-wcommerce
A Kwik Delivery integration for Woocommerce, including real time shipping rates, order scheduling and tracking updates.
Portugal VASP Expresso Kios network for WooCommerce Developer Profile
21 plugins · 27K total installs
How We Detect Portugal VASP Expresso Kios network for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/portugal-vasp-kios-woocommerce/assets/style.css/wp-content/plugins/portugal-vasp-kios-woocommerce/assets/style-flatsome.css/wp-content/plugins/portugal-vasp-kios-woocommerce/assets/functions.js/wp-content/plugins/portugal-vasp-kios-woocommerce/assets/functions.jsportugal-vasp-kios-woocommerce/assets/style.css?ver=portugal-vasp-kios-woocommerce/assets/style-flatsome.css?ver=portugal-vasp-kios-woocommerce/assets/functions.js?ver=HTML / DOM Fingerprints
name="pvkw"id="pvkw"name="pvkw_hide_shipping_address"id="pvkw_hide_shipping_address"name="pvkw_email_info"id="pvkw_email_info"+2 morepvkw