
Qiriman Security & Risk Analysis
wordpress.org/plugins/qirimanQiriman is a WooCommerce plugin that provide shipping method from various expedition in Indonesia.
Is Qiriman Safe to Use in 2026?
Generally Safe
Score 85/100Qiriman has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "qiriman" v1.0.4 plugin exhibits a significant security concern due to its unprotected AJAX handlers. While the plugin demonstrates good practices in terms of SQL query sanitization and output escaping, the presence of four AJAX entry points without any authentication or capability checks creates a substantial attack surface. This means any unauthenticated user could potentially interact with these handlers, leading to unintended consequences or exploitation. The absence of any recorded vulnerabilities in its history is a positive indicator, suggesting a history of secure development or at least a lack of publicly discovered flaws. However, this cannot compensate for the immediate and evident risk posed by the unprotected AJAX endpoints. The plugin's strengths lie in its internal code hygiene for SQL and output, but the external-facing unprotected AJAX handlers represent a critical weakness that needs immediate attention.
Key Concerns
- Unprotected AJAX handlers
- Large attack surface without auth
- Missing nonce checks on AJAX
- Missing capability checks on AJAX
Qiriman Security Vulnerabilities
Qiriman Code Analysis
Qiriman Attack Surface
AJAX Handlers 4
WordPress Hooks 13
Maintenance & Trust
Qiriman Maintenance & Trust
Maintenance Signals
Community Trust
Qiriman Alternatives
Epeken All Kurir for Woocommerce
epeken-all-kurir
Epeken All Kurir is a wordpress plugin for woocommerce to enable shipping method featuring many shipping companies for Indonesia e-commerce.
Shipping Discount for WooCommerce: Easy Make a Coupon for Shipping
shipping-discount
Want to make a strikeout price for shipping? It's easy to use the shipping discount plugin, all you have to do is set the shipping discount you w …
WooWIB – Payment Gateways Bank Indonesia
woo-payment-gateways-bank-indo-kode-payment
WooWIB - Payment Gateways Bank Indonesia plugin with 3 digits code payment
JNE Shipping – Plugin Ongkos Kirim Resmi Untuk WooCommerce
jne-shipping-official
Plugin pengiriman JNE resmi untuk WooCommerce di Indonesia. Menyediakan tarif real-time, pembuatan AWB, dan pelacakan pengiriman.
Brankas Payment for WooCommerce
brankas-payment-for-woocommerce
Brankas Direct plugin enables instant Account-to-Account fund transfers as a payment
Qiriman Developer Profile
1 plugin · 10 total installs
How We Detect Qiriman
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/qiriman/admin/css/qiriman-admin.css/wp-content/plugins/qiriman/admin/js/qiriman-admin.js/wp-content/plugins/qiriman/admin/js/qiriman-admin.jsqiriman-admin?ver=qiriman_admin?ver=HTML / DOM Fingerprints
data-qiriman-nonceqiriman_ajax