
Robonobo Shipping Security & Risk Analysis
wordpress.org/plugins/robonobo-shippingHandle your own local deliveries!
Is Robonobo Shipping Safe to Use in 2026?
Generally Safe
Score 100/100Robonobo Shipping has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The robonobo-shipping plugin version 1.0.4 exhibits a concerning security posture due to a significant number of unprotected entry points. While the plugin does not utilize dangerous functions, demonstrates a strong adherence to prepared statements for SQL queries, and shows a high percentage of properly escaped output, the lack of authentication checks on all AJAX handlers and the single REST API route presents a substantial risk. The presence of 4 unprotected entry points (3 AJAX handlers and 1 REST API route) means that any unauthenticated user could potentially interact with these plugin functionalities, leading to unintended consequences or exploitation.
Despite the absence of known vulnerabilities (CVEs) and no recorded critical or high severity taint flows, the foundational lack of security on its exposed endpoints is a major concern. The plugin's vulnerability history indicates a clean slate, which is positive, but it doesn't negate the risks identified in the static analysis. The plugin's strengths lie in its secure handling of database queries and output sanitization. However, these strengths are overshadowed by the critical weakness of leaving numerous entry points open to unauthenticated access. This necessitates immediate attention to implement proper authentication and authorization checks for all exposed handlers and routes.
Key Concerns
- AJAX handlers without auth checks
- REST API routes without permission callbacks
- Large attack surface without auth
Robonobo Shipping Security Vulnerabilities
Robonobo Shipping Code Analysis
Output Escaping
Data Flow Analysis
Robonobo Shipping Attack Surface
AJAX Handlers 3
REST API Routes 1
WordPress Hooks 11
Maintenance & Trust
Robonobo Shipping Maintenance & Trust
Maintenance Signals
Community Trust
Robonobo Shipping Alternatives
WooReer
wcsdm
WooReer calculates shipping rates based on distance via Google Maps, Mapbox, DistanceMatrix.ai, Geoapify, or HERE.
Calculate Prices based on Distance For WooCommerce
calculate-prices-based-on-distance-for-woocommerce
The best WooCommerce Distance Rate Shipping alternative. Secure delivery fee calculation by KM/Mile via Google Maps. Supports Block Checkout & Del …
Smart COD for WooCommerce
wc-smart-cod
All the COD restrictions and extra fees you'll ever need, in a single plugin.
Claudio Sanches – Correios for WooCommerce
woocommerce-correios
Integration between the Correios and WooCommerce
Print Invoice & Delivery Notes for WooCommerce
woocommerce-delivery-notes
Create and print PDF invoices, delivery notes and receipts for your WooCommerce orders. Choose your document format from multiple templates.
Robonobo Shipping Developer Profile
1 plugin · 0 total installs
How We Detect Robonobo Shipping
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/robonobo-shipping/js/robonobo-rates-by-weights.js/wp-content/plugins/robonobo-shipping/js/robonobo-rates-by-weights.jsrobonobo-shipping/js/robonobo-rates-by-weights.js?ver=HTML / DOM Fingerprints
id="robonobo-weight-rates-ui"window.robonobo_weight_rateswindow.robonobo_weight_rates_nonce