
RT Deliveries Security & Risk Analysis
wordpress.org/plugins/rtdeliveriesIntegrate WooCommerce with Road Train Deliveries (RTD) for automated shipping, tracking, and order syncing.
Is RT Deliveries Safe to Use in 2026?
Generally Safe
Score 100/100RT Deliveries has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The rtdeliveries plugin v1.0.0 exhibits a generally good security posture, with no known historical vulnerabilities and a strong emphasis on input validation and access control for its entry points. The plugin correctly implements nonce and capability checks on all identified AJAX handlers and REST API routes, significantly reducing the risk of unauthorized access or actions. Furthermore, the vast majority of output is properly escaped, and there are no dangerous function calls or file operations that could be easily exploited. The plugin also avoids bundling external libraries, simplifying its maintenance and reducing the risk of inherited vulnerabilities from outdated components.
However, the static analysis does reveal some areas for improvement. Specifically, the taint analysis identified two high-severity flows with unsanitized paths, indicating a potential for path traversal vulnerabilities if these flows are not handled with extreme care. Additionally, while 50% of SQL queries use prepared statements, the remaining 50% do not, presenting a risk of SQL injection if the unsanitized inputs are directly used in database queries. These findings, despite the overall strong security practices, warrant attention to prevent potential exploits.
In conclusion, rtdeliveries v1.0.0 is a well-secured plugin with no known public vulnerabilities. Its implementation of security best practices for entry points and output handling is commendable. The primary concerns lie within the identified taint flows and the use of raw SQL queries. Addressing these specific issues would further strengthen the plugin's security and eliminate potential avenues for attack.
Key Concerns
- High severity unsanitized path taint flows
- SQL queries not using prepared statements
RT Deliveries Security Vulnerabilities
RT Deliveries Release Timeline
RT Deliveries Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
RT Deliveries Attack Surface
AJAX Handlers 2
REST API Routes 1
WordPress Hooks 7
Maintenance & Trust
RT Deliveries Maintenance & Trust
Maintenance Signals
Community Trust
RT Deliveries Alternatives
Shiprocket
shiprocket
Auto Sync your Woocommerce store orders & ship them at lowest shipping rates. Automate your shipping, save time & money.
Local Delivery Drivers for WooCommerce
local-delivery-drivers-for-woocommerce
Improve the way you deliver, manage drivers, assign drivers to orders, send WhatsApp, SMS, and email notifications, route planning, navigation & more!
Woot
woot-ro
Unified shipping solution for WooCommerce. Integrates all popular couriers in Romania with real-time pricing and pickup point selection.
Uber Direct Integration
uber-direct-delivery-integration
Offer instant or scheduled delivery from your WooCommerce store with real-time quotes and Uber Direct integration
NCM API
ncm-api
Connect WooCommerce orders with Nepal Can Move and manage delivery operations directly from WordPress.
RT Deliveries Developer Profile
1 plugin · 0 total installs
How We Detect RT Deliveries
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rtdeliveries/assets/css/style.css/wp-content/plugins/rtdeliveries/assets/js/admin-order-list.js/wp-content/plugins/rtdeliveries/assets/js/admin-order-list.jsrtdeliveries/assets/css/style.css?ver=rtdeliveries/assets/js/admin-order-list.js?ver=HTML / DOM Fingerprints
rtdeliveriesData