
Sherpa Delivery for WooCommerce Security & Risk Analysis
wordpress.org/plugins/sherpa-on-demandConnects your WooCommerce store to your Sherpa Delivery account. Automated same day (and future day) local delivery for Australian businesses.
Is Sherpa Delivery for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100Sherpa Delivery for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sherpa-on-demand" v3.1 plugin presents a mixed security posture. The absence of any recorded historical vulnerabilities (CVEs) is a strong positive indicator of responsible development and maintenance. Furthermore, the plugin does not bundle any external libraries, which can often introduce security risks if not kept up-to-date.
However, the static analysis reveals notable concerns. A significant portion of the plugin's attack surface, specifically 4 out of 17 AJAX handlers, lack authentication checks. This is a critical oversight, as it could allow unauthenticated users to trigger sensitive actions or expose information. While there are no critical or high severity taint flows, the presence of one flow with unsanitized paths warrants attention, as it could potentially lead to vulnerabilities if combined with other exploitable conditions. The low rate of output escaping (33%) is also a concern, increasing the risk of cross-site scripting (XSS) vulnerabilities.
In conclusion, while the plugin benefits from a clean vulnerability history, the identified weaknesses in authentication for AJAX handlers and output escaping are significant and require immediate attention. The taint analysis suggests a lower immediate risk of critical vulnerabilities but highlights the need for careful code review in those identified flows.
Key Concerns
- Unprotected AJAX handlers
- Low output escaping rate
- Flow with unsanitized paths
Sherpa Delivery for WooCommerce Security Vulnerabilities
Sherpa Delivery for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Sherpa Delivery for WooCommerce Attack Surface
AJAX Handlers 17
WordPress Hooks 42
Maintenance & Trust
Sherpa Delivery for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Sherpa Delivery for WooCommerce Alternatives
Delivery & Pickup Date Time for WooCommerce
woo-delivery
Gives the facility of selecting delivery/pickup/both date/time/both at order checkout page.
PiWeb Flat rate / Conditional shipping for WooCommerce
advanced-free-flat-shipping-woocommerce
WooCommerce conditional shipping & WooCommerce Advanced Flat rate shipping rates plugin to Create Advanced Flat rate shipping or Free shipping met …
Order Delivery Date And Time
order-delivery-date-and-time
Order Delivery Date And Time plugin lets customers select delivery/pickup dates and times at checkout page.
Chwazi – Delivery & Pickup Scheduling for WooCommerce
delivery-and-pickup-scheduling-for-woocommerce
Empower customers to select their preferred delivery or pickup time using a convenient datetime picker integrated into the WooCommerce checkout page.
WooODT Lite – Delivery & pickup date time location for WooCommerce
byconsole-woo-order-delivery-time
WooODT Lite is a WooCommerce Delivery & Pickup Date Time extension that gives the facility of selecting delivery/pickup date and time/time slot o …
Sherpa Delivery for WooCommerce Developer Profile
1 plugin · 10 total installs
How We Detect Sherpa Delivery for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sherpa-on-demand/css/sherpa_checkout.css/wp-content/plugins/sherpa-on-demand/css/sherpa_frontend.css/wp-content/plugins/sherpa-on-demand/js/sherpa_frontend.js/wp-content/plugins/sherpa-on-demand/js/sherpa_admin.js/wp-content/plugins/sherpa-on-demand/js/sherpa_frontend.js/wp-content/plugins/sherpa-on-demand/js/sherpa_admin.jssherpa-on-demand/css/sherpa_checkout.css?ver=sherpa-on-demand/css/sherpa_frontend.css?ver=sherpa-on-demand/js/sherpa_frontend.js?ver=sherpa-on-demand/js/sherpa_admin.js?ver=HTML / DOM Fingerprints
sherpa_delivery_optionssherpa-delivery-options-selectdata-sherpa-settingdata-sherpa-delivery-options-urlsherpa_paramssherpa_frontend_params