
ShipDepot for WooCommerce Security & Risk Analysis
wordpress.org/plugins/ship-depotGiải pháp tích hợp giao hàng toàn diện với hàng loạt tiện ích: - Tích hợp các nhà vận chuyển hàng đầu tại Việt Nam (GHN, GHTK, Ahamove và nhiều khác) …
Is ShipDepot for WooCommerce Safe to Use in 2026?
Mostly Safe
Score 71/100ShipDepot for WooCommerce is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved.
The "ship-depot" plugin version 1.2.19 presents a significant security risk due to a large number of unprotected entry points. All 12 AJAX handlers and 10 REST API routes lack authorization checks, creating a broad attack surface where any unauthenticated user could potentially interact with sensitive plugin functionalities. While the plugin demonstrates good practices in other areas, such as using prepared statements for SQL queries and a high percentage of properly escaped output, the absence of authorization on its primary interaction points is a critical flaw. The vulnerability history, including a known medium-severity CVE related to missing authorization, reinforces this concern and suggests a recurring pattern of insecure access control implementation within the plugin.
The taint analysis shows a limited number of flows and none with critical or high severity, which is a positive indicator. However, the presence of 2 flows with unsanitized paths, even if not flagged as critical in the current analysis, warrants careful investigation as they could lead to unexpected behavior or vulnerabilities if exploited in conjunction with other weaknesses. The plugin's reliance on explicit capability checks for only 2 instances further highlights the overall deficiency in robust access control mechanisms. In conclusion, while the plugin has some strengths in data handling, the pervasive lack of authentication and authorization on its entry points makes it highly vulnerable to exploitation, necessitating immediate attention to secure these areas.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- Unpatched CVE (medium severity)
- Flows with unsanitized paths
- Limited capability checks
ShipDepot for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
ShipDepot for WooCommerce <= 1.2.19 - Missing Authorization
ShipDepot for WooCommerce Release Timeline
ShipDepot for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
ShipDepot for WooCommerce Attack Surface
AJAX Handlers 12
REST API Routes 10
WordPress Hooks 69
Maintenance & Trust
ShipDepot for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
ShipDepot for WooCommerce Alternatives
VNShipping for WooCommerce
vnshipping-for-woocommerce
Tích hợp các nhà vận chuyển tại Việt Nam cho WooCommerce.
Plugin Ongkos Kirim JNE Tiki Sicepat Wahana J&T POS for Woocommerce
ongkoskirim-id
OngkosKirim.id merupakan plugin ongkos kirim woocommerce dengan fitur terkomplit dan ekspedisi terlengkap, meliputi JNE, TIKI, POS, J&T, Sicepat, …
Shippit for WooCommerce
shippit-simplified-australia-shipping
Multi-carrier shipping technology.
Shipit
shipit
Shipit Calculator Mensajeros de envío
Woot
woot-ro
Unified shipping solution for WooCommerce. Integrates all popular couriers in Romania with real-time pricing and pickup point selection.
ShipDepot for WooCommerce Developer Profile
1 plugin · 10 total installs
How We Detect ShipDepot for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ship-depot/assets/js/admin-notices.js/wp-content/plugins/ship-depot/assets/js/admin-notices.jsship-depot/assets/js/admin-notices.js?ver=HTML / DOM Fingerprints
vf-noticedata-dismiss-urlSHIP_DEPOT_DIR_URLSHIP_DEPOT_VERSION