Shipment Tracking DDT for WooCommerce Security & Risk Analysis

wordpress.org/plugins/shipment-tracking-ddt-for-woocommerce

Add your Tracking code to WooCommerce orders and attach the DDT/Packing slip!

10 active installs v1.5.4 PHP 8.0+ WP 6.0.1+ Updated Unknown
ddtshipmenttrackingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Shipment Tracking DDT for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Shipment Tracking DDT for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "shipment-tracking-ddt-for-woocommerce" plugin version 1.5.4 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests are all positive indicators. The high percentage of properly escaped output and the presence of nonce and capability checks further bolster its security. The attack surface is minimal and, importantly, all identified entry points appear to have proper authorization checks.

No vulnerabilities were found during the taint analysis, which is an excellent sign. The lack of any recorded CVEs in its history also suggests a history of secure development or proactive patching by the developers. Overall, this plugin appears to be developed with security in mind, demonstrating good practices and a low risk profile. There are no immediate security concerns evident from the provided data.

Vulnerabilities
None known

Shipment Tracking DDT for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Shipment Tracking DDT for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
112 escaped
Nonce Checks
5
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

97% escaped115 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
hwit_stddt_save_tracking_settings (includes\wc-admin-options.php:81)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Shipment Tracking DDT for WooCommerce Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_ddt_pdf_uploadhw-shipment-tracking-ddt-for-woocommerce.php:389
authwp_ajax_delete_filehw-shipment-tracking-ddt-for-woocommerce.php:486
WordPress Hooks 28
actionadmin_noticeshw-shipment-tracking-ddt-for-woocommerce.php:63
actionadmin_enqueue_scriptshw-shipment-tracking-ddt-for-woocommerce.php:78
actionwoocommerce_loadedhw-shipment-tracking-ddt-for-woocommerce.php:88
actionadd_meta_boxeshw-shipment-tracking-ddt-for-woocommerce.php:91
actionwoocommerce_process_shop_order_metahw-shipment-tracking-ddt-for-woocommerce.php:95
actionwoocommerce_process_shop_order_metahw-shipment-tracking-ddt-for-woocommerce.php:98
actionadmin_footerhw-shipment-tracking-ddt-for-woocommerce.php:272
filterupload_dirhw-shipment-tracking-ddt-for-woocommerce.php:456
filterwoocommerce_email_classeshw-shipment-tracking-ddt-for-woocommerce.php:522
filterwoocommerce_email_actionshw-shipment-tracking-ddt-for-woocommerce.php:543
filterwoocommerce_order_actionshw-shipment-tracking-ddt-for-woocommerce.php:552
actionwoocommerce_order_action_send_ddt_emailhw-shipment-tracking-ddt-for-woocommerce.php:563
actionwoocommerce_order_action_send_shipped_emailhw-shipment-tracking-ddt-for-woocommerce.php:575
actionbefore_woocommerce_inithw-shipment-tracking-ddt-for-woocommerce.php:586
actionwoocommerce_order_status_shipped_notificationincludes\class-wc-email-shipped.php:30
filterwoocommerce_settings_tabs_arrayincludes\wc-admin-options.php:7
actionwoocommerce_settings_tabs_trackingincludes\wc-admin-options.php:14
actionwoocommerce_update_options_trackingincludes\wc-admin-options.php:79
filtermanage_woocommerce_page_wc-orders_columnsincludes\wc-admin-options.php:152
actionmanage_woocommerce_page_wc-orders_custom_columnincludes\wc-admin-options.php:175
filtermanage_edit-shop_order_columnsincludes\wc-admin-options.php:189
actionmanage_shop_order_posts_custom_columnincludes\wc-admin-options.php:211
filterwoocommerce_account_orders_columnsincludes\wc-frontend-functions.php:4
actionwoocommerce_my_account_my_orders_column_tracking-ddtincludes\wc-frontend-functions.php:19
actionwoocommerce_order_details_after_order_tableincludes\wc-frontend-functions.php:66
actioninitincludes\wc-shipped-status-functions.php:5
filterwc_order_statusesincludes\wc-shipped-status-functions.php:21
filterwc_order_is_editableincludes\wc-shipped-status-functions.php:32
Maintenance & Trust

Shipment Tracking DDT for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedUnknown
PHP min version8.0
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Shipment Tracking DDT for WooCommerce Developer Profile

giangel84

5 plugins · 1K total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Shipment Tracking DDT for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shipment-tracking-ddt-for-woocommerce/assets/css/hw-shipment-tracking-ddt-for-woocommerce.css
Version Parameters
shipment-tracking-ddt-for-woocommerce/assets/css/hw-shipment-tracking-ddt-for-woocommerce.css?ver=

HTML / DOM Fingerprints

CSS Classes
hwit_stddt_ddt_tracking_sent_wrapperhwit_stddt_tracking_sent_wrapperhwit_stddt_tracking_sent_messagehwit_stddt_tracking_not_sent_wrapperhwit_stddt_tracking_not_sent_messagehwit_stddt_ddt_sent_wrapperhwit_stddt_ddt_sent_messagehwit_stddt_ddt_not_sent_wrapper+2 more
HTML Comments
translator: datetime format to show DDT Sent date/time.
Data Attributes
name="hw_shipment_tracking_ddt_info_nonce"
FAQ

Frequently Asked Questions about Shipment Tracking DDT for WooCommerce