
Shipping & Delivery Date management with gift message Security & Risk Analysis
wordpress.org/plugins/shipping-delivery-date-management-with-gift-messageThis will add additional feature to allow your customer to put delivery date and address with some gift message of their own choice per product.
Is Shipping & Delivery Date management with gift message Safe to Use in 2026?
Generally Safe
Score 85/100Shipping & Delivery Date management with gift message has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "shipping-delivery-date-management-with-gift-message" plugin v2.0.0 exhibits a concerning security posture primarily due to its unprotected entry points. The static analysis reveals three AJAX handlers, all of which lack authentication checks. This represents a significant attack surface where unauthenticated users could potentially trigger unintended actions or access sensitive data. While the plugin demonstrates good practices in other areas, such as the absence of dangerous functions, 100% prepared statement usage for SQL queries, and no file operations or external HTTP requests, the unprotected AJAX endpoints are a critical weakness. The lack of taint analysis flows and a clean vulnerability history are positive signs, suggesting the plugin might not have a history of exploitable flaws. However, this does not mitigate the immediate risk posed by the exposed AJAX handlers. The plugin's strengths in other areas are overshadowed by this fundamental security oversight. A balanced conclusion is that while the plugin avoids common pitfalls like SQL injection and insecure file handling, the significant number of unprotected AJAX actions necessitates immediate attention and remediation to prevent potential compromise.
Key Concerns
- Unprotected AJAX handlers
- Missing nonce checks on AJAX
- Low output escaping percentage
- Missing capability checks on AJAX
Shipping & Delivery Date management with gift message Security Vulnerabilities
Shipping & Delivery Date management with gift message Code Analysis
Output Escaping
Shipping & Delivery Date management with gift message Attack Surface
AJAX Handlers 3
WordPress Hooks 14
Maintenance & Trust
Shipping & Delivery Date management with gift message Maintenance & Trust
Maintenance Signals
Community Trust
Shipping & Delivery Date management with gift message Alternatives
Shipping & Delivery Date management with gift message Developer Profile
21 plugins · 5K total installs
How We Detect Shipping & Delivery Date management with gift message
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shipping-delivery-date-management-with-gift-message/assets/css/frontend/delivery_date_style.css/wp-content/plugins/shipping-delivery-date-management-with-gift-message/assets/js/frontend/delivery_date_script.js/wp-content/plugins/shipping-delivery-date-management-with-gift-message/assets/js/frontend/delivery_date_script.js/wp-content/plugins/shipping-delivery-date-management-with-gift-message/assets/css/frontend/delivery_date_style.css?ver=/wp-content/plugins/shipping-delivery-date-management-with-gift-message/assets/js/frontend/delivery_date_script.js?ver=HTML / DOM Fingerprints
delivery-date-calenderdelivery_date_fielddata-delivery_date_tooltipdata-delivery_date_urldata-delivery_date_formatdata-delivery_date_noncedata-product_idced_sadc_delivery_date_obj