Shipway Experience – Tracking & Notification Security & Risk Analysis
wordpress.org/plugins/shipway-shipment-tracking-and-notifyShipway Experience provides shipment tracking and notification services along with features like Branded Tracking Page, Feedback collection and widget …
Is Shipway Experience – Tracking & Notification Safe to Use in 2026?
Generally Safe
Score 85/100Shipway Experience – Tracking & Notification has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The shipway-shipment-tracking-and-notify v3.0 plugin exhibits a generally positive security posture based on the static analysis. The absence of any identified vulnerabilities in its history, combined with zero critical or high severity taint flows, suggests a well-maintained codebase. Furthermore, the plugin has a minimal attack surface with only one shortcode and no AJAX handlers or REST API routes requiring authentication, which is a good practice for reducing exposure. However, there are significant areas of concern regarding data handling and authorization. The fact that 100% of SQL queries are not using prepared statements is a critical risk, potentially leading to SQL injection vulnerabilities. Coupled with a very low percentage of properly escaped output (18%), this indicates a high likelihood of cross-site scripting (XSS) vulnerabilities. The complete absence of nonce and capability checks is alarming, meaning that any authenticated user, regardless of their role, could potentially trigger sensitive actions or view restricted data through the shortcode or other unmonitored entry points.
Key Concerns
- SQL queries without prepared statements
- Low percentage of output escaping
- No nonce checks
- No capability checks
Shipway Experience – Tracking & Notification Security Vulnerabilities
Shipway Experience – Tracking & Notification Code Analysis
SQL Query Safety
Output Escaping
Shipway Experience – Tracking & Notification Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Shipway Experience – Tracking & Notification Maintenance & Trust
Maintenance Signals
Community Trust
Shipway Experience – Tracking & Notification Alternatives
Advanced Shipment Tracking for WooCommerce
woo-advanced-shipment-tracking
Add shipment tracking info to WooCommerce orders, send tracking numbers to customers via email, and let them track deliveries from My Account.
Shiprocket
shiprocket
Auto Sync your Woocommerce store orders & ship them at lowest shipping rates. Automate your shipping, save time & money.
AfterShip Tracking – All-In-One WooCommerce Order Tracking (Free plan available)
aftership-woocommerce-tracking
Track orders in one place. shipment tracking, automated notifications, order lookup, branded tracking page, delivery day prediction
YITH WooCommerce Order & Shipment Tracking
yith-woocommerce-order-tracking
Add an easy tool to manage order shipping information of your shop and to notified your customers about the shipping.
Sendcloud Shipping
sendcloud-connected-shipping
SendCloud helps to grow your online store by optimizing the shipping process. Shipping packages has never been that easy!
Shipway Experience – Tracking & Notification Developer Profile
2 plugins · 200 total installs
How We Detect Shipway Experience – Tracking & Notification
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shipway-shipment-tracking-and-notify/assets/css/shipway.css/wp-content/plugins/shipway-shipment-tracking-and-notify/assets/js/shipway.js/wp-content/plugins/shipway-shipment-tracking-and-notify/assets/js/shipway.jsHTML / DOM Fingerprints
shipwayshipway-tracking-formdata-shipway-carrier-iddata-shipway-awbdata-shipway-order-idshipway_tracking_ajax_object/wp-json/shipway-tracking/v1/track<form id="shipway" class="shipway" action="" method="POST">