Simple Connection for ChronoFresh Security & Risk Analysis

wordpress.org/plugins/simple-connection-for-chronofresh-woocommerce

Seamless Chronopost/Chronofresh shipping with WooCommerce, featuring secure pickup point selection.

10 active installs v1.0.3 PHP 7.4+ WP 5.8+ Updated Aug 25, 2025
chronofreshchronopostpickup-pointsshipping
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Simple Connection for ChronoFresh Safe to Use in 2026?

Generally Safe

Score 100/100

Simple Connection for ChronoFresh has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The "simple-connection-for-chronofresh-woocommerce" plugin version 1.0.3 demonstrates a strong security posture based on the provided static analysis. The plugin exhibits excellent adherence to secure coding practices, with 100% of SQL queries utilizing prepared statements and an exceptionally high rate of output escaping (99%). Furthermore, the presence of 15 nonce checks and 3 capability checks on its AJAX endpoints indicates a deliberate effort to protect against common attack vectors. The vulnerability history is clean, with no known CVEs, which is a significant positive indicator of the plugin's overall security maturity. The taint analysis also reveals no critical or high severity issues related to unsanitized data flows, further reinforcing its robust security.

While the plugin scores highly on many security metrics, the presence of 10 AJAX handlers, even with the noted security checks, represents a potential attack surface. Although the analysis states 0 unprotected AJAX handlers, a very large number of handlers, even if protected, can sometimes increase the complexity and the potential for misconfiguration or overlooked vulnerabilities. The 5 file operations and 1 external HTTP request are not inherently risky but warrant attention in any thorough audit to ensure they are implemented securely and do not expose unintended vulnerabilities. Overall, this plugin appears to be well-developed with security in mind, with a low risk profile, and its strengths significantly outweigh any minor concerns.

Key Concerns

  • 10 AJAX handlers present
  • 5 file operations
  • 1 external HTTP request
Vulnerabilities
None known

Simple Connection for ChronoFresh Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Simple Connection for ChronoFresh Release Timeline

v1.0.3Current
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Simple Connection for ChronoFresh Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
319 escaped
Nonce Checks
15
Capability Checks
3
File Operations
5
External Requests
1
Bundled Libraries
0

Output Escaping

99% escaped321 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

5 flows
handle_generate_label (includes/class-sccfcw-chronofresh-admin.php:111)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Simple Connection for ChronoFresh Attack Surface

Entry Points10
Unprotected0

AJAX Handlers 10

authwp_ajax_sccfcw_generate_labelincludes/class-sccfcw-chronofresh-admin.php:15
authwp_ajax_sccfcw_save_pickup_pointincludes/class-sccfcw-chronofresh-ajax.php:7
authwp_ajax_sccfcw_get_pickup_pointincludes/class-sccfcw-chronofresh-ajax.php:8
authwp_ajax_sccfcw_get_pickup_pointsincludes/class-sccfcw-chronofresh-ajax.php:9
authwp_ajax_sccfcw_save_pickup_pointincludes/class-sccfcw-chronofresh-frontend.php:14
noprivwp_ajax_sccfcw_save_pickup_pointincludes/class-sccfcw-chronofresh-frontend.php:15
authwp_ajax_sccfcw_get_pickup_pointincludes/class-sccfcw-chronofresh-frontend.php:16
noprivwp_ajax_sccfcw_get_pickup_pointincludes/class-sccfcw-chronofresh-frontend.php:17
authwp_ajax_sccfcw_get_pickup_pointsincludes/class-sccfcw-chronofresh-frontend.php:18
noprivwp_ajax_sccfcw_get_pickup_pointsincludes/class-sccfcw-chronofresh-frontend.php:19
WordPress Hooks 27
actionadmin_menuincludes/class-sccfcw-chronofresh-admin.php:9
actionadmin_initincludes/class-sccfcw-chronofresh-admin.php:10
actionwoocommerce_admin_order_actionsincludes/class-sccfcw-chronofresh-admin.php:11
actionadmin_post_sccfcw_generate_labelincludes/class-sccfcw-chronofresh-admin.php:12
actionadmin_post_sccfcw_test_connectionincludes/class-sccfcw-chronofresh-admin.php:13
actionadd_meta_boxesincludes/class-sccfcw-chronofresh-admin.php:14
actionadmin_enqueue_scriptsincludes/class-sccfcw-chronofresh-admin.php:16
actionadmin_footerincludes/class-sccfcw-chronofresh-admin.php:17
filterwoocommerce_order_is_block_compatibleincludes/class-sccfcw-chronofresh-admin.php:18
actionwoocommerce_product_options_shippingincludes/class-sccfcw-chronofresh-admin.php:19
actionwoocommerce_process_product_metaincludes/class-sccfcw-chronofresh-admin.php:20
actionadmin_noticesincludes/class-sccfcw-chronofresh-api.php:554
actionadmin_post_sccfcw_dismiss_review_noticeincludes/class-sccfcw-chronofresh-api.php:560
actionwoocommerce_after_shipping_rateincludes/class-sccfcw-chronofresh-frontend.php:9
filterwoocommerce_cart_shipping_packagesincludes/class-sccfcw-chronofresh-frontend.php:10
actionwoocommerce_checkout_update_order_reviewincludes/class-sccfcw-chronofresh-frontend.php:11
actionwoocommerce_checkout_create_orderincludes/class-sccfcw-chronofresh-frontend.php:12
actionwp_enqueue_scriptsincludes/class-sccfcw-chronofresh-frontend.php:13
actionadmin_post_sccfcw_export_logsincludes/class-sccfcw-chronofresh-logger.php:13
filterwoocommerce_shipping_methodsincludes/class-sccfcw-chronofresh-shipping.php:11
actionwoocommerce_checkout_update_order_metaincludes/class-sccfcw-chronofresh-shipping.php:49
actionwoocommerce_calculate_shippingincludes/class-sccfcw-chronofresh-shipping.php:50
actionadmin_noticessimple-connection-for-chronofresh-woocommerce.php:30
actionadmin_noticessimple-connection-for-chronofresh-woocommerce.php:36
actionplugins_loadedsimple-connection-for-chronofresh-woocommerce.php:67
actionadmin_noticessimple-connection-for-chronofresh-woocommerce.php:69
actionadmin_post_dismiss_sccfcw_premiumsimple-connection-for-chronofresh-woocommerce.php:75
Maintenance & Trust

Simple Connection for ChronoFresh Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 25, 2025
PHP min version7.4
Downloads404

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Simple Connection for ChronoFresh Developer Profile

Thomas Lloancy

11 plugins · 150 total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple Connection for ChronoFresh

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-connection-for-chronofresh-woocommerce/css/sccfcw-admin-style.css/wp-content/plugins/simple-connection-for-chronofresh-woocommerce/js/sccfcw-admin-script.js
Script Paths
/wp-content/plugins/simple-connection-for-chronofresh-woocommerce/js/sccfcw-admin-script.js
Version Parameters
simple-connection-for-chronofresh-woocommerce/css/sccfcw-admin-style.css?ver=simple-connection-for-chronofresh-woocommerce/js/sccfcw-admin-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
sccfcw-metabox-title
Data Attributes
data-sccfcw-order-id
JS Globals
sccfcw_ajax_object
FAQ

Frequently Asked Questions about Simple Connection for ChronoFresh