Smart Send Logistics Security & Risk Analysis

wordpress.org/plugins/smart-send-logistics

Complete WooCommerce shipping solution for PostNord, GLS, DAO, Burd, Budbee and Bring.

400 active installs v8.1.3 PHP 5.6.0+ WP 3.0.1+ Updated Dec 3, 2025
pick-up-pointspostnordshippingshipping-labelsmart-send
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Smart Send Logistics Safe to Use in 2026?

Generally Safe

Score 100/100

Smart Send Logistics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The smart-send-logistics plugin version 8.1.3 exhibits a generally strong security posture based on the provided static analysis. It demonstrates good practices by having no unpatched vulnerabilities in its history and by utilizing prepared statements for all SQL queries. Furthermore, the plugin has a very small attack surface, with all identified entry points (AJAX handlers) being protected by nonce checks. The absence of critical taint analysis findings and dangerous functions is also a positive indicator.

However, there are areas for improvement. The lack of capability checks on its AJAX handlers presents a potential concern, as it relies solely on nonce verification. While nonce checks are important, capability checks ensure that the logged-in user actually has the necessary permissions to perform the action. Additionally, a significant portion of output (27%) is not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if malicious data is ever introduced into these output points. The presence of an external HTTP request, while not inherently insecure, warrants careful review to ensure it's being handled securely and doesn't expose any sensitive information or introduce other risks.

In conclusion, the plugin is in a relatively secure state, particularly concerning SQL injection and its limited attack surface. The primary weaknesses lie in the absence of capability checks and the notable percentage of unescaped output. Addressing these areas would further solidify its security.

Key Concerns

  • AJAX handlers without capability checks
  • Unescaped output (27%)
  • External HTTP request
Vulnerabilities
None known

Smart Send Logistics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Smart Send Logistics Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
29
78 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

73% escaped107 total outputs
Attack Surface

Smart Send Logistics Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_ss_shipping_generate_labelincludes\class-ss-shipping-wc-order.php:53
authwp_ajax_ss_test_connectionsmart-send-logistics.php:189
WordPress Hooks 24
actionin_plugin_update_message-smart-send-logistics/smart-send-logistics.phpincludes\class-ss-plugins-screen-updates.php:28
actionadmin_enqueue_scriptsincludes\class-ss-shipping-wc-method.php:241
actionadd_meta_boxesincludes\class-ss-shipping-wc-order.php:52
filterupdate_post_metadata_by_midincludes\class-ss-shipping-wc-order.php:56
actiondeleted_post_metaincludes\class-ss-shipping-wc-order.php:57
filterwcs_renewal_order_meta_queryincludes\class-ss-shipping-wc-order.php:62
filterwoocommerce_subscriptions_renewal_order_meta_queryincludes\class-ss-shipping-wc-order.php:65
actionadmin_noticesincludes\class-ss-shipping-wc-order.php:73
actionwoocommerce_product_options_shippingincludes\class-ss-shipping-wc-product.php:26
actionwoocommerce_process_product_metaincludes\class-ss-shipping-wc-product.php:27
actionwoocommerce_after_shipping_rateincludes\frontend\class-ss-shipping-frontend.php:30
actionwoocommerce_checkout_processincludes\frontend\class-ss-shipping-frontend.php:31
actionwoocommerce_checkout_order_processedincludes\frontend\class-ss-shipping-frontend.php:32
actionwoocommerce_order_details_after_order_tableincludes\frontend\class-ss-shipping-frontend.php:33
actionwoocommerce_email_after_order_tableincludes\frontend\class-ss-shipping-frontend.php:34
actionbefore_woocommerce_initsmart-send-logistics.php:100
actioninitsmart-send-logistics.php:176
actioninitsmart-send-logistics.php:177
filterplugin_row_metasmart-send-logistics.php:180
actionadmin_enqueue_scriptssmart-send-logistics.php:182
actionwp_enqueue_scriptssmart-send-logistics.php:183
filterwoocommerce_shipping_methodssmart-send-logistics.php:185
filterwoocommerce_package_ratessmart-send-logistics.php:186
actionadmin_noticessmart-send-logistics.php:207
Maintenance & Trust

Smart Send Logistics Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 3, 2025
PHP min version5.6.0
Downloads30K

Community Trust

Rating100/100
Number of ratings5
Active installs400
Developer Profile

Smart Send Logistics Developer Profile

SmartSend

2 plugins · 410 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Smart Send Logistics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/smart-send-logistics/assets/css/admin-styles.css/wp-content/plugins/smart-send-logistics/assets/js/admin-scripts.js/wp-content/plugins/smart-send-logistics/assets/css/frontend-styles.css/wp-content/plugins/smart-send-logistics/assets/js/frontend-scripts.js
Script Paths
/wp-content/plugins/smart-send-logistics/assets/js/admin-scripts.js/wp-content/plugins/smart-send-logistics/assets/js/frontend-scripts.js
Version Parameters
smart-send-logistics/assets/css/admin-styles.css?ver=smart-send-logistics/assets/js/admin-scripts.js?ver=smart-send-logistics/assets/css/frontend-styles.css?ver=smart-send-logistics/assets/js/frontend-scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
ss-shipping-admin-notice
Data Attributes
data-ss-shipping-methoddata-ss-shipping-carrierdata-ss-shipping-servicedata-ss-shipping-price
JS Globals
SS_Shipping_FrontendSS_Shipping_WC_OrderSS_Shipping_WC_ProductSS_Plugins_Screen_Updates
FAQ

Frequently Asked Questions about Smart Send Logistics