SnappBox Security & Risk Analysis

wordpress.org/plugins/snappbox

The SnappBox WordPress plugin offers a fast and simple way to register and manage order deliveries. By installing this plugin, you can send your store …

300 active installs v1.1.2 PHP 7.4+ WP 5.6+ Updated Feb 18, 2026
deliveryordersshippingtrackingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SnappBox Safe to Use in 2026?

Generally Safe

Score 100/100

SnappBox has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "snappbox" plugin version 1.1.2 exhibits a mixed security posture. On the positive side, the plugin demonstrates excellent practices regarding SQL queries, utilizing prepared statements exclusively, and it has no recorded history of vulnerabilities (CVEs). This suggests a development team that is either very diligent or has been fortunate enough to avoid major security oversights and external exploits. However, a significant concern arises from its attack surface. With two identified AJAX handlers, both lacking authentication checks, this creates a direct entry point for attackers. Furthermore, only 19% of output is properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data could be rendered directly in the browser without proper sanitization.

While the absence of critical taint flows, dangerous functions, and file operations is reassuring, the unprotected AJAX endpoints and widespread unescaped output are substantial risks. The lack of any documented vulnerabilities might lead to a false sense of security. The plugin's strengths in SQL handling and its clean vulnerability history are outweighed by the immediate and exploitable weaknesses in its attack surface and output sanitization. Recommendations for improvement should focus heavily on implementing robust authentication and authorization checks for all AJAX handlers, and ensuring all output is properly escaped.

Key Concerns

  • Unprotected AJAX handlers
  • Low output escaping rate
Vulnerabilities
None known

SnappBox Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

SnappBox Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
76
18 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

19% escaped94 total outputs
Attack Surface
2 unprotected

SnappBox Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_snapp_nearbysnappbox.php:102
noprivwp_ajax_snapp_nearbysnappbox.php:103
WordPress Hooks 14
actionadmin_menuincludes\admin.php:7
actionadmin_initincludes\admin.php:8
actionadmin_initsnappbox.php:65
actionadmin_headsnappbox.php:66
actionwoocommerce_shipping_initsnappbox.php:89
actionplugins_loadedsnappbox.php:100
actionwp_footersnappbox.php:163
actionbefore_woocommerce_initsnappbox.php:180
actionwp_enqueue_scriptssnappbox.php:187
actionwoocommerce_after_order_notessnappbox.php:219
actionwoocommerce_checkout_create_ordersnappbox.php:224
actionadmin_noticessnappbox.php:267
actionadd_meta_boxessnappbox.php:278
actionadmin_headsnappbox.php:287
Maintenance & Trust

SnappBox Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 18, 2026
PHP min version7.4
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs300
Developer Profile

SnappBox Developer Profile

Snapp! Box

1 plugin · 300 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SnappBox

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/snappbox/assets/js/leaflet.js/wp-content/plugins/snappbox/assets/css/style.css/wp-content/plugins/snappbox/assets/js/gutenberg-map.js
Script Paths
/wp-content/plugins/snappbox/assets/js/leaflet.js/wp-content/plugins/snappbox/assets/js/gutenberg-map.js
Version Parameters
snappbox/assets/css/style.css?ver=snappbox/assets/js/leaflet.js?ver=snappbox/assets/js/gutenberg-map.js?ver=

HTML / DOM Fingerprints

Data Attributes
snappbox_geo_nonce
JS Globals
ym
REST Endpoints
/wp-json/snappbox/v1/nearby
FAQ

Frequently Asked Questions about SnappBox