
SnappBox Security & Risk Analysis
wordpress.org/plugins/snappboxThe SnappBox WordPress plugin offers a fast and simple way to register and manage order deliveries. By installing this plugin, you can send your store …
Is SnappBox Safe to Use in 2026?
Generally Safe
Score 100/100SnappBox has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "snappbox" plugin version 1.1.2 exhibits a mixed security posture. On the positive side, the plugin demonstrates excellent practices regarding SQL queries, utilizing prepared statements exclusively, and it has no recorded history of vulnerabilities (CVEs). This suggests a development team that is either very diligent or has been fortunate enough to avoid major security oversights and external exploits. However, a significant concern arises from its attack surface. With two identified AJAX handlers, both lacking authentication checks, this creates a direct entry point for attackers. Furthermore, only 19% of output is properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data could be rendered directly in the browser without proper sanitization.
While the absence of critical taint flows, dangerous functions, and file operations is reassuring, the unprotected AJAX endpoints and widespread unescaped output are substantial risks. The lack of any documented vulnerabilities might lead to a false sense of security. The plugin's strengths in SQL handling and its clean vulnerability history are outweighed by the immediate and exploitable weaknesses in its attack surface and output sanitization. Recommendations for improvement should focus heavily on implementing robust authentication and authorization checks for all AJAX handlers, and ensuring all output is properly escaped.
Key Concerns
- Unprotected AJAX handlers
- Low output escaping rate
SnappBox Security Vulnerabilities
SnappBox Code Analysis
Output Escaping
SnappBox Attack Surface
AJAX Handlers 2
WordPress Hooks 14
Maintenance & Trust
SnappBox Maintenance & Trust
Maintenance Signals
Community Trust
SnappBox Alternatives
Shiprocket
shiprocket
Auto Sync your Woocommerce store orders & ship them at lowest shipping rates. Automate your shipping, save time & money.
YITH WooCommerce Order & Shipment Tracking
yith-woocommerce-order-tracking
Add an easy tool to manage order shipping information of your shop and to notified your customers about the shipping.
Sendle Shipping Plugin
official-sendle-shipping-method
Sendle is an award-winning, 100% carbon neutral, door-to-door shipping carrier, designed to help small businesses thrive with simple, reliable, afford …
Custom Shipment Tracker for WooCommerce
custom-shipment-tracker-for-woocommerce
Track WooCommerce order shipment status with a timeline view. Admin can update status and choose whether to show dates.
Dewa Kirim – WooCommerce Gojek / Gosend
dewa-kirim-woocommerce-gojek
Dewa Kirim Gojek add shipping on demand services like gojek features to your website. Needs WooCommerce to work. WooCommerce 3.4.x compatible.
SnappBox Developer Profile
1 plugin · 300 total installs
How We Detect SnappBox
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/snappbox/assets/js/leaflet.js/wp-content/plugins/snappbox/assets/css/style.css/wp-content/plugins/snappbox/assets/js/gutenberg-map.js/wp-content/plugins/snappbox/assets/js/leaflet.js/wp-content/plugins/snappbox/assets/js/gutenberg-map.jssnappbox/assets/css/style.css?ver=snappbox/assets/js/leaflet.js?ver=snappbox/assets/js/gutenberg-map.js?ver=HTML / DOM Fingerprints
snappbox_geo_nonceym/wp-json/snappbox/v1/nearby