Thenine Logistic Security & Risk Analysis

wordpress.org/plugins/thenine-logistic

Professional WordPress Order Management System (OMS) integrated with WooCommerce. Features custom login page, modern dashboard.

0 active installs v1.0.0 PHP 7.4+ WP 5.0+ Updated Jan 5, 2026
inventorylogisticsomsorder-managementwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Thenine Logistic Safe to Use in 2026?

Generally Safe

Score 100/100

Thenine Logistic has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "thenine-logistic" plugin v1.0.0 exhibits a generally strong security posture based on the provided static analysis. A significant positive is the robust use of prepared statements for SQL queries (84%) and the high percentage of properly escaped output (97%). The presence of nonce and capability checks on all entry points is also commendable, indicating an awareness of fundamental WordPress security practices. The plugin also benefits from a clean vulnerability history with no known CVEs, suggesting a mature and well-maintained codebase. However, the taint analysis reveals a concern with nine flows identified as having unsanitized paths, all classified as high severity. While these don't appear to be directly exploitable due to the lack of exposed entry points or known CVEs, they represent potential areas where a skilled attacker might find a vulnerability if combined with other weaknesses. The presence of file operations and external HTTP requests, while not inherently risky, are entry points that warrant careful monitoring in future versions.

In conclusion, "thenine-logistic" v1.0.0 is a relatively secure plugin with good adherence to standard WordPress security practices. Its main weakness lies in the nine high-severity taint flows with unsanitized paths, which, despite not currently leading to known vulnerabilities, represent a significant area for improvement. The lack of historical vulnerabilities is a positive indicator, but the taint analysis suggests that ongoing vigilance and code review are important to maintain this strong security track record.

Key Concerns

  • High severity unsanitized paths in taint analysis
Vulnerabilities
None known

Thenine Logistic Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Thenine Logistic Code Analysis

Dangerous Functions
0
Raw SQL Queries
12
61 prepared
Unescaped Output
8
297 escaped
Nonce Checks
8
Capability Checks
9
File Operations
3
External Requests
2
Bundled Libraries
0

SQL Query Safety

84% prepared73 total queries

Output Escaping

97% escaped305 total outputs
Data Flows
9 unsanitized

Data Flow Analysis

13 flows9 with unsanitized paths
render_filters (includes\admin\screens\class-base-screen.php:133)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Thenine Logistic Attack Surface

Entry Points9
Unprotected0

AJAX Handlers 7

authwp_ajax_logistic_update_order_statusincludes\admin\class-oms-ajax.php:31
authwp_ajax_logistic_add_order_imagesincludes\admin\class-oms-ajax.php:34
authwp_ajax_logistic_remove_order_imageincludes\admin\class-oms-ajax.php:35
authwp_ajax_thenlo_oms_track_orderincludes\shortcodes\class-oms-tracking-shortcode.php:30
noprivwp_ajax_thenlo_oms_track_orderincludes\shortcodes\class-oms-tracking-shortcode.php:31
authwp_ajax_thenlo_loginthenine-logistic.php:367
noprivwp_ajax_logistic_loginthenine-logistic.php:368

REST API Routes 1

POST/wp-json/logistic/v1/webhooks/(?P<provider>[a-zA-Z0-9-]+)includes\integrations\shipping\webhooks\class-webhook-controller.php:38

Shortcodes 1

[thenlo_oms_tracking] includes\shortcodes\class-oms-tracking-shortcode.php:24
WordPress Hooks 34
actionadmin_initincludes\admin\class-fix-capabilities.php:39
actionadd_meta_boxesincludes\admin\class-woo-order-metabox.php:37
actionadd_meta_boxesincludes\admin\class-woo-order-metabox.php:40
actionadmin_menuincludes\class-logistic-settings.php:33
actionadmin_initincludes\class-logistic-settings.php:34
actioninitincludes\class-logistic-settings.php:143
actionrest_api_initincludes\integrations\shipping\webhooks\class-webhook-controller.php:31
actionwp_enqueue_scriptsincludes\shortcodes\class-oms-tracking-shortcode.php:27
actionplugins_loadedthenine-logistic.php:126
actionplugins_loadedthenine-logistic.php:129
actionadmin_initthenine-logistic.php:139
actionadmin_menuthenine-logistic.php:147
actionplugins_loadedthenine-logistic.php:151
actionplugins_loadedthenine-logistic.php:155
actionplugins_loadedthenine-logistic.php:158
actionplugins_loadedthenine-logistic.php:161
actioninitthenine-logistic.php:164
actioninitthenine-logistic.php:167
actionadmin_noticesthenine-logistic.php:194
actionadmin_noticesthenine-logistic.php:282
actionadmin_noticesthenine-logistic.php:293
actioninitthenine-logistic.php:335
filterquery_varsthenine-logistic.php:336
filterrequestthenine-logistic.php:339
actionparse_requestthenine-logistic.php:343
actiontemplate_redirectthenine-logistic.php:344
actionwp_loadedthenine-logistic.php:345
actioninitthenine-logistic.php:346
actionwpthenine-logistic.php:348
actioninitthenine-logistic.php:352
actionadmin_bar_menuthenine-logistic.php:357
actioninitthenine-logistic.php:362
actionadmin_initthenine-logistic.php:379
actionplugins_loadedthenine-logistic.php:1092
Maintenance & Trust

Thenine Logistic Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 5, 2026
PHP min version7.4
Downloads86

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Thenine Logistic Developer Profile

theninedotstore

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Thenine Logistic

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/thenine-logistic/assets/css/backend.css/wp-content/plugins/thenine-logistic/assets/css/frontend.css/wp-content/plugins/thenine-logistic/assets/js/backend.js/wp-content/plugins/thenine-logistic/assets/js/frontend.js
Script Paths
/wp-content/plugins/thenine-logistic/assets/js/backend.js/wp-content/plugins/thenine-logistic/assets/js/frontend.js
Version Parameters
thenine-logistic/assets/css/backend.css?ver=thenine-logistic/assets/css/frontend.css?ver=thenine-logistic/assets/js/backend.js?ver=thenine-logistic/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
thenine-logistic-order-tracking
Data Attributes
data-thenine-logistic-tracking-url
JS Globals
ThenineLogisticBackendThenineLogisticFrontend
REST Endpoints
/wp-json/thenine-logistic/v1/tracking
Shortcode Output
[thenine_logistic_tracking]
FAQ

Frequently Asked Questions about Thenine Logistic