
Torod – The smart shipping and delivery portal for e-shops and retailers Security & Risk Analysis
wordpress.org/plugins/torodA platform that enables you to compare KSA shipping prices, print shipping labels, track orders, and manage returns from a single place.
Is Torod – The smart shipping and delivery portal for e-shops and retailers Safe to Use in 2026?
Mostly Safe
Score 71/100Torod – The smart shipping and delivery portal for e-shops and retailers is generally safe to use. 3 past CVEs were resolved. Keep it updated.
The "torod" v2.1 plugin presents a mixed security posture. While it demonstrates some positive security practices, such as a high percentage of SQL queries using prepared statements and proper output escaping for a majority of outputs, significant concerns arise from its attack surface and historical vulnerability profile. The plugin exposes a considerable number of AJAX handlers without proper authentication checks, creating a broad entry point for potential unauthorized actions. This is further exacerbated by the presence of three high-severity taint flows with unsanitized paths, suggesting potential for vulnerabilities like path traversal or insecure file operations. The plugin's history of three known CVEs, including one currently unpatched high-severity vulnerability, and a recent discovery date, indicates a recurring pattern of security weaknesses. The common vulnerability types (CSRF, SQL Injection, Missing Authorization) align with the observed lack of authentication on AJAX handlers and the taint analysis findings. Overall, the plugin has potential strengths but is significantly weakened by its unprotected entry points and a history of exploitable vulnerabilities, demanding careful consideration and remediation.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows
- Unpatched high severity CVE
- Common SQL Injection vulnerability history
- Common Missing Authorization vulnerability history
- Bundled Select2 library
- Bundled Guzzle library
- Unsanitized paths in taint flows
Torod – The smart shipping and delivery portal for e-shops and retailers Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Torod – The smart shipping and delivery portal for e-shops and retailers <= 1.9 - Cross-Site Request Forgery To Plugin's Settings Modification
Torod <= 1.9 - Unauthenticated SQL Injection
Torod – The smart shipping and delivery portal for e-shops and retailers <= 1.7 - Missing Authorization to Unauthenticated Plugin Settings Update
Torod – The smart shipping and delivery portal for e-shops and retailers Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Torod – The smart shipping and delivery portal for e-shops and retailers Attack Surface
AJAX Handlers 24
REST API Routes 1
WordPress Hooks 30
Scheduled Events 1
Maintenance & Trust
Torod – The smart shipping and delivery portal for e-shops and retailers Maintenance & Trust
Maintenance Signals
Community Trust
Torod – The smart shipping and delivery portal for e-shops and retailers Alternatives
SmartShip – The ideal entrepreneur destination for shipping solutions
smartship
A platform that enables you to compare KSA shipping prices, print shipping labels, track orders, and manage returns from a single place.
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy
instant-images
One-click uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy directly to your WordPress media library.
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid
the-post-grid
Display WordPress posts in beautiful grid, list, slider, and filter layouts. Works with Gutenberg, Elementor, Divi, and Shortcodes.
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
Username Changer
username-changer
Unlock the power to change WordPress usernames with complete security and data integrity.
Torod – The smart shipping and delivery portal for e-shops and retailers Developer Profile
1 plugin · 70 total installs
How We Detect Torod – The smart shipping and delivery portal for e-shops and retailers
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/torod/assets/css/select2.min.css/wp-content/plugins/torod/assets/js/select2.min.js/wp-content/plugins/torod/assets/js/torod_script.js/wp-content/plugins/torod/assets/js/torod_script_new.js/wp-content/plugins/torod/assets/css/bootstrap.min.css/wp-content/plugins/torod/assets/css/torod_style.css/wp-content/plugins/torod/assets/js/bootstrap.min.jstorod_script.js?ver=torod_script_new.js?ver=HTML / DOM Fingerprints
torod-settings-styledata-plugin-name="torod"data-plugin-version="2.1"torodtorod_new