
Track Orders for WooCommerce – Multi Carrier WooCommerce Shipping Security & Risk Analysis
wordpress.org/plugins/track-orders-for-woocommerceTrack Orders for WooCommerce - WooCommerce Shipping Plugin with delivery notifications, tracking templates, and live updates.
Is Track Orders for WooCommerce – Multi Carrier WooCommerce Shipping Safe to Use in 2026?
Generally Safe
Score 100/100Track Orders for WooCommerce – Multi Carrier WooCommerce Shipping has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'track-orders-for-woocommerce' plugin exhibits a mixed security posture. On the positive side, it has a clean vulnerability history with no recorded CVEs, indicating a history of responsible development or timely patching. The code also demonstrates good practices in SQL query preparation and output escaping, with a very high percentage of queries using prepared statements and a strong majority of outputs being properly escaped. However, significant concerns arise from the static analysis. A substantial portion of the plugin's attack surface, specifically 14 out of 22 entry points, lacks authentication checks. This presents a considerable risk, as unauthenticated users could potentially interact with these components. Furthermore, the presence of the `exec` dangerous function, even if only 3 times, warrants caution, as it can lead to serious security issues if not handled with extreme care. The taint analysis found one flow with unsanitized paths, which, although not classified as critical or high severity, is still a potential avenue for exploitation that should be addressed.
Key Concerns
- Large attack surface without auth checks
- Presence of dangerous function 'exec'
- Flow with unsanitized paths (Taint Analysis)
Track Orders for WooCommerce – Multi Carrier WooCommerce Shipping Security Vulnerabilities
Track Orders for WooCommerce – Multi Carrier WooCommerce Shipping Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Track Orders for WooCommerce – Multi Carrier WooCommerce Shipping Attack Surface
AJAX Handlers 18
REST API Routes 1
Shortcodes 3
WordPress Hooks 78
Scheduled Events 2
Maintenance & Trust
Track Orders for WooCommerce – Multi Carrier WooCommerce Shipping Maintenance & Trust
Maintenance Signals
Community Trust
Track Orders for WooCommerce – Multi Carrier WooCommerce Shipping Alternatives
AfterShip Tracking – All-In-One WooCommerce Order Tracking (Free plan available)
aftership-woocommerce-tracking
Track orders in one place. shipment tracking, automated notifications, order lookup, branded tracking page, delivery day prediction
Štíteknabalík.cz
foxdeli
Looking for a reliable label printing solution? Štíteknabalík.cz will help you!
Advanced Shipment Tracking for WooCommerce
woo-advanced-shipment-tracking
Add shipment tracking info to WooCommerce orders, send tracking numbers to customers via email, and let them track deliveries from My Account.
Shiprocket
shiprocket
Auto Sync your Woocommerce store orders & ship them at lowest shipping rates. Automate your shipping, save time & money.
ZeroV99 Shipment Tracking
zerov99-shipment-tracking
Add a 'Shipped' status to WooCommerce orders, track shipments, and provide real-time updates to customers effortlessly.
Track Orders for WooCommerce – Multi Carrier WooCommerce Shipping Developer Profile
13 plugins · 43K total installs
How We Detect Track Orders for WooCommerce – Multi Carrier WooCommerce Shipping
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/track-orders-for-woocommerce/assets/css/wps-order-tracking-front.css/wp-content/plugins/track-orders-for-woocommerce/assets/css/wps-order-tracking-common.css/wp-content/plugins/track-orders-for-woocommerce/assets/js/wps-order-tracking-front.js/wp-content/plugins/track-orders-for-woocommerce/assets/js/wps-order-tracking-common.js/wp-content/plugins/track-orders-for-woocommerce/assets/js/wps-order-tracking-public.js/wp-content/plugins/track-orders-for-woocommerce/assets/css/tracking-info-display.css/wp-content/plugins/track-orders-for-woocommerce/assets/js/tracking-info-display.js/wp-content/plugins/track-orders-for-woocommerce/assets/js/wps-order-tracking-common.js/wp-content/plugins/track-orders-for-woocommerce/assets/js/wps-order-tracking-public.js/wp-content/plugins/track-orders-for-woocommerce/assets/js/tracking-info-display.jstrack-orders-for-woocommerce/assets/css/wps-order-tracking-front.css?ver=track-orders-for-woocommerce/assets/css/wps-order-tracking-common.css?ver=track-orders-for-woocommerce/assets/js/wps-order-tracking-front.js?ver=track-orders-for-woocommerce/assets/js/wps-order-tracking-common.js?ver=track-orders-for-woocommerce/assets/js/wps-order-tracking-public.js?ver=track-orders-for-woocommerce/assets/css/tracking-info-display.css?ver=track-orders-for-woocommerce/assets/js/tracking-info-display.js?ver=HTML / DOM Fingerprints
wps-order-tracking-wrapperwps-tracking-order-sectionwps-order-tracking-detailswps-tracking-stepswps-tracking-stepwps-tracking-activewps-tracking-completedwps-tracking-pending+11 more<!-- track-orders-for-woocommerce --><!-- WPSwings Order Tracking --><!-- WPS DHL Tracking Template --><!-- Track Orders for WooCommerce -->data-tracking-iddata-tracking-providerdata-order-iddata-tracking-urlwps_order_tracking_params[wps_order_tracking][wps_track_order]