TrackFree – All-In-One WooCommerce Order Tracking Security & Risk Analysis
wordpress.org/plugins/trackfree-woocommerce-trackingTrackFree is a shipment tracking and customer engagement solution which enables businesses to better engage with customers and inspire long-term custo …
Is TrackFree – All-In-One WooCommerce Order Tracking Safe to Use in 2026?
Generally Safe
Score 100/100TrackFree – All-In-One WooCommerce Order Tracking has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "trackfree-woocommerce-tracking" v3.2.1 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for SQL queries and having a clean vulnerability history with no known CVEs. The presence of 18 nonce checks and 48 capability checks also suggests an effort to secure certain functionalities. However, significant concerns arise from the static analysis. The plugin exposes 23 AJAX handlers, with 5 of them lacking proper authentication checks, representing a considerable attack surface that could be exploited by unauthenticated users. Additionally, 3 out of 7 analyzed taint flows involved unsanitized paths, which, while not flagged as critical or high severity in this specific analysis, indicates a potential risk for path traversal or similar vulnerabilities if not handled with extreme care. The 59% proper output escaping rate is also a weakness, leaving room for cross-site scripting (XSS) vulnerabilities if the unescaped outputs are user-controlled.
While the plugin's vulnerability history is currently clear, this does not guarantee future safety, especially given the identified weaknesses in authentication and output sanitization. The presence of unsanitized paths, even without critical flags, warrants attention as these can often be exploited under specific conditions. The large number of unprotected AJAX handlers is a direct and significant security risk. Therefore, while the plugin has some strengths in database query security and a clean history, the potential for unauthorized access via unprotected AJAX endpoints and the risk of XSS through insufficient output escaping present notable weaknesses that require attention.
Key Concerns
- AJAX handlers without auth checks
- Unsanitized paths in taint analysis
- Low percentage of properly escaped output
TrackFree – All-In-One WooCommerce Order Tracking Security Vulnerabilities
TrackFree – All-In-One WooCommerce Order Tracking Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
TrackFree – All-In-One WooCommerce Order Tracking Attack Surface
AJAX Handlers 23
REST API Routes 3
Shortcodes 1
WordPress Hooks 20
Maintenance & Trust
TrackFree – All-In-One WooCommerce Order Tracking Maintenance & Trust
Maintenance Signals
Community Trust
TrackFree – All-In-One WooCommerce Order Tracking Alternatives
AfterShip Tracking – All-In-One WooCommerce Order Tracking (Free plan available)
aftership-woocommerce-tracking
Track orders in one place. shipment tracking, automated notifications, order lookup, branded tracking page, delivery day prediction
Štíteknabalík.cz
foxdeli
Looking for a reliable label printing solution? Štíteknabalík.cz will help you!
Shiprocket
shiprocket
Auto Sync your Woocommerce store orders & ship them at lowest shipping rates. Automate your shipping, save time & money.
Track Orders for WooCommerce – Multi Carrier WooCommerce Shipping
track-orders-for-woocommerce
Track Orders for WooCommerce - WooCommerce Shipping Plugin with delivery notifications, tracking templates, and live updates.
Advanced Shipment Tracking for WooCommerce
woo-advanced-shipment-tracking
Add shipment tracking info to WooCommerce orders, send tracking numbers to customers via email, and let them track deliveries from My Account.
TrackFree – All-In-One WooCommerce Order Tracking Developer Profile
1 plugin · 200 total installs
How We Detect TrackFree – All-In-One WooCommerce Order Tracking
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/trackfree-woocommerce-tracking/assets/css/trackfree-woo.css/wp-content/plugins/trackfree-woocommerce-tracking/assets/js/trackfree-woo.js/wp-content/plugins/trackfree-woocommerce-tracking/assets/js/trackfree-woo.jstrackfree-woocommerce-tracking/assets/css/trackfree-woo.css?ver=trackfree-woocommerce-tracking/assets/js/trackfree-woo.js?ver=HTML / DOM Fingerprints
trackfree-woo-tracking-noticeTrackFreeWooConfig