TrackingMore Order Tracking for WooCommerce (Free plan available) Security & Risk Analysis
wordpress.org/plugins/trackingmore-woocommerce-trackingAll in one eCommerce order tracking, tracking page, customer notification and EDD. Support USPS, FedEx, UPS, DHL and 1100 carriers.
Is TrackingMore Order Tracking for WooCommerce (Free plan available) Safe to Use in 2026?
Generally Safe
Score 85/100TrackingMore Order Tracking for WooCommerce (Free plan available) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "trackingmore-woocommerce-tracking" plugin v1.1.6 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and performing a reasonable number of capability checks and nonce checks. There are no recorded vulnerabilities (CVEs) in its history, which suggests a generally secure development history or lack of public discovery. However, a significant concern arises from the presence of four AJAX handlers that lack authentication checks. This creates a substantial attack surface, as any unauthenticated user could potentially interact with these endpoints, leading to unintended actions or information disclosure if not carefully handled internally.
The static analysis reveals no critical or high-severity taint flows, indicating that sensitive data is likely handled appropriately within the codebase. However, the output escaping is only properly implemented for 47% of the outputs, which is a notable weakness. While not a direct vulnerability in itself without a specific exploit path, it increases the risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is reflected in the output without proper sanitization.
In conclusion, while the plugin has strengths in its SQL handling and a clean vulnerability history, the unprotected AJAX endpoints and insufficient output escaping present clear security risks. The lack of authentication on these entry points is the most immediate and impactful concern, requiring immediate attention to secure these handlers.
Key Concerns
- 4 AJAX handlers without auth checks
- 47% of outputs properly escaped
TrackingMore Order Tracking for WooCommerce (Free plan available) Security Vulnerabilities
TrackingMore Order Tracking for WooCommerce (Free plan available) Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
TrackingMore Order Tracking for WooCommerce (Free plan available) Attack Surface
AJAX Handlers 4
WordPress Hooks 24
Maintenance & Trust
TrackingMore Order Tracking for WooCommerce (Free plan available) Maintenance & Trust
Maintenance Signals
Community Trust
TrackingMore Order Tracking for WooCommerce (Free plan available) Alternatives
Advanced Shipment Tracking for WooCommerce
woo-advanced-shipment-tracking
Add shipment tracking info to WooCommerce orders, send tracking numbers to customers via email, and let them track deliveries from My Account.
Shiprocket
shiprocket
Auto Sync your Woocommerce store orders & ship them at lowest shipping rates. Automate your shipping, save time & money.
AfterShip Tracking – All-In-One WooCommerce Order Tracking (Free plan available)
aftership-woocommerce-tracking
Track orders in one place. shipment tracking, automated notifications, order lookup, branded tracking page, delivery day prediction
Shipping Live Rates and Access Points for UPS for WooCommerce
flexible-shipping-ups
Provide auto-calculated UPS rates and Access Point options. Easy 5-minute setup. Show real prices and nearest pickup points at WooCommerce checkout.
Shiptastic Integration for DHL
shiptastic-integration-for-dhl
Connect Shiptastic to the DHL API and create DHL labels to shipments and returns.
TrackingMore Order Tracking for WooCommerce (Free plan available) Developer Profile
1 plugin · 800 total installs
How We Detect TrackingMore Order Tracking for WooCommerce (Free plan available)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/trackingmore-woocommerce-tracking/assets/plugin/chosen/chosen.min.css/wp-content/plugins/trackingmore-woocommerce-tracking/assets/css/admin.css/wp-content/plugins/trackingmore-woocommerce-tracking/assets/plugin/chosen/chosen.jquery.min.js/wp-content/plugins/trackingmore-woocommerce-tracking/assets/plugin/chosen/chosen.proto.min.js/wp-content/plugins/trackingmore-woocommerce-tracking/assets/js/util.js/wp-content/plugins/trackingmore-woocommerce-tracking/assets/js/couriers.js/wp-content/plugins/trackingmore-woocommerce-tracking/assets/js/admin.js/wp-content/plugins/trackingmore-woocommerce-tracking/assets/plugin/chosen/chosen.min.css/wp-content/plugins/trackingmore-woocommerce-tracking/assets/css/admin.css/wp-content/plugins/trackingmore-woocommerce-tracking/assets/plugin/chosen/chosen.jquery.min.js/wp-content/plugins/trackingmore-woocommerce-tracking/assets/plugin/chosen/chosen.proto.min.js/wp-content/plugins/trackingmore-woocommerce-tracking/assets/js/util.js/wp-content/plugins/trackingmore-woocommerce-tracking/assets/js/couriers.js+1 moretrackingmore-woocommerce-tracking/assets/plugin/chosen/chosen.min.css?ver=trackingmore-woocommerce-tracking/assets/css/admin.css?ver=trackingmore-woocommerce-tracking/assets/plugin/chosen/chosen.jquery.min.js?ver=trackingmore-woocommerce-tracking/assets/plugin/chosen/chosen.proto.min.js?ver=trackingmore-woocommerce-tracking/assets/js/util.js?ver=trackingmore-woocommerce-tracking/assets/js/couriers.js?ver=trackingmore-woocommerce-tracking/assets/js/admin.js?ver=HTML / DOM Fingerprints
trackingmore-wraptrackingmore-shipping-infotrackingmore-shipping-labeltrackingmore-shipping-datatrackingmore-shipping-update-buttontrackingmore-wrap-ordertrackingmore-shipping-wrap-order<!-- TrackingMore - Order Details Tracking Info --><!-- TrackingMore - Order Status in Admin List --><!-- TrackingMore - Shipping Details -->data-trackingmore-order-iddata-trackingmore-tracking-iddata-trackingmore-carrier-namedata-trackingmore-tracking-numbertrackingmore_params/wp-json/trackingmore/v1/get_init_settings/wp-json/trackingmore/v1/get_single_tracking/wp-json/trackingmore/v1/save_single_tracking/wp-json/trackingmore/v1/delete_single_tracking