
TrackShip for WooCommerce Security & Risk Analysis
wordpress.org/plugins/trackship-for-woocommerceTrackShip auto-tracks orders, adds a branded tracking experience to your store and handles all customer touchpoints from shipping to delivery
Is TrackShip for WooCommerce Safe to Use in 2026?
Generally Safe
Score 98/100TrackShip for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The trackship-for-woocommerce plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices in output escaping, SQL query preparation, and generally implements nonce and capability checks. The absence of dangerous functions, file operations, and critical/high severity taint flows is commendable.
However, significant concerns arise from the unprotected entry points. Eight out of 41 total entry points (33 AJAX handlers and 6 REST API routes) lack authentication or permission checks, creating a substantial attack surface for unauthorized actions. Furthermore, four taint flows with unsanitized paths, even without critical severity, indicate potential vulnerabilities that could be exploited if user input is not properly handled. The vulnerability history, despite no currently unpatched CVEs, shows a pattern of SQL injection and missing authorization issues in the past, suggesting a recurring need for vigilance in these areas.
In conclusion, while the plugin has strengths in several key security areas, the unprotected entry points and flagged unsanitized taint flows present real risks. The historical prevalence of authorization and SQL-related vulnerabilities warrants careful monitoring and proactive patching for any future findings. The plugin is generally well-developed but requires immediate attention to secure its exposed entry points.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- Taint flows with unsanitized paths (4)
- Past medium severity SQL injection vulns
- Past medium severity missing authorization vulns
TrackShip for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
TrackShip for WooCommerce <= 1.9.1 - Authenticated (Shop manager+) SQL Injection
TrackShip for WooCommerce <= 1.7.5 - Missing Authorization
TrackShip for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
TrackShip for WooCommerce Attack Surface
AJAX Handlers 33
REST API Routes 6
Shortcodes 2
WordPress Hooks 107
Scheduled Events 1
Maintenance & Trust
TrackShip for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
TrackShip for WooCommerce Alternatives
Orders Tracking for WooCommerce
woo-orders-tracking
Easily import/manage your tracking numbers, add tracking numbers to PayPal and send email notifications to customers.
ParcelWILL (Formerly ParcelPanel) – Shipment Tracking, Tracking & Order Tracking for WooCommerce
parcelpanel
Free Plan Available. Order Tracking, Shipment Tracking. The best WooCommerce Order Tracker for Track Order Status & Delivery Notifications
Advanced Shipment Tracking for WooCommerce
woo-advanced-shipment-tracking
Add shipment tracking info to WooCommerce orders, send tracking numbers to customers via email, and let them track deliveries from My Account.
AfterShip Tracking – All-In-One WooCommerce Order Tracking (Free plan available)
aftership-woocommerce-tracking
Track orders in one place. shipment tracking, automated notifications, order lookup, branded tracking page, delivery day prediction
Sendcloud Shipping
sendcloud-connected-shipping
SendCloud helps to grow your online store by optimizing the shipping process. Shipping packages has never been that easy!
TrackShip for WooCommerce Developer Profile
1 plugin · 7K total installs
How We Detect TrackShip for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/trackship-for-woocommerce/assets/css/trackship-frontend.css/wp-content/plugins/trackship-for-woocommerce/assets/css/trackship-common.css/wp-content/plugins/trackship-for-woocommerce/assets/js/trackship-frontend.js/wp-content/plugins/trackship-for-woocommerce/assets/js/trackship-common.js/wp-content/plugins/trackship-for-woocommerce/assets/js/trackship-frontend.js/wp-content/plugins/trackship-for-woocommerce/assets/js/trackship-common.jstrackship-for-woocommerce/assets/css/trackship-frontend.css?ver=trackship-for-woocommerce/assets/css/trackship-common.css?ver=trackship-for-woocommerce/assets/js/trackship-frontend.js?ver=trackship-for-woocommerce/assets/js/trackship-common.js?ver=HTML / DOM Fingerprints
trackship-tracking-page-wrappertrackship-tracking-form-containertrackship-tracking-results-containertrackship-tracking-infotrackship-tracking-historytrackship-tracking-map-wrapper<!-- START TrackShip tracking template --><!-- END TrackShip tracking template -->data-ts-tracking-endpointdata-ts-tracking-keytrackship_frontend_paramsTrackShip/wp-json/trackship/v1/trackings