
UDW Delivery – Uber Direct for WooCommerce Security & Risk Analysis
wordpress.org/plugins/udwdeliveryDelivery service for WooCommerce integrating with Uber Direct API.
Is UDW Delivery – Uber Direct for WooCommerce Safe to Use in 2026?
Generally Safe
Score 92/100UDW Delivery – Uber Direct for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "udwdelivery" v2.2.6 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and properly escaping nearly all output, significantly mitigating risks associated with SQL injection and cross-site scripting (XSS). The absence of recorded vulnerabilities in its history is also a strong indicator of past diligence. However, a significant concern lies in its attack surface, with 3 out of 4 entry points lacking authentication checks. Specifically, the presence of 3 unprotected AJAX handlers represents a notable risk, as these could potentially be exploited by unauthenticated users to perform unintended actions or trigger malicious behavior.
The taint analysis, while limited to two flows, did not reveal any critical or high-severity unsanitized paths, which is reassuring. However, the fact that both analyzed flows had unsanitized paths, even if not deemed critical in this specific analysis, warrants caution as it suggests potential for future vulnerabilities if input handling changes or new attack vectors are discovered. The plugin's reliance on external HTTP requests (6) is also an area to monitor, as vulnerabilities in external services could indirectly impact the plugin's security. Overall, while the plugin has strengths in its data handling and output sanitization, the lack of authentication on a significant portion of its AJAX endpoints is a critical weakness that needs immediate attention.
Key Concerns
- Unprotected AJAX handlers
- Taint flows with unsanitized paths (2 total)
- External HTTP requests (6)
UDW Delivery – Uber Direct for WooCommerce Security Vulnerabilities
UDW Delivery – Uber Direct for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
UDW Delivery – Uber Direct for WooCommerce Attack Surface
AJAX Handlers 3
REST API Routes 1
WordPress Hooks 16
Maintenance & Trust
UDW Delivery – Uber Direct for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
UDW Delivery – Uber Direct for WooCommerce Alternatives
Uber Direct Integration
uber-direct-delivery-integration
Offer instant or scheduled delivery from your WooCommerce store with real-time quotes and Uber Direct integration
Local Delivery Drivers for WooCommerce
local-delivery-drivers-for-woocommerce
Improve the way you deliver, manage drivers, assign drivers to orders, send WhatsApp, SMS, and email notifications, route planning, navigation & more!
Woot
woot-ro
Unified shipping solution for WooCommerce. Integrates all popular couriers in Romania with real-time pricing and pickup point selection.
Gobuddy – The smart delivery solution
gobuddy-the-smart-delivery-solution
The official Gobuddy plugin for WooCommerce
CityCourier – Local Courier Booking & Tracking System
citycourier-local-courier-booking-tracking-system
Courier booking form with Google Maps integration, distance-based pricing, delivery zones, map picker, and order tracking. Built for WooCommerce.
UDW Delivery – Uber Direct for WooCommerce Developer Profile
2 plugins · 40 total installs
How We Detect UDW Delivery – Uber Direct for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/udwdelivery/assets/css/udwd-admin.css/wp-content/plugins/udwdelivery/assets/js/udwd-admin.js/wp-content/plugins/udwdelivery/assets/js/udwd-admin.jsudwdelivery/assets/css/udwd-admin.css?ver=udwdelivery/assets/js/udwd-admin.js?ver=HTML / DOM Fingerprints
udwd-metabox-containerudwd-delivery-tracking_urludwd-delivery-btn_coppy-tracking_url translators: %s: delivery status id="udwd-metabox-container"id="udwd-delivery-tracking_url"id="udwd-delivery-btn_coppy-tracking_url"udwdelivery_params/uberdirect/v1/status