Voyapp Chile – Lugares y Cotizador de Despachos Security & Risk Analysis

wordpress.org/plugins/voya-chile-lugares-y-cotizador-de-despachos

Añade las regiones y comunas de Chile a WooCommerce. También podrás contar con un cotizador de despachos de múltiples couriers y mucho más.

300 active installs v1.8.6 PHP 7.0+ WP 5.6+ Updated Nov 14, 2025
chilechilexpressshippingstarkenwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Voyapp Chile – Lugares y Cotizador de Despachos Safe to Use in 2026?

Generally Safe

Score 100/100

Voyapp Chile – Lugares y Cotizador de Despachos has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "voya-chile-lugares-y-cotizador-de-despachos" plugin, version 1.8.6, exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all its SQL queries and has no recorded history of vulnerabilities or known CVEs. This suggests a generally well-maintained codebase in terms of direct database manipulation and long-term security track record.

However, significant concerns arise from the attack surface analysis. The plugin exposes two REST API routes without any permission callbacks, meaning any authenticated user, regardless of their role, could potentially interact with these endpoints. Furthermore, the taint analysis indicates four flows with unsanitized paths. While these are not classified as critical or high severity, unsanitized paths can still lead to unexpected behavior or serve as vectors for further exploitation if other security measures are bypassed.

The absence of nonce checks on its entry points, combined with the unprotected REST API routes, presents a notable weakness. While the direct use of dangerous functions is zero, and file operations are not present, the presence of unsanitized flows and unprotected API endpoints, especially without nonce verification, creates potential avenues for attack that could be exploited by authenticated users. The plugin's vulnerability history is a strength, but it doesn't negate the risks identified in the static analysis.

Key Concerns

  • REST API routes without permission callbacks
  • Flows with unsanitized paths found
  • No nonce checks on entry points
  • Output escaping is only 50% proper
Vulnerabilities
None known

Voyapp Chile – Lugares y Cotizador de Despachos Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Voyapp Chile – Lugares y Cotizador de Despachos Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
113
113 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
8
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

50% escaped226 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
showShippingLabelsPage (includes\classes\voya_despachos_menus.php:25)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Voyapp Chile – Lugares y Cotizador de Despachos Attack Surface

Entry Points4
Unprotected2

REST API Routes 2

POST/wp-json/voyacl/v1/settings/getincludes\classes\voya_despachos_endpoints.php:7
POST/wp-json/voyacl/v1/notificationsincludes\classes\voya_despachos_notification.php:11

Shortcodes 2

[voya_seguimiento] includes\classes\voya_despachos_tracking.php:9
[voyapp_tracking] includes\classes\voya_despachos_tracking.php:10
WordPress Hooks 36
actionwoocommerce_checkout_update_order_metaincludes\classes\voya_despachos_calculo.php:91
filterwoocommerce_package_ratesincludes\classes\voya_despachos_calculo.php:385
filterwoocommerce_package_ratesincludes\classes\voya_despachos_calculo.php:401
actionplugins_loadedincludes\classes\voya_despachos_destinos.php:20
actionwp_print_scriptsincludes\classes\voya_despachos_destinos.php:23
actionwp_enqueue_scriptsincludes\classes\voya_despachos_destinos.php:24
filterwoocommerce_statesincludes\classes\voya_despachos_destinos.php:41
filterwoocommerce_billing_fieldsincludes\classes\voya_despachos_destinos.php:48
filterwoocommerce_shipping_fieldsincludes\classes\voya_despachos_destinos.php:49
filterwoocommerce_form_field_cityincludes\classes\voya_despachos_destinos.php:50
actionwp_enqueue_scriptsincludes\classes\voya_despachos_destinos.php:52
actionrest_api_initincludes\classes\voya_despachos_endpoints.php:6
actionadmin_noticesincludes\classes\voya_despachos_important_info.php:6
actioninitincludes\classes\voya_despachos_menus.php:6
actionadmin_menuincludes\classes\voya_despachos_menus.php:7
actionwoocommerce_payment_completeincludes\classes\voya_despachos_metrics.php:10
actionwoocommerce_order_status_completedincludes\classes\voya_despachos_metrics.php:11
actionwoocommerce_order_status_changedincludes\classes\voya_despachos_metrics.php:12
actionadmin_noticesincludes\classes\voya_despachos_notification.php:8
actionrest_api_initincludes\classes\voya_despachos_notification.php:10
filterwoocommerce_checkout_fieldsincludes\classes\voya_despachos_third_level_address.php:8
actionwoocommerce_after_checkout_validationincludes\classes\voya_despachos_third_level_address.php:9
actionwoocommerce_admin_order_data_after_billing_addressincludes\classes\voya_despachos_third_level_address.php:10
actionwoocommerce_admin_order_data_after_shipping_addressincludes\classes\voya_despachos_third_level_address.php:11
actionadd_meta_boxesincludes\classes\voya_despachos_wc_order.php:6
actionvoyapp_send_tracking_email_notificationincludes\emails\class-voyapp-tracking-email.php:25
actionplugins_loadedvoya-despachos.php:289
actionplugins_loadedvoya-despachos.php:290
actionwoocommerce_shipping_initvoya-despachos.php:291
actionwoocommerce_review_order_after_order_totalvoya-despachos.php:292
filterwoocommerce_cart_shipping_method_full_labelvoya-despachos.php:293
filterwoocommerce_default_address_fieldsvoya-despachos.php:294
filterwoocommerce_shipping_methodsvoya-despachos.php:295
filterwoocommerce_order_shipping_to_display_shipped_viavoya-despachos.php:296
filterwoocommerce_email_classesvoya-despachos.php:297
actionbefore_woocommerce_initvoya-despachos.php:300
Maintenance & Trust

Voyapp Chile – Lugares y Cotizador de Despachos Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 14, 2025
PHP min version7.0
Downloads17K

Community Trust

Rating96/100
Number of ratings16
Active installs300
Developer Profile

Voyapp Chile – Lugares y Cotizador de Despachos Developer Profile

Voyapp

1 plugin · 300 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Voyapp Chile – Lugares y Cotizador de Despachos

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/voya-chile-lugares-y-cotizador-de-despachos/public/assets/css/voya-despachos-destinos.css/wp-content/plugins/voya-chile-lugares-y-cotizador-de-despachos/public/assets/js/voya-despachos-destinos.js/wp-content/plugins/voya-chile-lugares-y-cotizador-de-despachos/public/assets/js/voya-despachos-calculo.js/wp-content/plugins/voya-chile-lugares-y-cotizador-de-despachos/public/assets/js/voya-despachos-checkout.js/wp-content/plugins/voya-chile-lugares-y-cotizador-de-despachos/public/assets/js/voya-despachos-tracking.js/wp-content/plugins/voya-chile-lugares-y-cotizador-de-despachos/public/assets/js/voya-despachos-general.js/wp-content/plugins/voya-chile-lugares-y-cotizador-de-despachos/public/assets/css/voya-despachos-general.css
Script Paths
/wp-content/plugins/voya-chile-lugares-y-cotizador-de-despachos/public/assets/js/voya-despachos-destinos.js/wp-content/plugins/voya-chile-lugares-y-cotizador-de-despachos/public/assets/js/voya-despachos-calculo.js/wp-content/plugins/voya-chile-lugares-y-cotizador-de-despachos/public/assets/js/voya-despachos-checkout.js/wp-content/plugins/voya-chile-lugares-y-cotizador-de-despachos/public/assets/js/voya-despachos-tracking.js/wp-content/plugins/voya-chile-lugares-y-cotizador-de-despachos/public/assets/js/voya-despachos-general.js
Version Parameters
/wp-content/plugins/voya-chile-lugares-y-cotizador-de-despachos/public/assets/css/voya-despachos-destinos.css?ver=/wp-content/plugins/voya-chile-lugares-y-cotizador-de-despachos/public/assets/js/voya-despachos-destinos.js?ver=/wp-content/plugins/voya-chile-lugares-y-cotizador-de-despachos/public/assets/js/voya-despachos-calculo.js?ver=/wp-content/plugins/voya-chile-lugares-y-cotizador-de-despachos/public/assets/js/voya-despachos-checkout.js?ver=/wp-content/plugins/voya-chile-lugares-y-cotizador-de-despachos/public/assets/js/voya-despachos-tracking.js?ver=/wp-content/plugins/voya-chile-lugares-y-cotizador-de-despachos/public/assets/js/voya-despachos-general.js?ver=/wp-content/plugins/voya-chile-lugares-y-cotizador-de-despachos/public/assets/css/voya-despachos-general.css?ver=

HTML / DOM Fingerprints

CSS Classes
voya-despachos-destinos-wrapvoya-despachos-calculator-wrapvoya-despachos-tracking-wrapvoya-despachos-form
HTML Comments
<!-- begin voya-despachos-destinos --><!-- End voya-despachos-destinos --><!-- begin voya-despachos-calculo --><!-- End voya-despachos-calculo -->+4 more
Data Attributes
data-voya-urldata-voya-url-frontofficedata-voya-app-namedata-voya-plugin-slugdata-voya-supported-countriesdata-voya-call-timeout
JS Globals
VoyaDespachosDestinosVoya_Despachos_CalculoVoyaDespachosTrackingVoyaDespachosNotificationVoyaDespachosEndpointsVoyaDespachosThirdLevelAddress+9 more
Shortcode Output
[voya_despachos_destinos][voya_despachos_calculo][voya_despachos_tracking][voya_despachos_general]
FAQ

Frequently Asked Questions about Voyapp Chile – Lugares y Cotizador de Despachos