
Wanderlust OCA para WooCommerce Security & Risk Analysis
wordpress.org/plugins/wanderlust-oca-e-pak-shipping-ratesObtener costos de envío de manera dinámica utilizando la API de OCA E-Pak.
Is Wanderlust OCA para WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Wanderlust OCA para WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wanderlust-oca-e-pak-shipping-rates" plugin, version 1.1.995, exhibits a mixed security posture. While it demonstrates positive practices such as using prepared statements for all SQL queries and having no recorded vulnerabilities, significant concerns arise from its attack surface. The plugin exposes four AJAX handlers, all of which lack authentication checks. This represents a substantial risk, as any unauthenticated user could potentially interact with these handlers, leading to unintended actions or information disclosure.
The static analysis reveals that a concerning 37% of output is not properly escaped. This deficiency, while not directly linked to critical taint flows in the provided data, could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is reflected in the output without adequate sanitization. The absence of nonce checks on the AJAX handlers further exacerbates this risk, as it simplifies the exploitation of potential XSS flaws. Despite the clean vulnerability history, the exposed AJAX endpoints and unescaped output are significant weaknesses that require immediate attention to improve the plugin's overall security.
Key Concerns
- AJAX handlers without authentication
- Unescaped output
- Missing nonce checks on AJAX handlers
Wanderlust OCA para WooCommerce Security Vulnerabilities
Wanderlust OCA para WooCommerce Code Analysis
Output Escaping
Wanderlust OCA para WooCommerce Attack Surface
AJAX Handlers 4
WordPress Hooks 13
Maintenance & Trust
Wanderlust OCA para WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Wanderlust OCA para WooCommerce Alternatives
Printful Integration for WooCommerce
printful-shipping-for-woocommerce
Grow your store with the top print-on-demand dropshipping plugin
WC Hide Shipping Methods
wc-hide-shipping-methods
This plugin automatically hides all other shipping methods when "Free Shipping" is available, while allowing you to retain "Local Picku …
Hide Shipping Method For WooCommerce
hide-shipping-method-for-woocommerce
Allows store owners to hide shipping methods based on specific conditions!
USPS Simple Shipping for Woocommerce
woo-usps-simple-shipping
USPS Simple provides real-time USPS domestic rates.
Shipping Live Rates and Access Points for UPS for WooCommerce
flexible-shipping-ups
Provide auto-calculated UPS rates and Access Point options. Easy 5-minute setup. Show real prices and nearest pickup points at WooCommerce checkout.
Wanderlust OCA para WooCommerce Developer Profile
6 plugins · 2K total installs
How We Detect Wanderlust OCA para WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wanderlust-oca-e-pak-shipping-rates/assets/css/admin.css/wp-content/plugins/wanderlust-oca-e-pak-shipping-rates/assets/js/admin.js/wp-content/plugins/wanderlust-oca-e-pak-shipping-rates/assets/js/checkout.jsjquery-ui-sortablewanderlust-oca-e-pak-shipping-rates/assets/css/admin.css?ver=wanderlust-oca-e-pak-shipping-rates/assets/js/admin.js?ver=wanderlust-oca-e-pak-shipping-rates/assets/js/checkout.js?ver=HTML / DOM Fingerprints
pv_centro_oca_estandarmaxLengthorder_sucursal_mainonly_numbers_ocasoca_admin_notice/wp-ajax.php?action=check_sucursales/wp-ajax.php?action=check_admision