
WC China Checkout 物流通知插件 Security & Risk Analysis
wordpress.org/plugins/wc-china-checkoutWooCommerce中国本地结算,三级联动收货地址,物流查询,订单信息推送到海关。
Is WC China Checkout 物流通知插件 Safe to Use in 2026?
Generally Safe
Score 85/100WC China Checkout 物流通知插件 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wc-china-checkout" plugin v1.0.0 exhibits a mixed security posture. On one hand, it demonstrates good practices in areas like SQL query preparedness and output escaping, with a low number of external HTTP requests and a single nonce check. The absence of recorded CVEs and a clean vulnerability history are positive indicators of past security diligence. However, significant concerns arise from the static analysis. The presence of two "shell_exec" calls is a critical red flag, as this function can be exploited for arbitrary code execution if not handled with extreme caution and strict input validation. Furthermore, the taint analysis reveals two high-severity flows with unsanitized paths, indicating potential vulnerabilities that could allow attackers to manipulate file system operations or command execution. The lack of any capability checks for the identified entry points, though currently zero, is a potential weakness should new entry points be introduced in the future. Overall, while the plugin has a clean history and some good coding practices, the identified dangerous functions and taint flows represent a substantial security risk that requires immediate attention.
Key Concerns
- Dangerous function: shell_exec found
- High severity taint flow with unsanitized path (x2)
- No capability checks on entry points
- Bundled library: Select2 (potential for outdated version)
WC China Checkout 物流通知插件 Security Vulnerabilities
WC China Checkout 物流通知插件 Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WC China Checkout 物流通知插件 Attack Surface
WordPress Hooks 36
Maintenance & Trust
WC China Checkout 物流通知插件 Maintenance & Trust
Maintenance Signals
Community Trust
WC China Checkout 物流通知插件 Alternatives
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
WooPayments: Integrated WooCommerce Payments
woocommerce-payments
Securely accept credit and debit cards on your WooCommerce store. Manage payments without leaving your WordPress dashboard. Only with WooPayments.
WooCommerce PayPal Payments
woocommerce-paypal-payments
PayPal's latest payment processing solution. Accept PayPal, Pay Later, credit/debit cards, alternative digital wallets and bank accounts.
Click to Chat – HoliThemes
click-to-chat-for-whatsapp
WhatsApp Chat🔥. Let's make your Web page visitors contact you through 'WhatsApp', 'WhatsApp Business'. Add matching Widget✅
WC China Checkout 物流通知插件 Developer Profile
3 plugins · 40 total installs
How We Detect WC China Checkout 物流通知插件
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-china-checkout/assets/css/admin.css/wp-content/plugins/wc-china-checkout/assets/css/style.css/wp-content/plugins/wc-china-checkout/assets/js/admin.js/wp-content/plugins/wc-china-checkout/assets/js/frontend.js/wp-content/plugins/wc-china-checkout/assets/js/admin.js/wp-content/plugins/wc-china-checkout/assets/js/frontend.jswc-china-checkout/assets/css/admin.css?ver=wc-china-checkout/assets/css/style.css?ver=wc-china-checkout/assets/js/admin.js?ver=wc-china-checkout/assets/js/frontend.js?ver=HTML / DOM Fingerprints
wc-sinicwc-sinic-checkout<!-- WC China Checkout -->data-wc-sinicWC_Sinic[wc_sinic_checkout_button]