WC Correios Easy Tracking Code Security & Risk Analysis
wordpress.org/plugins/wc-correios-easy-tracking-codeAdicione código de rastreio dos Correios sem precisar abrir o pedido no WooCommerce.
Is WC Correios Easy Tracking Code Safe to Use in 2026?
Generally Safe
Score 85/100WC Correios Easy Tracking Code has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wc-correios-easy-tracking-code" plugin v1.3.0 exhibits a mixed security posture. On the positive side, the code demonstrates good practices regarding SQL queries, exclusively using prepared statements, and there are no identified dangerous functions, file operations, or external HTTP requests. The absence of any recorded vulnerability history (CVEs) is also a strong indicator of a relatively secure codebase historically.
However, significant concerns arise from the static analysis. The plugin exposes two AJAX entry points, and alarmingly, both lack any form of authentication or capability checks. This creates a substantial attack surface for unauthorized actions. Furthermore, while only three output operations were analyzed, one-third of them were not properly escaped, indicating a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in these outputs. The complete lack of nonce checks on AJAX handlers is a critical omission that exacerbates the risk posed by the unprotected entry points.
In conclusion, despite a clean vulnerability history and good SQL practices, the plugin's security is severely undermined by unprotected AJAX handlers and a notable lack of input sanitization and output escaping in certain areas. The potential for exploiting these unprotected entry points, especially combined with potential XSS vulnerabilities, presents a moderate to high risk for WordPress sites using this plugin.
Key Concerns
- Unprotected AJAX handlers
- Missing nonce checks on AJAX
- Unescaped output
WC Correios Easy Tracking Code Security Vulnerabilities
WC Correios Easy Tracking Code Code Analysis
Output Escaping
WC Correios Easy Tracking Code Attack Surface
AJAX Handlers 2
WordPress Hooks 4
Maintenance & Trust
WC Correios Easy Tracking Code Maintenance & Trust
Maintenance Signals
Community Trust
WC Correios Easy Tracking Code Alternatives
Claudio Sanches – Correios for WooCommerce
woocommerce-correios
Integration between the Correios and WooCommerce
Autocomplete Address for WooCommerce
autocomplete-address-for-woocommerce
Preencha automaticamente o endereço a partir do CEP no WooCommerce
Frenet Shipping Gateway for WooCommerce – Correios, Etiquetas e Rastreio
woo-shipping-gateway
Frete inteligente, simples e acessível para negócios que querem crescer
FPG – Endereço automático por Cep no Checkout
fpg-endereco-automatico-por-cep-no-checkout
Preenche o endereço, no checkout, automáticamente através do cep.
Virtuaria Correios – Frete, Etiqueta, Rastreio e Declaração
virtuaria-correios
Etiqueta, declaração, rastreio, calculadora, devolução, campos de checkout, descontos, tudo isso na versão grátis, com ou sem contrato. Tem MUITO+
WC Correios Easy Tracking Code Developer Profile
7 plugins · 109K total installs
How We Detect WC Correios Easy Tracking Code
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-correios-easy-tracking-code/assets/wc-correios-easy-tracking-code.css/wp-content/plugins/wc-correios-easy-tracking-code/assets/wc-correios-easy-tracking-code.js/wp-content/plugins/wc-correios-easy-tracking-code/assets/wc-correios-easy-tracking-code.jswc-correios-easy-tracking-code-css?ver=wc-correios-easy-tracking-code-js?ver=HTML / DOM Fingerprints
wc-correios-tracking-fieldCopyright (C) 2016 Fernando Acosta contato@fernandoacosta.netThis program is free software; you can redistribute it and/or modifyit under the terms of the GNU General Public License, version 2, aspublished by the Free Software Foundation.+8 moredata-order-idwc_correios_update_tracking_code/wp-json/wc-correios-easy-tracking-code/v1/add_tracking