
Shipping of Nova Poshta for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wc-nova-poshta-for-shopПідключення служби доставки Нова Пошта до Вашого сайту (WooCommerce)
Is Shipping of Nova Poshta for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Shipping of Nova Poshta for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wc-nova-poshta-for-shop" plugin version 1.2.1 exhibits a concerning security posture primarily due to a large number of unprotected entry points. With 6 out of 7 total entry points lacking any form of authentication or capability checks, the plugin presents a significant attack surface for unauthorized access and potential manipulation. While the static analysis indicates no dangerous functions, raw SQL queries, or exploitable taint flows, the absence of proper authorization on AJAX handlers is a critical oversight that could lead to privilege escalation or unauthorized actions if not properly mitigated within the application logic. The plugin also shows a weakness in output escaping, with only 21% of outputs properly escaped, increasing the risk of cross-site scripting (XSS) vulnerabilities. The lack of any recorded vulnerability history might suggest a lack of public discovery or a more robust development process in that area, but this should not overshadow the immediate risks identified in the code. Overall, the plugin has strengths in its use of prepared statements and lack of dangerous functions, but the numerous unprotected entry points and poor output sanitization demand immediate attention to avoid serious security breaches.
Key Concerns
- High number of unprotected AJAX handlers
- Low percentage of properly escaped output
- Missing nonce checks on AJAX handlers
- Missing capability checks on AJAX handlers
Shipping of Nova Poshta for WooCommerce Security Vulnerabilities
Shipping of Nova Poshta for WooCommerce Code Analysis
Output Escaping
Shipping of Nova Poshta for WooCommerce Attack Surface
AJAX Handlers 6
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
Shipping of Nova Poshta for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Shipping of Nova Poshta for WooCommerce Alternatives
WC Ukraine Shipping – Integration of Nova Poshta and Ukrposhta for WooCommerce
wc-ukr-shipping
Connect Nova Poshta, Ukrposhta, Meest or international delivery services with your store. Create labels, track orders and calculate rates in one place …
Morkva UA Shipping
morkva-ua-shipping
Нова Пошта по Україні та закордон, Укрпошта по Україні та закордон. Rozetka Delivery. Зручне створення ТТН. Друк ТТН. Сумісний з іншими плагінами.
Яндекс Доставка (Boxberry)
boxberry
Удобный плагин для интеграции с Яндекс Доставкой (Boxberry): расчет стоимости и сроков доставки, выбор ПВЗ, выгрузка заказов, печать этикеток и актов.
Shipping for Nova Poshta
nova-poshta-ttn
Доставка на відділення, поштомат та адресу (з автопошуком вулиць). Створення ТТН. Найзручніший плагін.
SafeRoute WooCommerce
saferoute-woocommerce
Плагин для быстрой интеграции виджета доставки SafeRoute в магазины на основе WooCommerce.
Shipping of Nova Poshta for WooCommerce Developer Profile
2 plugins · 20 total installs
How We Detect Shipping of Nova Poshta for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-nova-poshta-for-shop/assets_file/css/admin_style.css/wp-content/plugins/wc-nova-poshta-for-shop/assets_file/js/admin_custom.js/wp-content/plugins/wc-nova-poshta-for-shop/assets_file/js/jquery.sumoselect.min.js/wp-content/plugins/wc-nova-poshta-for-shop/assets_file/js/custom.js/wp-content/plugins/wc-nova-poshta-for-shop/assets_file/css/jquery-ui.min.css/wp-content/plugins/wc-nova-poshta-for-shop/assets_file/css/sumoselect.min.css/wp-content/plugins/wc-nova-poshta-for-shop/assets_file/css/style.css../assets_file/js/admin_custom.js../assets_file/js/jquery.sumoselect.min.js../assets_file/js/custom.jsHTML / DOM Fingerprints
npfw_billing_np_citynpfw_billing_warehousesid="billing_np_city"name="billing_np_city"id="billing_warehouses_field"name="billing_warehouses"id="billing_warehouses"myajax/wp-json/wp/v2/posts<div class="npfw_billing_np_city"><label>City</labe><input id="billing_np_city" name="billing_np_city" type="text" placeholder="Please select city"></div><div class="npfw_billing_warehouses" id="billing_warehouses_field">