
Pickupp Delivery for eCommerce Shops using WooCommerce Security & Risk Analysis
wordpress.org/plugins/wc-pickuppPickupp offers door-to-door, same-day delivery in HK, SG, TW, MY. Easily create orders from your WooCommerce shop to the Pickupp platform!
Is Pickupp Delivery for eCommerce Shops using WooCommerce Safe to Use in 2026?
Mostly Safe
Score 74/100Pickupp Delivery for eCommerce Shops using WooCommerce is generally safe to use. 1 past CVE were resolved.
The "wc-pickupp" v2.4.3 plugin exhibits a mixed security posture. While it demonstrates good practices by utilizing prepared statements for all SQL queries and generally good output escaping, significant concerns arise from its attack surface and vulnerability history. The presence of unprotected REST API routes represents a clear entry point for potential attacks that are not properly authenticated or authorized. Furthermore, the plugin has a history of critical vulnerabilities, specifically improper control of filename for include/require statements, indicating a recurring weakness that could be exploited for remote code execution. The fact that a critical vulnerability from 2025 remains unpatched is a major red flag and suggests a lack of proactive security maintenance.
While the static analysis doesn't reveal any dangerous functions or critical taint flows in this specific version, the historical data and the exposed REST API routes are substantial risks. The absence of nonce and capability checks on entry points, combined with the historical pattern of file inclusion vulnerabilities, paints a picture of a plugin that, despite some good coding practices, is susceptible to serious exploitation. The unpatched critical vulnerability from the past, coupled with unprotected REST API endpoints, warrants immediate attention and remediation. Users should be highly cautious, and the plugin developers must address the unpatched vulnerability and secure all entry points.
Key Concerns
- Unpatched critical CVE
- Unprotected REST API routes
- Missing capability checks on entry points
- Missing nonce checks on entry points
- Vulnerability history with RFI
Pickupp Delivery for eCommerce Shops using WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WooCommerce Pickupp <= 2.4.0 - Unauthenticated Local File Inclusion
Pickupp Delivery for eCommerce Shops using WooCommerce Release Timeline
Pickupp Delivery for eCommerce Shops using WooCommerce Code Analysis
Output Escaping
Pickupp Delivery for eCommerce Shops using WooCommerce Attack Surface
REST API Routes 5
WordPress Hooks 14
Maintenance & Trust
Pickupp Delivery for eCommerce Shops using WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Pickupp Delivery for eCommerce Shops using WooCommerce Alternatives
Shipbubble – Shipping Automation for Woocommerce
shipbubble
[youtube https://www.youtube.com/watch?v=eGxMxB0QbXc]
Blowhorn Logistics Same Day Delivery
blowhorn-logistics-same-day-delivery
Blowhorn Logistics Same Day Delivery plugin helps you ship out your products from the website making the fulfilment process seamless.
Delyva
delyva-com
THIS PLUGIN IS NOT ACTIVELY MAINTAINED ANYMORE, please use DelyvaX instead.
RT Deliveries
rtdeliveries
Integrate WooCommerce with Road Train Deliveries (RTD) for automated shipping, tracking, and order syncing.
Shiprocket
shiprocket
Auto Sync your Woocommerce store orders & ship them at lowest shipping rates. Automate your shipping, save time & money.
Pickupp Delivery for eCommerce Shops using WooCommerce Developer Profile
1 plugin · 30 total installs
How We Detect Pickupp Delivery for eCommerce Shops using WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-pickupp/assets/css/wc-pickupp-admin-setting.css/wp-content/plugins/wc-pickupp/assets/js/wc-pickupp-admin-setting.js/wp-content/plugins/wc-pickupp/assets/js/wc-pickupp-admin-setting.jswc-pickupp/assets/css/wc-pickupp-admin-setting.css?ver=wc-pickupp/assets/js/wc-pickupp-admin-setting.js?ver=HTML / DOM Fingerprints
wc_pickupp_admin_noticedata-order_idwcPickuppAdminSettings/wp-json/wc-pickupp/v1/order