
shipmendo – Lite Security & Risk Analysis
wordpress.org/plugins/wc-shipmendo-liteshipmendo - Lite kullanarak siparişlerin kargo adımlarını müşterilerinizle paylaşın. Desteklenen kargo firmaları: - Aras Kargo, - MNG Kargo, - PTT Kar …
Is shipmendo – Lite Safe to Use in 2026?
Generally Safe
Score 85/100shipmendo – Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wc-shipmendo-lite" v1.2 plugin exhibits a generally good security posture based on the provided static analysis. The absence of known CVEs and a clean vulnerability history are positive indicators. The plugin demonstrates strong practices by not utilizing dangerous functions, performing all SQL queries using prepared statements, and avoiding file operations and external HTTP requests. Furthermore, the attack surface, including AJAX handlers, REST API routes, shortcodes, and cron events, is reported as zero, which is an exceptionally secure design if accurate.
However, a significant concern arises from the taint analysis, which identified two flows with unsanitized paths. While these are not categorized as critical or high severity, unsanitized paths are a common entry point for various vulnerabilities, including cross-site scripting (XSS) and file inclusion. The low percentage of properly escaped output (10%) is also a major red flag. This indicates a high likelihood of XSS vulnerabilities, where malicious scripts could be injected into the user interface. The complete lack of nonce and capability checks, while not directly exploitable without an attack surface, suggests a potential weakness in authorization if any entry points were to be discovered or introduced in future versions.
In conclusion, while the plugin avoids many common pitfalls and has no documented past vulnerabilities, the identified unsanitized paths in taint analysis and the overwhelmingly poor output escaping present substantial risks. The lack of explicit capability checks also poses a latent risk. Future development should prioritize addressing these output escaping issues and thoroughly reviewing the taint analysis findings.
Key Concerns
- Unsanitized paths in taint analysis
- Only 10% of outputs properly escaped
- No nonce checks implemented
- No capability checks implemented
shipmendo – Lite Security Vulnerabilities
shipmendo – Lite Code Analysis
Output Escaping
Data Flow Analysis
shipmendo – Lite Attack Surface
WordPress Hooks 13
Maintenance & Trust
shipmendo – Lite Maintenance & Trust
Maintenance Signals
Community Trust
shipmendo – Lite Alternatives
Kargo Takip
kargo-takip-turkiye
WooCommerce siparişlerinize kargo takip bilgisi ekleyin ve müşterilerinize otomatik e-posta/SMS bildirimleri gönderin.
Kargo Takip
kargo-takip
Müşterilerinizin kargolarını takip etmesine olanak sağlayan bir kargo takip eklentisidir. Kargo takip eklentisi aras kargo, mng kargo , sürat kargo ve …
Kargom Nerede – Markalı Kargo Takip Sayfası, Sms, Mail
kargom-nerede-kargo-takip
Kargom Nerede - Markalı Kargo Takip Sayfası - Sms (Netgsm) - Mail WooCommerce > Siparişleriniz içerisinden "Kargom Nerede" bileşenine ka …
Hezarfen – WooCommerce için Kargo Entegrasyonu – Sözleşmeler, Mahalle, İlçe, SMS
hezarfen-for-woocommerce
🚀 2 bin site! Kargo takip, ücretsiz Hepsijet Entegrasyonu (1-4 desi: 89,24TL+KDV - Hezarfen Pro gerekmez), Mesafeli Sözleşmeler, NetGSM sipariş SMS
Cargo Tracking for WooCommerce
cargo-tracking-for-woocommerce
With the WooCommerce cargo tracking plugin, you can add as many cargo companies as you want, show cargo tracking links on the front and admin side, an …
shipmendo – Lite Developer Profile
5 plugins · 290 total installs
How We Detect shipmendo – Lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-shipmendo-lite/assets/css/shipmendo-lite-admin.css/wp-content/plugins/wc-shipmendo-lite/assets/js/admin.js/wp-content/plugins/wc-shipmendo-lite/assets/images/shipmendo-small-icon.png/wp-content/plugins/wc-shipmendo-lite/assets/images/settings.svg/wp-content/plugins/wc-shipmendo-lite/assets/images/help.svg/wp-content/plugins/wc-shipmendo-lite/assets/images/up-arrow.png/wp-content/plugins/wc-shipmendo-lite/assets/images/shipmendo-transparent-logo.png/wp-content/plugins/wc-shipmendo-lite/assets/js/admin.jswc-shipmendo-lite/assets/css/shipmendo-lite-admin.css?ver=wc-shipmendo-lite/assets/js/admin.js?ver=HTML / DOM Fingerprints
shipmendo-lite-top-navbarshipmendo-lite-top-navbar-divshipmendo-lite-top-navbar-ulshipmendo-lite-top-navbar-nav-itemshipmendo-lite-top-navbar-nav-linkshipmendo-upgrade-buttongrilabs-logoshipmendo-plugin-contentid="shipmendo-container"id="shipmendo-lite-copy-area"