
WC Ukraine Shipping – Integration of Nova Poshta and Ukrposhta for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wc-ukr-shippingConnect Nova Poshta, Ukrposhta, Meest or international delivery services with your store. Create labels, track orders and calculate rates in one place …
Is WC Ukraine Shipping – Integration of Nova Poshta and Ukrposhta for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100WC Ukraine Shipping – Integration of Nova Poshta and Ukrposhta for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'wc-ukr-shipping' plugin, version 1.21.6, exhibits a generally good security posture based on the provided static analysis. The total number of entry points is low and importantly, all identified entry points (AJAX, REST API, cron events) appear to have appropriate authentication or permission checks. The absence of known vulnerabilities in its history further strengthens this assessment, suggesting a track record of secure development and maintenance. However, there are areas for improvement that warrant attention. The plugin has a moderate percentage of SQL queries not using prepared statements and a significant portion of output not being properly escaped. While the taint analysis did not reveal critical or high severity flows, the presence of flows with unsanitized paths is a concern and could potentially lead to issues if not handled with extreme care or if further vulnerabilities are introduced. The limited number of file operations and external HTTP requests, along with nonce and capability checks, are positive indicators. Overall, the plugin is in a relatively secure state, but the identified code quality issues, particularly around SQL and output sanitization, represent potential weaknesses that could be exploited in conjunction with other factors or future code changes.
Key Concerns
- SQL queries not using prepared statements
- Output not properly escaped
- Flows with unsanitized paths
WC Ukraine Shipping – Integration of Nova Poshta and Ukrposhta for WooCommerce Security Vulnerabilities
WC Ukraine Shipping – Integration of Nova Poshta and Ukrposhta for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WC Ukraine Shipping – Integration of Nova Poshta and Ukrposhta for WooCommerce Attack Surface
REST API Routes 1
WordPress Hooks 40
Scheduled Events 1
Maintenance & Trust
WC Ukraine Shipping – Integration of Nova Poshta and Ukrposhta for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
WC Ukraine Shipping – Integration of Nova Poshta and Ukrposhta for WooCommerce Alternatives
Morkva UA Shipping
morkva-ua-shipping
Нова Пошта по Україні та закордон, Укрпошта по Україні та закордон. Rozetka Delivery. Зручне створення ТТН. Друк ТТН. Сумісний з іншими плагінами.
Nova Post for WooCommerce
nova-post-for-woocommerce
Official Nova Post shipping plugin for WooCommerce. Create shipments, calculate rates, print labels and track deliveries across Europe and Ukraine.
Weight Based Shipping Table Rate for WooCommerce – Flexible Shipping
flexible-shipping
Weight based shipping methods for WooCommerce. Flexible shipping with table rate rules by cart weight and order value. Accurate rates at checkout.
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels
print-invoices-packing-slip-labels-for-woocommerce
Auto-generate and attach WooCommerce PDF invoices and packing slips to order emails with customizable templates & bulk print options.
Weight Based Shipping for WooCommerce
weight-based-shipping-for-woocommerce
Weight Based Shipping is a flexible and widely-used solution to calculate shipping costs based on the total cart weight and value.
WC Ukraine Shipping – Integration of Nova Poshta and Ukrposhta for WooCommerce Developer Profile
5 plugins · 7K total installs
How We Detect WC Ukraine Shipping – Integration of Nova Poshta and Ukrposhta for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-ukr-shipping/assets/css/admin.min.css/wp-content/plugins/wc-ukr-shipping/assets/js/tabs.js/wp-content/plugins/wc-ukr-shipping/assets/js/settings.min.js/wp-content/plugins/wc-ukr-shipping/assets/js/ttn-widget.min.js/wp-content/plugins/wc-ukr-shipping/assets/css/sp-admin.min.css/wp-content/plugins/wc-ukr-shipping/assets/js/sp-admin.min.js/wp-content/plugins/wc-ukr-shipping/assets/js/plugin.min.js/wp-content/plugins/wc-ukr-shipping/assets/js/orders.min.js+2 more/wp-content/plugins/wc-ukr-shipping/assets/js/tabs.js/wp-content/plugins/wc-ukr-shipping/assets/js/settings.min.js/wp-content/plugins/wc-ukr-shipping/assets/js/ttn-widget.min.js/wp-content/plugins/wc-ukr-shipping/assets/js/sp-admin.min.js/wp-content/plugins/wc-ukr-shipping/assets/js/plugin.min.js/wp-content/plugins/wc-ukr-shipping/assets/js/orders.min.js+2 morewc-ukr-shipping/assets/css/admin.min.css?ver=wc-ukr-shipping/assets/js/tabs.js?ver=wc-ukr-shipping/assets/js/settings.min.js?ver=wc-ukr-shipping/assets/js/ttn-widget.min.js?ver=wc-ukr-shipping/assets/css/sp-admin.min.css?ver=wc-ukr-shipping/assets/js/sp-admin.min.js?ver=wc-ukr-shipping/assets/js/plugin.min.js?ver=wc-ukr-shipping/assets/js/orders.min.js?ver=wc-ukr-shipping/assets/js/automation.min.js?ver=wc-ukr-shipping/assets/js/tools.min.js?ver=HTML / DOM Fingerprints
wc-ukr-shipping-optionswcus-settings-tabswcus-tab-contentwcus-sectionwcus-section-titlewcus-section-contentwcus-labelwcus-input-wrapper+11 more<!-- WC Ukraine Shipping Settings --><!-- End WC Ukraine Shipping Settings --><!-- WC Ukraine Shipping TTN Widget --><!-- End WC Ukraine Shipping TTN Widget -->+8 moredata-wcus-noncedata-wcus-ajax-urldata-wcus-home-urldata-wcus-admin-urldata-wcus-langdata-wcus-disable-default-billing-fields+4 morewc_ukr_shipping_globalssmarty_parcel_globals