Wildrobot Security & Risk Analysis

wordpress.org/plugins/wildrobot

WooCommerce shipping integration with Wildrobot.

0 active installs v1.1.0 PHP 7.4+ WP 5.1+ Updated Aug 5, 2025
checkoutfreightlogisticsshippingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Wildrobot Safe to Use in 2026?

Generally Safe

Score 100/100

Wildrobot has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The plugin "wildrobot" v1.1.0 demonstrates a generally strong security posture in its static analysis. The absence of any identified attack surface points (AJAX handlers, REST API routes, shortcodes, cron events) suggests a minimal exposure to external inputs. Furthermore, the code signals are positive, with no dangerous functions, 100% of SQL queries using prepared statements, and a high percentage of properly escaped output. The lack of file operations and external HTTP requests also reduces potential attack vectors.

However, the analysis reveals several areas for concern. Notably, there are zero nonce checks and zero capability checks, which is a significant weakness. While the attack surface is currently zero, this lack of authentication and authorization mechanisms means that if any new entry points are introduced in the future, they would be inherently unprotected. The bundled Freemius v1.0 library is also present; while not explicitly flagged as vulnerable in the provided history, outdated bundled libraries can pose a risk if they contain unpatched vulnerabilities not yet reported.

The vulnerability history is entirely clear, with no recorded CVEs, which is a positive indicator. This suggests that the developers have historically maintained a good security standard or that the plugin has not been a target for in-depth vulnerability research. However, the lack of historical vulnerabilities should not be interpreted as absolute security, especially given the identified weaknesses in authentication and authorization checks. The overall risk assessment is therefore moderate; the plugin is currently well-defended due to its minimal attack surface, but it has underlying structural weaknesses that could be exploited if new entry points are added without proper security controls.

Key Concerns

  • No nonce checks present
  • No capability checks present
  • Bundled Freemius library outdated
Vulnerabilities
None known

Wildrobot Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Wildrobot Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

90% escaped10 total outputs
Attack Surface

Wildrobot Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionadmin_initincludes\admin.php:57
actionwoocommerce_admin_order_data_after_shipping_addressincludes\admin.php:58
actionadmin_noticesincludes\admin.php:67
actioninitincludes\settings.php:51
actionwoocommerce_settings_wildrobotincludes\settings.php:55
filterwoocommerce_settings_tabs_arrayincludes\settings.php:57
actionwoocommerce_update_options_wildrobotincludes\settings.php:59
actionadmin_enqueue_scriptsincludes\wildrobot.php:131
actionadmin_enqueue_scriptsincludes\wildrobot.php:132
actionwp_enqueue_scriptsincludes\wildrobot.php:144
actionwp_enqueue_scriptsincludes\wildrobot.php:145
filterwoocommerce_shipping_methodsincludes\wildrobot.php:149
actionplugins_loadedwildrobot.php:61
Maintenance & Trust

Wildrobot Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 5, 2025
PHP min version7.4
Downloads296

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Wildrobot Developer Profile

Robin Pedersen

2 plugins · 200 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Wildrobot

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wildrobot/css/wildrobot-admin.css/wp-content/plugins/wildrobot/js/wildrobot-admin.js
Script Paths
/wp-content/plugins/wildrobot/js/wildrobot-admin.js
Version Parameters
wildrobot/css/wildrobot-admin.css?ver=wildrobot/js/wildrobot-admin.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Wildrobot Freight requires WooCommerce to be installed and active. -->
Data Attributes
data-wildrobot-pickup-point-iddata-wildrobot-pickup-point-namedata-wildrobot-pickup-point-city
FAQ

Frequently Asked Questions about Wildrobot