Wilje Online Verzendlabel Security & Risk Analysis

wordpress.org/plugins/wilje-verzendlabel

Connect your Woocommerce shop with the PostNL API using this simple solution provided by Wilje Online!

0 active installs v1.0.0 PHP 8.0+ WP 6.6+ Updated Oct 11, 2024
postnlshipmentwoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Wilje Online Verzendlabel Safe to Use in 2026?

Generally Safe

Score 92/100

Wilje Online Verzendlabel has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "wilje-verzendlabel" v1.0.0 plugin exhibits a generally good security posture, with no known vulnerabilities or critical security signals detected during static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests are strong positive indicators. The plugin also demonstrates good practices in output escaping (93%) and implements nonce checks, which are crucial for AJAX security. Taint analysis also reveals no critical or high severity unsanitized flows.

However, a notable area for improvement lies in capability checks. The presence of AJAX handlers without explicit capability checks introduces a potential risk if these handlers perform sensitive operations. While the current attack surface for unprotected entry points is zero, the lack of capability checks on these two AJAX handlers could become a concern if the plugin's functionality evolves or if new attack vectors are discovered that bypass nonce checks. The vulnerability history being clean is a positive sign, suggesting a well-developed and maintained plugin, but it is important to maintain these good practices as the plugin is updated.

In conclusion, "wilje-verzendlabel" v1.0.0 is a relatively secure plugin due to its robust handling of common web vulnerabilities and clean vulnerability history. The primary weakness lies in the potential for privilege escalation or unauthorized actions via the AJAX handlers due to the absence of capability checks. Addressing this would elevate its security to an even higher standard.

Key Concerns

  • AJAX handlers without capability checks
Vulnerabilities
None known

Wilje Online Verzendlabel Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Wilje Online Verzendlabel Release Timeline

v1.0.0Current
Code Analysis
Analyzed Mar 17, 2026

Wilje Online Verzendlabel Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
28 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

93% escaped30 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<wilje-verzendlabel> (wilje-verzendlabel.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Wilje Online Verzendlabel Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_print_postnl_labelwilje-verzendlabel.php:216
authwp_ajax_send_track_tracewilje-verzendlabel.php:253
WordPress Hooks 15
actionplugins_loadedincludes\class-wilje-verzendlabel.php:147
actionadmin_enqueue_scriptsincludes\class-wilje-verzendlabel.php:162
actionadmin_enqueue_scriptsincludes\class-wilje-verzendlabel.php:163
actionwp_enqueue_scriptsincludes\class-wilje-verzendlabel.php:178
actionwp_enqueue_scriptsincludes\class-wilje-verzendlabel.php:179
actionwoocommerce_shipping_initwilje-verzendlabel.php:85
filterwoocommerce_shipping_methodswilje-verzendlabel.php:91
actionadmin_enqueue_scriptswilje-verzendlabel.php:111
actionadmin_enqueue_scriptswilje-verzendlabel.php:112
actionadd_meta_boxeswilje-verzendlabel.php:169
actionwoocommerce_order_status_completedwilje-verzendlabel.php:254
filtermanage_edit-shop_order_columnswilje-verzendlabel.php:297
filtermanage_woocommerce_page_wc-orders_columnswilje-verzendlabel.php:298
actionmanage_shop_order_posts_custom_columnwilje-verzendlabel.php:299
actionmanage_woocommerce_page_wc-orders_custom_columnwilje-verzendlabel.php:300
Maintenance & Trust

Wilje Online Verzendlabel Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedOct 11, 2024
PHP min version8.0
Downloads903

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Wilje Online Verzendlabel Developer Profile

danielwiljeonline

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Wilje Online Verzendlabel

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wilje-verzendlabel/admin/css/wilje-verzendlabel-admin.css/wp-content/plugins/wilje-verzendlabel/admin/js/url-switch.js
Script Paths
/wp-content/plugins/wilje-verzendlabel/admin/js/url-switch.js
Version Parameters
wilje-verzendlabel/admin/css/wilje-verzendlabel-admin.css?ver=wilje-verzendlabel/admin/js/url-switch.js?ver=

HTML / DOM Fingerprints

CSS Classes
wilje_online_verzendlabel_parcel_optionswilje_online_verzendlabel_print_labelwilje_online_verzendlabel_download_labelwilje_online_verzendlabel_send_track_trace
Data Attributes
id="wilje_online_verzendlabel_parcel_options"id="wilje_online_verzendlabel_print_label"id="wilje_online_verzendlabel_download_label"id="wilje_online_verzendlabel_send_track_trace"
JS Globals
url_switch
REST Endpoints
wp-json/wilje-verzendlabel/
FAQ

Frequently Asked Questions about Wilje Online Verzendlabel