Advanced Shipment Tracking for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woo-advanced-shipment-trackingAdd shipment tracking info to WooCommerce orders, send tracking numbers to customers via email, and let them track deliveries from My Account.
Is Advanced Shipment Tracking for WooCommerce Safe to Use in 2026?
Generally Safe
Score 98/100Advanced Shipment Tracking for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "woo-advanced-shipment-tracking" plugin v3.9 exhibits a mixed security posture. On the positive side, the plugin demonstrates strong adherence to secure coding practices with a high percentage of prepared SQL statements and properly escaped output. The presence of numerous nonce and capability checks is also a good indicator of security awareness. However, a significant concern arises from the substantial attack surface exposed through AJAX handlers, with a concerning 9 out of 23 handlers lacking proper authentication checks. This creates a clear pathway for unauthorized actions if exploited.
Taint analysis reveals 7 high-severity flows, which, coupled with 10 flows with unsanitized paths, points to potential risks where user-supplied data might not be adequately validated or sanitized before being used, especially in conjunction with the unprotected AJAX endpoints. The vulnerability history, including a past critical CVE related to missing authorization, reinforces the concern that authorization and input validation are recurring areas of weakness for this plugin. While there are currently no unpatched vulnerabilities, the pattern suggests a tendency for these types of issues to emerge.
In conclusion, while the plugin has strengths in its use of prepared statements and output escaping, the high number of unprotected AJAX handlers and the critical taint flows represent significant security weaknesses. The historical pattern of missing authorization vulnerabilities further emphasizes the need for diligent security reviews and robust input validation, particularly for the identified AJAX entry points. Addressing these vulnerabilities is crucial to mitigate potential risks.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows
- Flows with unsanitized paths
- Past critical CVE
- Past medium CVE
Advanced Shipment Tracking for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Advanced Shipment Tracking for WooCommerce <= 3.5.2 - Cross-Site Request Forgery via paginate_shipping_provider_list and filter_shipping_provider_list
Advanced Shipment Tracking for WooCommerce <= 3.2.6 - Authenticated WordPress Options Change
Advanced Shipment Tracking for WooCommerce Release Timeline
Advanced Shipment Tracking for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Advanced Shipment Tracking for WooCommerce Attack Surface
AJAX Handlers 23
Shortcodes 1
WordPress Hooks 87
Maintenance & Trust
Advanced Shipment Tracking for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Shipment Tracking for WooCommerce Alternatives
Orders Tracking for WooCommerce
woo-orders-tracking
Easily import/manage your tracking numbers, add tracking numbers to PayPal and send email notifications to customers.
AfterShip Tracking – All-In-One WooCommerce Order Tracking (Free plan available)
aftership-woocommerce-tracking
Track orders in one place. shipment tracking, automated notifications, order lookup, branded tracking page, delivery day prediction
Track Orders for WooCommerce – Multi Carrier WooCommerce Shipping
track-orders-for-woocommerce
Track Orders for WooCommerce – WooCommerce Shipping Plugin with delivery notifications, tracking templates, and live updates.
Štíteknabalík.cz
foxdeli
Looking for a reliable label printing solution? Štíteknabalík.cz will help you!
ZeroV99 Shipment Tracking
zerov99-shipment-tracking
Add a 'Shipped' status to WooCommerce orders, track shipments, and provide real-time updates to customers effortlessly.
Advanced Shipment Tracking for WooCommerce Developer Profile
4 plugins · 70K total installs
How We Detect Advanced Shipment Tracking for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-advanced-shipment-tracking/assets/css/admin-style.css/wp-content/plugins/woo-advanced-shipment-tracking/assets/css/style.css/wp-content/plugins/woo-advanced-shipment-tracking/assets/js/admin-script.js/wp-content/plugins/woo-advanced-shipment-tracking/assets/js/script.js/wp-content/plugins/woo-advanced-shipment-tracking/assets/js/script.jswoo-advanced-shipment-tracking/assets/css/admin-style.css?ver=woo-advanced-shipment-tracking/assets/css/style.css?ver=woo-advanced-shipment-tracking/assets/js/admin-script.js?ver=woo-advanced-shipment-tracking/assets/js/script.js?ver=HTML / DOM Fingerprints
wcast_tracking_formwcast_tracking_providerwcast_tracking_numberast-order-tracking-wrap<!-- woo_shippment_provider table created --><!-- ADDED BY WOO ADVANCED SHIPMENT TRACKING --><!-- ADDED BY WOO ADVANCED SHIPMENT TRACKING FOR EACH TRACKING --><!-- THIS IS TO SHOW SHIPPING PROVIDER IN MY ACCOUNT PAGE -->+4 moredata-wcast-providerdata-wcast-tracking-numberdata-wcast-tracking-urlwcast_order_datawcast_settings/wp-json/ast-free/v1/tracking-providers/wp-json/ast-free/v1/orders