
ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce Security & Risk Analysis
wordpress.org/plugins/woo-alidropshipTransfer data from AliExpress products to WooCommerce effortlessly and fulfill WooCommerce orders to AliExpress automatically.
Is ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "woo-alidropship" v2.1.17 plugin exhibits a generally strong security posture, with excellent adherence to best practices in most areas. The static analysis reveals a low number of unprotected entry points, a very low percentage of SQL queries not using prepared statements, and a high rate of output escaping. Nonce and capability checks are also present in a significant number of cases, indicating a conscious effort to secure operations.
However, the presence of one taint flow with unsanitized paths rated as High severity is a notable concern, suggesting a potential for vulnerabilities if this flow is exploited. The plugin's vulnerability history, while showing no currently unpatched CVEs, reveals a past of two medium-severity vulnerabilities, specifically Cross-Site Request Forgery (CSRF) and Missing Authorization. This history, coupled with the high-severity taint flow, suggests that while the developers are responsive to patching, there might be underlying patterns or coding practices that can lead to such issues.
Overall, the plugin is well-maintained with good security practices, but the identified high-severity taint flow and historical medium-severity vulnerabilities warrant careful monitoring and potential further investigation to ensure the complete elimination of risks. The strengths in SQL handling and output escaping are commendable, but the specific taint flow and past vulnerabilities are areas that prevent a perfect security score.
Key Concerns
- High severity taint flow with unsanitized paths
- Past medium vulnerabilities (CSRF, Missing Auth)
ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
ALD Dropping and Fulfillment for AliExpress and WooCommerce <= 1.0.21 - Cross-Site Request Forgery to Order Information Disclosure
ALD Dropping and Fulfillment for AliExpress and WooCommerce <= 1.0.21 - Missing Authorization to Order Information Disclosure
ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce Attack Surface
AJAX Handlers 27
WordPress Hooks 98
Maintenance & Trust
ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce Alternatives
AliExpress Dropshipping Plugin for WooCommerce – AliNext
ali2woo-lite
AliExpress Dropshipping Plugin for WooCommerce lets you import products, reviews, images, set rules, and automate orders
TMDS – Dropshipping for TEMU and Woo
tmds-dropshipping-for-temu-and-woo
Transfer data from Temu products to WooCommerce effortlessly.
YD Culqi gateway for AliDropship
yd-culqi-gateway-for-alidropship
YD Culqi payment gateway for AliDropship provides an easy way to take credit card payments on your online store using Culqi.
AppScenic – Smart AI Dropshipping
appscenic
Expand your store catalogue with no upfront inventory cost. Source high-quality products from verified domestic suppliers and use AI in the process.
Importify – AI Dropshipping for WooCommerce
importify
Importify is a dropshipping app that allows you to find products from a variety of wholesalers, add them to your WooCommerce store, and sell them onli …
ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce Developer Profile
58 plugins · 167K total installs
How We Detect ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-alidropship/assets/css/admin-style.css/wp-content/plugins/woo-alidropship/assets/css/frontend-style.css/wp-content/plugins/woo-alidropship/assets/js/admin-script.js/wp-content/plugins/woo-alidropship/assets/js/frontend-script.js/wp-content/plugins/woo-alidropship/assets/js/admin-script.js/wp-content/plugins/woo-alidropship/assets/js/frontend-script.jswoo-alidropship/assets/css/admin-style.css?ver=woo-alidropship/assets/css/frontend-style.css?ver=woo-alidropship/assets/js/admin-script.js?ver=woo-alidropship/assets/js/frontend-script.js?ver=HTML / DOM Fingerprints
vi-woo-alidropship-admin-wrapvi-wad-auth-formdata-noncedata-set-urlvi_wad_admin_paramsvi_wad_frontend_params/wp-json/woo-alidropship/v1/settings