WooTcsShipmentMaker Security & Risk Analysis

wordpress.org/plugins/woo-tcs-extension

Stable tag: License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.html This plugin is develop to integrate WooCommerce store wit …

10 active installs v0.0.0 PHP + WP + Updated Oct 17, 2017
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WooTcsShipmentMaker Safe to Use in 2026?

Generally Safe

Score 85/100

WooTcsShipmentMaker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "woo-tcs-extension" v0.0.0 plugin exhibits a mixed security posture. On the positive side, the code signals indicate a strong adherence to secure coding practices. There are no dangerous functions, all SQL queries use prepared statements, and all output is properly escaped. Furthermore, there are no file operations, external HTTP requests, or bundled libraries that could introduce vulnerabilities. This suggests that the developers have a good understanding of fundamental WordPress security.

However, a significant concern arises from the attack surface analysis. The plugin has one AJAX handler that lacks any authentication checks. This creates a direct entry point for unauthenticated users to interact with the plugin, potentially leading to unintended actions or information disclosure if not handled with extreme care within the AJAX function itself. The absence of any recorded vulnerabilities in its history is a positive indicator, but it doesn't negate the immediate risk posed by the unprotected AJAX endpoint.

In conclusion, while the plugin demonstrates good internal coding hygiene, the presence of an unprotected AJAX handler represents a critical security weakness. This single vulnerability significantly elevates the risk profile, as it provides a direct avenue for attackers. The lack of vulnerability history is reassuring but should not lead to complacency, especially given this identifiable flaw. The plugin's security can be significantly improved by implementing proper authentication and authorization checks on its AJAX endpoint.

Key Concerns

  • Unprotected AJAX handler
Vulnerabilities
None known

WooTcsShipmentMaker Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WooTcsShipmentMaker Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface
1 unprotected

WooTcsShipmentMaker Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_create_tcs_shipmentindex.php:31
WordPress Hooks 8
filterwoocommerce_settings_tabs_arrayincludes\WC_TCS_Setting_Tag.php:13
actionwoocommerce_settings_tabs_tcs_settings_tabincludes\WC_TCS_Setting_Tag.php:14
actionwoocommerce_update_options_tcs_settings_tabincludes\WC_TCS_Setting_Tag.php:15
actionadmin_initindex.php:26
filterwoocommerce_admin_order_actionsindex.php:29
filterwoocommerce_admin_order_actionsindex.php:30
actionadmin_headindex.php:32
actionadmin_headindex.php:33
Maintenance & Trust

WooTcsShipmentMaker Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedOct 17, 2017
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Alternatives

WooTcsShipmentMaker Alternatives

No alternatives data available yet.

Developer Profile

WooTcsShipmentMaker Developer Profile

qasimgulzar

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WooTcsShipmentMaker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-tcs-extension/includes/tcs-soap-driver.php/wp-content/plugins/woo-tcs-extension/includes/WC_TCS_Setting_Tag.php

HTML / DOM Fingerprints

CSS Classes
create_consignmenttracking
FAQ

Frequently Asked Questions about WooTcsShipmentMaker