
Ukrposhta Security & Risk Analysis
wordpress.org/plugins/woo-ukrposhtaСтворюйте експрес-накладні автоматично, на сторінці замовлення. 10% знижка на відправлення, створені онлайн за допомогою API Ukrposhta.
Is Ukrposhta Safe to Use in 2026?
Generally Safe
Score 99/100Ukrposhta has a strong security track record. Known vulnerabilities have been patched promptly.
The "woo-ukrposhta" v1.18.1 plugin exhibits a mixed security posture. While it demonstrates good practices with a high percentage of prepared SQL statements and properly escaped output, there are significant concerns regarding its attack surface. A notable portion of its AJAX handlers (6 out of 10) and all of its REST API routes (3 out of 3) lack proper authentication or permission checks. This creates numerous entry points that could be exploited by unauthenticated users.
The taint analysis reveals some unsanitized paths, although no critical or high-severity flows were identified. The vulnerability history shows one past medium-severity CVE related to Cross-Site Scripting, which has been patched. The presence of past vulnerabilities, even if resolved, underscores the importance of maintaining vigilance. Overall, the plugin has strengths in its code hygiene for database interactions and output rendering, but the lack of robust access control on many of its endpoints is a primary risk that needs immediate attention.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- Flows with unsanitized paths
- Low capability check coverage
Ukrposhta Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Woo Ukrposhta <= 1.17.11 - Reflected Cross-Site Scripting via order, post, and idd Parameters
Ukrposhta Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Ukrposhta Attack Surface
AJAX Handlers 10
REST API Routes 3
WordPress Hooks 44
Maintenance & Trust
Ukrposhta Maintenance & Trust
Maintenance Signals
Community Trust
Ukrposhta Alternatives
WC Ukraine Shipping – Integration of Nova Poshta and Ukrposhta for WooCommerce
wc-ukr-shipping
Connect Nova Poshta, Ukrposhta, Meest or international delivery services with your store. Create labels, track orders and calculate rates in one place …
Morkva UA Shipping
morkva-ua-shipping
Нова Пошта по Україні та закордон, Укрпошта по Україні та закордон. Rozetka Delivery. Зручне створення ТТН. Друк ТТН. Сумісний з іншими плагінами.
Ukrposhta Developer Profile
14 plugins · 3K total installs
How We Detect Ukrposhta
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-ukrposhta/dist/style.css/wp-content/plugins/woo-ukrposhta/dist/script.js/wp-content/plugins/woo-ukrposhta/admin/css/settings.css/wp-content/plugins/woo-ukrposhta/admin/js/settings.js/wp-content/plugins/woo-ukrposhta/assets/css/admin-styles.css/wp-content/plugins/woo-ukrposhta/assets/css/checkout.css/wp-content/plugins/woo-ukrposhta/assets/js/checkout.js/wp-content/plugins/woo-ukrposhta/assets/js/settings.js+1 more/wp-content/plugins/woo-ukrposhta/dist/script.js/wp-content/plugins/woo-ukrposhta/admin/js/settings.js/wp-content/plugins/woo-ukrposhta/assets/js/checkout.js/wp-content/plugins/woo-ukrposhta/assets/js/settings.js/wp-content/plugins/woo-ukrposhta/assets/js/order.jswoo-ukrposhta/dist/style.css?ver=woo-ukrposhta/dist/script.js?ver=woo-ukrposhta/admin/css/settings.css?ver=woo-ukrposhta/admin/js/settings.js?ver=woo-ukrposhta/assets/css/admin-styles.css?ver=woo-ukrposhta/assets/css/checkout.css?ver=woo-ukrposhta/assets/js/checkout.js?ver=woo-ukrposhta/assets/js/settings.js?ver=woo-ukrposhta/assets/js/order.js?ver=HTML / DOM Fingerprints
ukrposhta-checkout-fieldukrposhta-shipping-method<!-- ukrposhta-shipping-method --><!-- Ukrposhta Settings --><!-- Ukrposhta Order Details --><!-- Ukrposhta Shipping Options -->data-ukrposhta-shipping-methoddata-ukrposhta-api-keyUkrposhtaApiukrposhtaSettings/wp-json/ukrposhta/v1/settings/wp-json/ukrposhta/v1/calculate_shipping[ukrposhta_shipping_calculator][ukrposhta_tracking_info]