Claudio Sanches – Correios for WooCommerce Security & Risk Analysis

wordpress.org/plugins/woocommerce-correios

Integration between the Correios and WooCommerce

30K active installs v4.2.5 PHP 5.6+ WP 4.0+ Updated Jan 25, 2025
correiosdeliveryshippingwoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Claudio Sanches – Correios for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Claudio Sanches – Correios for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "woocommerce-correios" v4.2.5 plugin demonstrates a generally strong security posture based on the provided static analysis. The absence of any recorded vulnerabilities or CVEs in its history is a positive indicator. Furthermore, the code analysis reveals no critical or high-severity taint flows, no dangerous functions, and a strong emphasis on output escaping (94%). The plugin also implements nonce and capability checks on its AJAX handlers, limiting its immediate attack surface to those authorized.

Key Concerns

  • 50% of SQL queries not using prepared statements
  • External HTTP requests present
  • Some output not properly escaped (6%)
Vulnerabilities
None known

Claudio Sanches – Correios for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Claudio Sanches – Correios for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
2 prepared
Unescaped Output
6
98 escaped
Nonce Checks
4
Capability Checks
2
File Operations
0
External Requests
4
Bundled Libraries
0

SQL Query Safety

50% prepared4 total queries

Output Escaping

94% escaped104 total outputs
Attack Surface

Claudio Sanches – Correios for WooCommerce Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_woocommerce_correios_add_tracking_codeincludes\admin\class-wc-correios-admin-orders.php:25
authwp_ajax_woocommerce_correios_remove_tracking_codeincludes\admin\class-wc-correios-admin-orders.php:26
authwp_ajax_correios_cws_update_services_listincludes\integrations\class-wc-correios-integration.php:68
authwp_ajax_correios_autofill_addresses_empty_databaseincludes\integrations\class-wc-correios-integration.php:78
WordPress Hooks 29
actionadd_meta_boxesincludes\admin\class-wc-correios-admin-orders.php:23
filterwoocommerce_resend_order_emails_availableincludes\admin\class-wc-correios-admin-orders.php:24
actionmanage_shop_order_posts_custom_columnincludes\admin\class-wc-correios-admin-orders.php:29
actioninitincludes\class-wc-correios-autofill-addresses.php:44
actionwp_enqueue_scriptsincludes\class-wc-correios-autofill-addresses.php:54
actionwoocommerce_after_shipping_rateincludes\class-wc-correios-cart.php:21
filterwoocommerce_order_shipping_methodincludes\class-wc-correios-orders.php:21
filterwoocommerce_order_item_display_meta_keyincludes\class-wc-correios-orders.php:22
filterwoocommerce_api_order_responseincludes\class-wc-correios-rest-api.php:23
filterwoocommerce_api_create_orderincludes\class-wc-correios-rest-api.php:24
filterwoocommerce_api_edit_orderincludes\class-wc-correios-rest-api.php:25
actionrest_api_initincludes\class-wc-correios-rest-api.php:26
actionwoocommerce_order_details_after_order_tableincludes\class-wc-correios-tracking-history.php:23
actioninitincludes\class-wc-correios.php:23
actionbefore_woocommerce_initincludes\class-wc-correios.php:27
filterwoocommerce_integrationsincludes\class-wc-correios.php:38
filterwoocommerce_shipping_methodsincludes\class-wc-correios.php:39
filterwoocommerce_email_classesincludes\class-wc-correios.php:40
actionadmin_noticesincludes\class-wc-correios.php:43
filterwoocommerce_correios_cws_is_enabledincludes\integrations\class-wc-correios-integration.php:64
filterwoocommerce_correios_cws_environmentincludes\integrations\class-wc-correios-integration.php:65
filterwoocommerce_correios_cws_user_dataincludes\integrations\class-wc-correios-integration.php:66
filterwoocommerce_correios_cws_debugincludes\integrations\class-wc-correios-integration.php:67
filterwoocommerce_correios_enable_tracking_historyincludes\integrations\class-wc-correios-integration.php:71
filterwoocommerce_correios_get_tracking_link_correiosincludes\integrations\class-wc-correios-integration.php:72
filterwoocommerce_correios_enable_autofill_addressesincludes\integrations\class-wc-correios-integration.php:75
filterwoocommerce_correios_autofill_addresses_validity_timeincludes\integrations\class-wc-correios-integration.php:76
filterwoocommerce_correios_autofill_addresses_force_autofillincludes\integrations\class-wc-correios-integration.php:77
actionplugins_loadedwoocommerce-correios.php:40
Maintenance & Trust

Claudio Sanches – Correios for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 25, 2025
PHP min version5.6
Downloads836K

Community Trust

Rating98/100
Number of ratings867
Active installs30K
Developer Profile

Claudio Sanches – Correios for WooCommerce Developer Profile

Claudio Sanches

17 plugins · 134K total installs

69
trust score
Avg Security Score
85/100
Avg Patch Time
831 days
View full developer profile
Detection Fingerprints

How We Detect Claudio Sanches – Correios for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woocommerce-correios/assets/css/admin/orders.css/wp-content/plugins/woocommerce-correios/assets/js/admin/orders.min.js/wp-content/plugins/woocommerce-correios/assets/js/admin/orders.js/wp-content/plugins/woocommerce-correios/assets/css/admin/settings.css/wp-content/plugins/woocommerce-correios/assets/js/admin/shipping-methods.min.js/wp-content/plugins/woocommerce-correios/assets/js/admin/shipping-methods.js
Script Paths
/wp-content/plugins/woocommerce-correios/assets/js/admin/orders.min.js/wp-content/plugins/woocommerce-correios/assets/js/admin/orders.js/wp-content/plugins/woocommerce-correios/assets/js/admin/shipping-methods.min.js/wp-content/plugins/woocommerce-correios/assets/js/admin/shipping-methods.js
Version Parameters
woocommerce-correios/assets/css/admin/orders.css?ver=woocommerce-correios/assets/js/admin/orders.min.js?ver=woocommerce-correios/assets/js/admin/orders.js?ver=woocommerce-correios/assets/css/admin/settings.css?ver=woocommerce-correios/assets/js/admin/shipping-methods.min.js?ver=woocommerce-correios/assets/js/admin/shipping-methods.js?ver=

HTML / DOM Fingerprints

CSS Classes
wc-correios-add-tracking-code-wrapwc-correios-tracking-codes-listwc-correios-tracking-code-add-newwc-correios-tracking-code-remove
HTML Comments
Shipping methods admin settings.Admin orders actions.Display tracking code into orders list.Register tracking code metabox.+4 more
Data Attributes
data-order_iddata-tracking_code
JS Globals
WCCorreiosAdminOrdersParams
FAQ

Frequently Asked Questions about Claudio Sanches – Correios for WooCommerce