AgenWebsite Shipping – Plugin Ongkos Kirim & Generate Resi Otomatis Semua Kurir Indonesia Security & Risk Analysis

wordpress.org/plugins/woocommerce-jne

Otomatisasi pengiriman WooCommerce dengan kurir terpercaya Indonesia. Tarif real-time, pelacakan instan, cetak resi otomatis - tanpa hitung manual!

300 active installs v9.2.12 PHP 7.4+ WP 6.8+ Updated Mar 2, 2026
awbjneresishippingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AgenWebsite Shipping – Plugin Ongkos Kirim & Generate Resi Otomatis Semua Kurir Indonesia Safe to Use in 2026?

Generally Safe

Score 100/100

AgenWebsite Shipping – Plugin Ongkos Kirim & Generate Resi Otomatis Semua Kurir Indonesia has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "woocommerce-jne" plugin v9.2.12 presents a mixed security posture. While it demonstrates good practices in areas like using prepared statements for SQL queries and proper output escaping, there are notable concerns regarding its attack surface. The plugin has a significant number of AJAX handlers, with a substantial portion (8 out of 32) lacking authentication checks, creating potential entry points for unauthorized actions. The taint analysis also reveals a concerning number of flows with unsanitized paths, including three classified as high severity, indicating potential risks of data injection or manipulation if these flows are reachable by unauthenticated users.

The plugin's vulnerability history is clean, with no recorded CVEs. This is a positive indicator, suggesting that the development team has either been diligent in patching issues or that fewer vulnerabilities have been discovered. However, the clean history should not entirely overshadow the risks identified in the static and taint analysis. The absence of past vulnerabilities does not guarantee future security, especially when significant weaknesses in authentication and data sanitization are present.

In conclusion, the plugin has strengths in its SQL query and output handling. Nevertheless, the numerous unprotected AJAX endpoints and the high-severity unsanitized taint flows represent significant security weaknesses that require immediate attention. Addressing these identified risks is crucial to improving the plugin's overall security.

Key Concerns

  • Unprotected AJAX handlers present
  • High severity unsanitized taint flows
  • Taint flows with unsanitized paths detected
Vulnerabilities
None known

AgenWebsite Shipping – Plugin Ongkos Kirim & Generate Resi Otomatis Semua Kurir Indonesia Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AgenWebsite Shipping – Plugin Ongkos Kirim & Generate Resi Otomatis Semua Kurir Indonesia Code Analysis

Dangerous Functions
0
Raw SQL Queries
13
24 prepared
Unescaped Output
252
917 escaped
Nonce Checks
50
Capability Checks
39
File Operations
4
External Requests
19
Bundled Libraries
0

SQL Query Safety

65% prepared37 total queries

Output Escaping

78% escaped1169 total outputs
Data Flows
9 unsanitized

Data Flow Analysis

11 flows9 with unsanitized paths
render_print_page (includes\class-fulfillment-packing-slip.php:91)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
8 unprotected

AgenWebsite Shipping – Plugin Ongkos Kirim & Generate Resi Otomatis Semua Kurir Indonesia Attack Surface

Entry Points32
Unprotected8

AJAX Handlers 32

authwp_ajax_aw_wizard_save_stepincludes\admin\class-awshipping-setup-wizard.php:39
authwp_ajax_aw_shipping_activate_codincludes\class-cod-activation.php:32
authwp_ajax_aw_shipping_deactivate_codincludes\class-cod-activation.php:33
authwp_ajax_aw_shipping_get_cod_statusincludes\class-cod-activation.php:34
authwp_ajax_aw_shipping_get_kyc_urlincludes\class-cod-activation.php:35
authwp_ajax_aw_fulfillment_check_eligibilityincludes\class-fulfillment-ajax.php:49
authwp_ajax_aw_fulfillment_get_order_previewincludes\class-fulfillment-ajax.php:50
authwp_ajax_aw_fulfillment_get_ratesincludes\class-fulfillment-ajax.php:51
authwp_ajax_aw_fulfillment_get_pickup_timesincludes\class-fulfillment-ajax.php:52
authwp_ajax_aw_fulfillment_create_shipmentincludes\class-fulfillment-ajax.php:53
authwp_ajax_aw_fulfillment_request_pickupincludes\class-fulfillment-ajax.php:54
authwp_ajax_aw_fulfillment_get_bulk_ordersincludes\class-fulfillment-ajax.php:55
authwp_ajax_aw_fulfillment_check_payment_statusincludes\class-fulfillment-ajax.php:56
authwp_ajax_aw_fulfillment_get_labelsincludes\class-fulfillment-label.php:28
authwp_ajax_aw_fulfillment_print_labelsincludes\class-fulfillment-label.php:29
authwp_ajax_aw_checkout_insurance_updateincludes\class-insurance.php:35
noprivwp_ajax_aw_checkout_insurance_updateincludes\class-insurance.php:36
authwp_ajax_agenwebsite_shipping_toggle_featureincludes\class-settings.php:38
authwp_ajax_aw_shipping_smart_analysisincludes\class-smart-analysis.php:26
authwp_ajax_aw_shipping_retry_analysisincludes\class-smart-analysis.php:27
authwp_ajax_aw_shipping_get_analysis_statusincludes\class-smart-analysis.php:28
authwp_ajax_aw_shipping_get_balanceincludes\class-wallet.php:33
authwp_ajax_aw_shipping_create_topupincludes\class-wallet.php:34
authwp_ajax_aw_shipping_topup_historyincludes\class-wallet.php:35
authwp_ajax_aw_shipping_check_topup_statusincludes\class-wallet.php:36
authwp_ajax_aw_shipping_get_recent_resiincludes\class-wallet.php:37
authwp_ajax_aw_shipping_save_awb_configincludes\class-wallet.php:38
authwp_ajax_aw_shipping_get_deduction_historyincludes\class-wallet.php:39
authwp_ajax_aw_shipping_get_api_logsincludes\class-wallet.php:42
authwp_ajax_aw_shipping_get_api_log_detailincludes\class-wallet.php:43
authwp_ajax_aw_shipping_clear_api_logsincludes\class-wallet.php:44
authwp_ajax_aw_shipping_get_gamification_tasksincludes\class-wallet.php:47
WordPress Hooks 83
actionadmin_menuincludes\admin\class-awshipping-setup-wizard.php:36
actionadmin_initincludes\admin\class-awshipping-setup-wizard.php:37
actionadmin_noticesincludes\admin\class-awshipping-setup-wizard.php:38
actionadmin_enqueue_scriptsincludes\admin\class-awshipping-setup-wizard.php:40
actionadmin_menuincludes\agenwebsite-menu-helper.php:96
actionaw_api_log_cleanupincludes\class-api-logger.php:124
actionrest_api_initincludes\class-awb-callback.php:53
filterwoocommerce_product_tabsincludes\class-check-ongkir.php:19
actionwp_enqueue_scriptsincludes\class-check-ongkir.php:20
actionadmin_menuincludes\class-fulfillment-label.php:25
filtermanage_woocommerce_page_wc-orders_columnsincludes\class-fulfillment-orders.php:64
actionmanage_woocommerce_page_wc-orders_custom_columnincludes\class-fulfillment-orders.php:65
filtermanage_edit-shop_order_columnsincludes\class-fulfillment-orders.php:68
actionmanage_shop_order_posts_custom_columnincludes\class-fulfillment-orders.php:69
filterbulk_actions-woocommerce_page_wc-ordersincludes\class-fulfillment-orders.php:72
filterbulk_actions-edit-shop_orderincludes\class-fulfillment-orders.php:73
filterhandle_bulk_actions-woocommerce_page_wc-ordersincludes\class-fulfillment-orders.php:74
filterhandle_bulk_actions-edit-shop_orderincludes\class-fulfillment-orders.php:75
actionadmin_enqueue_scriptsincludes\class-fulfillment-orders.php:78
actionadmin_footerincludes\class-fulfillment-orders.php:81
actionadmin_noticesincludes\class-fulfillment-orders.php:84
actionadmin_noticesincludes\class-fulfillment-orders.php:87
actionadmin_menuincludes\class-fulfillment-packing-slip.php:62
filterwoocommerce_checkout_fieldsincludes\class-instant-courier.php:24
actionwoocommerce_checkout_update_order_metaincludes\class-instant-courier.php:25
actionwoocommerce_checkout_update_order_reviewincludes\class-instant-courier.php:27
actionwp_enqueue_scriptsincludes\class-instant-courier.php:29
actionwp_headincludes\class-instant-courier.php:30
actionwp_footerincludes\class-instant-courier.php:31
actionadd_meta_boxesincludes\class-instant-courier.php:33
filterwoocommerce_form_field_aw_map_pinpointincludes\class-instant-courier.php:36
actionwoocommerce_review_order_before_paymentincludes\class-insurance.php:29
actionwoocommerce_checkout_update_order_reviewincludes\class-insurance.php:32
actionwoocommerce_cart_calculate_feesincludes\class-insurance.php:39
actionwoocommerce_checkout_create_orderincludes\class-insurance.php:42
actionwoocommerce_thankyouincludes\class-insurance.php:45
actionwoocommerce_order_details_after_order_tableincludes\class-insurance.php:48
actionwoocommerce_email_after_order_tableincludes\class-insurance.php:51
actionwoocommerce_initincludes\class-insurance.php:54
actionadmin_enqueue_scriptsincludes\class-settings.php:32
actionadmin_menuincludes\class-settings.php:33
actioninitincludes\class-settings.php:34
actionadmin_initincludes\class-settings.php:36
actionadd_meta_boxesincludes\class-tracking.php:27
actionwoocommerce_process_shop_order_metaincludes\class-tracking.php:28
actioninitincludes\class-tracking.php:30
actioninitincludes\class-tracking.php:31
filterwc_order_statusesincludes\class-tracking.php:32
actionwp_enqueue_scriptsincludes\class-tracking.php:34
actionwoocommerce_order_details_after_order_tableincludes\class-tracking.php:35
filterwoocommerce_email_classesincludes\class-tracking.php:38
filterwoocommerce_email_actionsincludes\class-tracking.php:41
actionwoocommerce_shipping_initincludes\class-woocommerce-frontend.php:20
filterwoocommerce_shipping_methodsincludes\class-woocommerce-frontend.php:21
filterwoocommerce_checkout_fieldsincludes\class-woocommerce-frontend.php:23
actionwoocommerce_review_order_before_shippingincludes\class-woocommerce-frontend.php:25
actionwoocommerce_before_shipping_calculatorincludes\class-woocommerce-frontend.php:28
actionwoocommerce_cart_calculate_feesincludes\class-woocommerce-frontend.php:31
actionwoocommerce_after_shipping_rateincludes\class-woocommerce-frontend.php:34
actionwoocommerce_cart_calculate_feesincludes\class-woocommerce-frontend.php:37
actionwoocommerce_thankyouincludes\class-woocommerce-frontend.php:40
actionwoocommerce_order_status_completedincludes\class-woocommerce-frontend.php:41
actionwoocommerce_blocks_checkout_order_processedincludes\class-woocommerce-frontend.php:42
actionwoocommerce_checkout_order_processedincludes\class-woocommerce-shipping.php:61
actionwoocommerce_order_status_shipped_notificationincludes\emails\class-wc-email-customer-shipped-order.php:38
actionwoocommerce_order_status_shippedincludes\emails\class-wc-email-customer-shipped-order.php:39
actionwoocommerce_order_status_changedincludes\emails\class-wc-email-customer-shipped-order.php:42
filterwoocommerce_checkout_fieldsincludes\shipping\shipping-frontend.php:31
filterwoocommerce_billing_fieldsincludes\shipping\shipping-frontend.php:34
filterwoocommerce_shipping_fieldsincludes\shipping\shipping-frontend.php:37
filterwoocommerce_shipping_calculator_enable_cityincludes\shipping\shipping-frontend.php:40
filterwoocommerce_get_country_localeincludes\shipping\shipping-frontend.php:43
actionjne_admin_noticesincludes\shipping\shipping-method.php:429
actionwoocommerce_shipping_initincludes\shipping\shipping.php:35
filterwoocommerce_shipping_methodsincludes\shipping\shipping.php:44
filterwoocommerce_shipping_chosen_methodincludes\shipping\shipping.php:47
filterweight_unit_total_weightincludes\shipping\shipping.php:154
filterwoocommerce_agenwebsite_location_api_option_nameincludes\wc-jne-api.php:35
actionwp_enqueue_scriptswoocommerce-jne.php:81
actionbefore_woocommerce_initwoocommerce-jne.php:138
actionadmin_menuwoocommerce-jne.php:146
actionadmin_initwoocommerce-jne.php:375
actionadmin_initwoocommerce-jne.php:401

Scheduled Events 1

aw_api_log_cleanup
Maintenance & Trust

AgenWebsite Shipping – Plugin Ongkos Kirim & Generate Resi Otomatis Semua Kurir Indonesia Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 2, 2026
PHP min version7.4
Downloads54K

Community Trust

Rating90/100
Number of ratings41
Active installs300
Developer Profile

AgenWebsite Shipping – Plugin Ongkos Kirim & Generate Resi Otomatis Semua Kurir Indonesia Developer Profile

agenwebsite

2 plugins · 310 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AgenWebsite Shipping – Plugin Ongkos Kirim & Generate Resi Otomatis Semua Kurir Indonesia

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woocommerce-jne/assets/css/agenwebsite-shipping.css/wp-content/plugins/woocommerce-jne/assets/js/agenwebsite-shipping.js
Script Paths
/wp-content/plugins/woocommerce-jne/assets/js/agenwebsite-shipping.js
Version Parameters
woocommerce-jne/assets/css/agenwebsite-shipping.css?ver=woocommerce-jne/assets/js/agenwebsite-shipping.js?ver=

HTML / DOM Fingerprints

CSS Classes
aw_shipping_settingsagenwebsite_shipping
Data Attributes
data-noncedata-ajax-urldata-public-api-url
JS Globals
aw_shipping
FAQ

Frequently Asked Questions about AgenWebsite Shipping – Plugin Ongkos Kirim & Generate Resi Otomatis Semua Kurir Indonesia