
MyParcel Security & Risk Analysis
wordpress.org/plugins/woocommerce-myparcelExport your WooCommerce orders to MyParcel (www.myparcel.nl) and print labels directly from the WooCommerce admin
Is MyParcel Safe to Use in 2026?
Generally Safe
Score 99/100MyParcel has a strong security track record. Known vulnerabilities have been patched promptly.
The WooCommerce MyParcel plugin v4.24.3 presents a mixed security posture. While it demonstrates good practices in using prepared statements for SQL queries and generally escapes output effectively, significant concerns arise from its attack surface. A substantial number of AJAX handlers lack proper authentication checks, creating a considerable risk for unauthorized actions. The presence of the `unserialize` function is also a point of concern, especially if it processes user-supplied input without robust sanitization.
The vulnerability history shows a past medium-severity Cross-Site Scripting (XSS) vulnerability. Although there are no currently unpatched CVEs, this history indicates that the plugin has had security weaknesses in the past, suggesting a need for ongoing vigilance. The lack of taint analysis results is noted, but the existing code signals are more immediately indicative of potential risks. The plugin's strengths lie in its SQL handling and output escaping, but the unprotected entry points and the `unserialize` function are areas that require immediate attention to mitigate potential security threats.
Key Concerns
- High number of unprotected AJAX handlers
- Presence of unserialize function
- Medium severity CVE in history
MyParcel Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
MyParcel <= 4.24.1 - Reflected Cross-Site Scripting
MyParcel Code Analysis
Dangerous Functions Found
Output Escaping
MyParcel Attack Surface
AJAX Handlers 7
Shortcodes 1
WordPress Hooks 83
Maintenance & Trust
MyParcel Maintenance & Trust
Maintenance Signals
Community Trust
MyParcel Alternatives
Claudio Sanches – Correios for WooCommerce
woocommerce-correios
Integration between the Correios and WooCommerce
Shiprocket
shiprocket
Auto Sync your Woocommerce store orders & ship them at lowest shipping rates. Automate your shipping, save time & money.
YITH WooCommerce Order & Shipment Tracking
yith-woocommerce-order-tracking
Add an easy tool to manage order shipping information of your shop and to notified your customers about the shipping.
Frenet Shipping Gateway for WooCommerce – Correios, Etiquetas e Rastreio
woo-shipping-gateway
Frete inteligente, simples e acessível para negócios que querem crescer
CDEKDelivery
cdekdelivery
Integration with CDEK delivery for your WooCommerce store.
MyParcel Developer Profile
2 plugins · 10K total installs
How We Detect MyParcel
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woocommerce-myparcel/assets/css/admin/checkout.css/wp-content/plugins/woocommerce-myparcel/assets/css/admin/settings.css/wp-content/plugins/woocommerce-myparcel/assets/css/admin/style.css/wp-content/plugins/woocommerce-myparcel/assets/css/frontend/checkout.css/wp-content/plugins/woocommerce-myparcel/assets/css/frontend/style.css/wp-content/plugins/woocommerce-myparcel/assets/js/admin/order-edit.js/wp-content/plugins/woocommerce-myparcel/assets/js/admin/settings.js/wp-content/plugins/woocommerce-myparcel/assets/js/frontend/checkout.js+2 morewoocommerce-myparcel/assets/css/admin/checkout.css?ver=woocommerce-myparcel/assets/css/admin/settings.css?ver=woocommerce-myparcel/assets/css/admin/style.css?ver=woocommerce-myparcel/assets/css/frontend/checkout.css?ver=woocommerce-myparcel/assets/css/frontend/style.css?ver=woocommerce-myparcel/assets/js/admin/order-edit.js?ver=woocommerce-myparcel/assets/js/admin/settings.js?ver=woocommerce-myparcel/assets/js/frontend/checkout.js?ver=woocommerce-myparcel/assets/js/frontend/track-trace.js?ver=woocommerce-myparcel/assets/js/admin/main.js?ver=HTML / DOM Fingerprints
myparcel-admin-settingsmyparcel-checkout-delivery-optionsmyparcel-track-trace-container<!-- MyParcel Widget Start --><!-- MyParcel Widget End --><!-- MyParcel delivery options --><!-- MyParcel Track & Trace -->data-myparcel-country-codedata-myparcel-api-keydata-myparcel-order-idwc_myparcel_checkout_paramsMyParcel/wp-json/myparcelnl/v1/delivery-options/wp-json/myparcelnl/v1/shipments