DropStream – Automated eCommerce Fulfillment Security & Risk Analysis

wordpress.org/plugins/wp-dropstream

DropStream is a powerful eCommerce plugin that integrates your WordPress site with your shipping solution or third-party fulfillment provider, allowin …

90 active installs v1.2.3 PHP + WP 4.0+ Updated Jul 22, 2022
e-commerceecommercefulfillmentwoocommercewp-e-commerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is DropStream – Automated eCommerce Fulfillment Safe to Use in 2026?

Generally Safe

Score 85/100

DropStream – Automated eCommerce Fulfillment has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The static analysis of wp-dropstream v1.2.3 reveals an exceptionally clean codebase with no identified dangerous functions, SQL injection vulnerabilities due to the exclusive use of prepared statements, and all output properly escaped. Furthermore, the absence of file operations, external HTTP requests, and a zero-count for taint flows with unsanitized paths are all strong indicators of robust security practices within the plugin's code. The vulnerability history also shows a complete lack of any recorded CVEs, reinforcing the impression of a secure and well-maintained plugin.

However, the analysis also highlights a significant concern: the complete absence of any nonces or capability checks across all identified entry points (AJAX handlers, REST API routes, shortcodes, cron events). While the current attack surface is reported as zero, this lack of security controls on potential future entry points or even on the existing (though currently zero) handlers creates a substantial risk. If any entry points were to be added or if the zero-count is an anomaly of the static analysis tool's scope, these would be entirely unprotected. This reliance on the absence of entry points rather than explicit security measures is a weakness. The plugin's current security posture is excellent in terms of code quality and history, but its lack of fundamental security controls on its potential interaction points presents a notable, albeit currently unrealized, risk.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

DropStream – Automated eCommerce Fulfillment Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

DropStream – Automated eCommerce Fulfillment Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
7 prepared
Unescaped Output
0
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared7 total queries

Output Escaping

100% escaped3 total outputs
Attack Surface

DropStream – Automated eCommerce Fulfillment Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
filterwp_mail_frominc\adapters\wp_e_commerce.php:130
filterwp_mail_from_nameinc\adapters\wp_e_commerce.php:131
filterwp_mail_content_typeinc\adapters\wp_e_commerce.php:132
filterxmlrpc_methodswp-dropstream.php:38
filterwc_order_statuseswp-dropstream.php:204
actioninitwp-dropstream.php:207
filterwoocommerce_reports_order_statuseswp-dropstream.php:212
filterwc_order_statuseswp-dropstream.php:213
actionadmin_initwp-dropstream.php:216
actionplugins_loadedwp-dropstream.php:221
Maintenance & Trust

DropStream – Automated eCommerce Fulfillment Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedJul 22, 2022
PHP min version
Downloads9K

Community Trust

Rating0/100
Number of ratings0
Active installs90
Developer Profile

DropStream – Automated eCommerce Fulfillment Developer Profile

karlfalconer

1 plugin · 90 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DropStream – Automated eCommerce Fulfillment

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about DropStream – Automated eCommerce Fulfillment