ZeroV99 Shipment Tracking Security & Risk Analysis
wordpress.org/plugins/zerov99-shipment-trackingAdd a 'Shipped' status to WooCommerce orders, track shipments, and provide real-time updates to customers effortlessly.
Is ZeroV99 Shipment Tracking Safe to Use in 2026?
Generally Safe
Score 100/100ZeroV99 Shipment Tracking has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The zerov99-shipment-tracking plugin v1.0.3 exhibits a generally strong security posture based on the provided static analysis. The absence of direct SQL injection risks due to 100% prepared statement usage, a high percentage of properly escaped output, and no detected file operations or external HTTP requests are positive indicators. Furthermore, the complete lack of known vulnerabilities (CVEs) in its history suggests a well-maintained and secure codebase over time.
However, a significant concern arises from the absence of capability checks on the identified AJAX handler. While there is only one AJAX handler, and it is protected by a nonce check, the lack of an explicit capability check means that any authenticated user, regardless of their role or permissions, could potentially interact with this endpoint. This could lead to unintended actions or data manipulation if the functionality accessible via the AJAX handler is sensitive.
In conclusion, the plugin demonstrates good development practices in several key areas. The absence of critical vulnerabilities and the robust handling of SQL queries and output are commendable. Nevertheless, the missing capability check on the AJAX handler represents a potential weakness that could be exploited by authenticated attackers with lower privileges. Addressing this would further strengthen the plugin's security.
Key Concerns
- Missing capability checks on AJAX
ZeroV99 Shipment Tracking Security Vulnerabilities
ZeroV99 Shipment Tracking Code Analysis
SQL Query Safety
Output Escaping
ZeroV99 Shipment Tracking Attack Surface
AJAX Handlers 1
WordPress Hooks 18
Maintenance & Trust
ZeroV99 Shipment Tracking Maintenance & Trust
Maintenance Signals
Community Trust
ZeroV99 Shipment Tracking Alternatives
Advanced Shipment Tracking for WooCommerce
woo-advanced-shipment-tracking
Add shipment tracking info to WooCommerce orders, send tracking numbers to customers via email, and let them track deliveries from My Account.
Orders Tracking for WooCommerce
woo-orders-tracking
Easily import/manage your tracking numbers, add tracking numbers to PayPal and send email notifications to customers.
AfterShip Tracking – All-In-One WooCommerce Order Tracking (Free plan available)
aftership-woocommerce-tracking
Track orders in one place. shipment tracking, automated notifications, order lookup, branded tracking page, delivery day prediction
ParcelWILL (Formerly ParcelPanel) – Shipment Tracking, Tracking & Order Tracking for WooCommerce
parcelpanel
Free Plan Available. Order Tracking, Shipment Tracking. The best WooCommerce Order Tracker for Track Order Status & Delivery Notifications
TrackShip for WooCommerce
trackship-for-woocommerce
TrackShip auto-tracks orders, adds a branded tracking experience to your store and handles all customer touchpoints from shipping to delivery
ZeroV99 Shipment Tracking Developer Profile
2 plugins · 0 total installs
How We Detect ZeroV99 Shipment Tracking
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zerov99-shipment-tracking/assets/js/zerov99-shipment-tracking-admin-deactivate-confirm.min.js/wp-content/plugins/zerov99-shipment-tracking/assets/js/zerov99-shipment-tracking-admin-deactivate-confirm.js/wp-content/plugins/zerov99-shipment-tracking/assets/css/zerov99-orders-styles.min.css/wp-content/plugins/zerov99-shipment-tracking/assets/css/zerov99-orders-styles.css/wp-content/plugins/zerov99-shipment-tracking/assets/js/zerov99-combined-orders.min.js/wp-content/plugins/zerov99-shipment-tracking/assets/js/zerov99-combined-orders.js/wp-content/plugins/zerov99-shipment-tracking/assets/css/zerov99-shipping-providers.min.css/wp-content/plugins/zerov99-shipment-tracking/assets/css/zerov99-shipping-providers.css+2 more/wp-content/plugins/zerov99-shipment-tracking/assets/js/zerov99-shipment-tracking-admin-deactivate-confirm.js/wp-content/plugins/zerov99-shipment-tracking/assets/js/zerov99-combined-orders.js/wp-content/plugins/zerov99-shipment-tracking/assets/js/zerov99-settings.jszerov99-shipment-tracking/assets/js/zerov99-shipment-tracking-admin-deactivate-confirm.js?ver=zerov99-shipment-tracking/assets/css/zerov99-orders-styles.css?ver=zerov99-shipment-tracking/assets/js/zerov99-combined-orders.js?ver=zerov99-shipment-tracking/assets/css/zerov99-shipping-providers.css?ver=zerov99-shipment-tracking/assets/js/zerov99-settings.js?ver=HTML / DOM Fingerprints
order-statusstatus-shippeddata-deactivate-confirmzerov99Adminzerov99Data