HDWebmobile Shipment Tracking adds a simple "Shipment Tracking" section to the WooCommerce order edit screen. Pick a carrier, enter the tracking number, and the customer sees it on their order page (both the classic My Account view and the thank-you page) and receives a "Your order has shipped" email with a direct link to track their package.
Two real 2026 vulnerabilities were researched in this exact plugin category: a stored XSS in a competing "Shipment Tracker" plugin caused by unescaped tracking-number/carrier input, and a SQL injection in a competing plugin's CSV bulk-import feature. This plugin closes both by construction -- every tracking field is strictly allowlist-sanitized on save and escaped on every output, and there is no bulk-import feature at all in this version.
Key Features
- Add a carrier and tracking number directly on the order edit screen -- no separate settings page needed
- Predefined carrier list with automatic tracking-link generation: USPS, UPS, FedEx, DHL, GHN, GHTK, Vietnam Post, plus a custom-URL option for any other carrier
- Automatic "Your order has shipped" email the moment a tracking number is first added, with a manual resend option any time after
- Tracking shown on the customer's My Account order page and the order-received/thank-you page
- Strict allowlist sanitization on every field, escaped on every output -- closes the exact stored-XSS class found in a competing plugin
- Zero bulk-import surface -- closes the exact SQL-injection class found in a competing plugin's CSV import feature
Limitations (please read before installing)
- One tracking number per order -- no multi-package/partial-shipment support in this version
- No bulk CSV import -- a deliberate security tradeoff, not an oversight; see above
- No live carrier-API status polling ("in transit" / "delivered" webhooks) -- just a link to the carrier's own tracking page
- No tracking column on the My Account orders list -- tracking is shown on the individual order page only