{"id":354585,"date":"2026-08-23T05:12:17","date_gmt":"2026-08-23T05:12:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/hdwebmobile-shipment-tracking\/"},"modified":"2026-08-23T05:11:52","modified_gmt":"2026-08-23T05:11:52","slug":"hdwebmobile-shipment-tracking","status":"publish","type":"plugin","link":"https:\/\/vi.wordpress.org\/plugins\/hdwebmobile-shipment-tracking\/","author":9757813,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"7.1","requires":"6.9","requires_php":"7.4","requires_plugins":null,"header_name":"HDWebmobile Shipment Tracking","header_author":"htrxuan - Han Tran","header_description":"Add a carrier and tracking number to any order and show it to the customer -- on their order page, in a \"Your order has shipped\" email, with strict output escaping and no bulk-import surface.","assets_banners_color":"327864","last_updated":"2026-08-23 05:11:52","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/paypal.me\/htrxuan\/20","header_plugin_uri":"https:\/\/hdwebmobile.com\/plugins\/hdwebmobile-shipment-tracking\/","header_author_uri":"https:\/\/hdwebmobile.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":43,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"htrxuan","date":"2026-08-23 05:11:52"}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3661430,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3661430,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3661407,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3661407,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3661407,"resolution":"1","location":"assets","locale":"","width":1600,"height":1000},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3661407,"resolution":"2","location":"assets","locale":"","width":1600,"height":1000},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3661407,"resolution":"3","location":"assets","locale":"","width":1600,"height":1000}},"screenshots":{"1":"The Shipment Tracking fields on the admin order edit screen.","2":"The \"Your order has shipped\" email.","3":"The Shipping section on the customer's My Account order page."}},"plugin_section":[],"plugin_tags":[5566,45369,55977,3546,286],"plugin_category":[45],"plugin_contributors":[254181],"plugin_business_model":[],"class_list":["post-354585","plugin","type-plugin","status-publish","hentry","plugin_tags-carrier","plugin_tags-order-tracking","plugin_tags-shipment-tracking","plugin_tags-shipping","plugin_tags-woocommerce","plugin_category-ecommerce","plugin_contributors-htrxuan","plugin_committers-htrxuan"],"banners":{"banner":"https:\/\/ps.w.org\/hdwebmobile-shipment-tracking\/assets\/banner-772x250.png?rev=3661407","banner_2x":"https:\/\/ps.w.org\/hdwebmobile-shipment-tracking\/assets\/banner-1544x500.png?rev=3661407","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/hdwebmobile-shipment-tracking\/assets\/icon-128x128.png?rev=3661430","icon_2x":"https:\/\/ps.w.org\/hdwebmobile-shipment-tracking\/assets\/icon-256x256.png?rev=3661430","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/hdwebmobile-shipment-tracking\/assets\/screenshot-1.png?rev=3661407","caption":"The Shipment Tracking fields on the admin order edit screen."},{"src":"https:\/\/ps.w.org\/hdwebmobile-shipment-tracking\/assets\/screenshot-2.png?rev=3661407","caption":"The \"Your order has shipped\" email."},{"src":"https:\/\/ps.w.org\/hdwebmobile-shipment-tracking\/assets\/screenshot-3.png?rev=3661407","caption":"The Shipping section on the customer's My Account order page."}],"raw_content":"<!--section=description-->\n<p>HDWebmobile Shipment Tracking adds a simple \"Shipment Tracking\" section to the WooCommerce order edit screen. Pick a carrier, enter the tracking number, and the customer sees it on their order page (both the classic My Account view and the thank-you page) and receives a \"Your order has shipped\" email with a direct link to track their package.<\/p>\n\n<p>Two real 2026 vulnerabilities were researched in this exact plugin category: a stored XSS in a competing \"Shipment Tracker\" plugin caused by unescaped tracking-number\/carrier input, and a SQL injection in a competing plugin's CSV bulk-import feature. This plugin closes both by construction -- every tracking field is strictly allowlist-sanitized on save and escaped on every output, and there is no bulk-import feature at all in this version.<\/p>\n\n<h4>Key Features<\/h4>\n\n<ul>\n<li>Add a carrier and tracking number directly on the order edit screen -- no separate settings page needed<\/li>\n<li>Predefined carrier list with automatic tracking-link generation: USPS, UPS, FedEx, DHL, GHN, GHTK, Vietnam Post, plus a custom-URL option for any other carrier<\/li>\n<li>Automatic \"Your order has shipped\" email the moment a tracking number is first added, with a manual resend option any time after<\/li>\n<li>Tracking shown on the customer's My Account order page and the order-received\/thank-you page<\/li>\n<li>Strict allowlist sanitization on every field, escaped on every output -- closes the exact stored-XSS class found in a competing plugin<\/li>\n<li>Zero bulk-import surface -- closes the exact SQL-injection class found in a competing plugin's CSV import feature<\/li>\n<\/ul>\n\n<h4>Limitations (please read before installing)<\/h4>\n\n<ul>\n<li>One tracking number per order -- no multi-package\/partial-shipment support in this version<\/li>\n<li>No bulk CSV import -- a deliberate security tradeoff, not an oversight; see above<\/li>\n<li>No live carrier-API status polling (\"in transit\" \/ \"delivered\" webhooks) -- just a link to the carrier's own tracking page<\/li>\n<li>No tracking column on the My Account orders list -- tracking is shown on the individual order page only<\/li>\n<\/ul>\n\n<h3>How to Use<\/h3>\n\n<h4>1. Add tracking to an order<\/h4>\n\n<p>Open an order's edit screen (Screenshot 1), scroll to the \"Shipment Tracking\" section, choose a carrier, enter the tracking number, and click Update.<\/p>\n\n<h4>2. The customer is notified automatically<\/h4>\n\n<p>The first time a tracking number is saved for an order, a \"Your order has shipped\" email (Screenshot 2) is sent automatically with a direct tracking link.<\/p>\n\n<h4>3. The customer can see it anytime<\/h4>\n\n<p>The tracking info also appears on the customer's My Account order page (Screenshot 3) and the order-received\/thank-you page, for as long as they're logged in or hold the order key.<\/p>\n\n<h4>4. Resend the notification<\/h4>\n\n<p>If you need to resend the shipped email (e.g. the customer says they never got it), click \"Resend shipping notification email\" on the order edit screen -- no need to re-enter the tracking number.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin files to the <code>\/wp-content\/plugins\/hdwebmobile-shipment-tracking<\/code> directory, or install the plugin through the WordPress plugins screen directly.<\/li>\n<li>Activate the plugin through the 'Plugins' screen in WordPress. WooCommerce must already be installed and active.<\/li>\n<li>Open any order's edit screen -- the Shipment Tracking section appears automatically, no configuration needed.<\/li>\n<\/ol>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release: carrier + tracking number on the order edit screen, automatic shipped-notification email, customer-facing tracking display, strict input sanitization and output escaping, no bulk-import surface.<\/li>\n<\/ul>","raw_excerpt":"Add a carrier and tracking number to any order and show it to the customer -- no bulk-import surface, strict output escaping.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/354585","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=354585"}],"author":[{"embeddable":true,"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/htrxuan"}],"wp:attachment":[{"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=354585"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=354585"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=354585"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=354585"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=354585"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/vi.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=354585"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}