HDWebmobile Shipment Tracking

Àpèjúwe

HDWebmobile Shipment Tracking adds a simple “Shipment Tracking” section to the WooCommerce order edit screen. Pick a carrier, enter the tracking number, and the customer sees it on their order page (both the classic My Account view and the thank-you page) and receives a “Your order has shipped” email with a direct link to track their package.

Two real 2026 vulnerabilities were researched in this exact plugin category: a stored XSS in a competing “Shipment Tracker” plugin caused by unescaped tracking-number/carrier input, and a SQL injection in a competing pluginÌtumọ̀ Yorùbá: ’s CSV bulk-import feature. This plugin closes both by construction Ìtumọ̀ Yorùbá: — every tracking field is strictly allowlist-sanitized on save and escaped on every output, and there is no bulk-import feature at all in this version.

Key Features

  • Add a carrier and tracking number directly on the order edit screen Ìtumọ̀ Yorùbá: — no separate settings page needed
  • Predefined carrier list with automatic tracking-link generation: USPS, UPS, FedEx, DHL, GHN, GHTK, Vietnam Post, plus a custom-URL option for any other carrier
  • Automatic “Your order has shipped” email the moment a tracking number is first added, with a manual resend option any time after
  • Tracking shown on the customerÌtumọ̀ Yorùbá: ’s My Account order page and the order-received/thank-you page
  • Strict allowlist sanitization on every field, escaped on every output Ìtumọ̀ Yorùbá: — closes the exact stored-XSS class found in a competing plugin
  • Zero bulk-import surface Ìtumọ̀ Yorùbá: — closes the exact SQL-injection class found in a competing pluginÌtumọ̀ Yorùbá: ’s CSV import feature

Limitations (please read before installing)

  • One tracking number per order Ìtumọ̀ Yorùbá: — no multi-package/partial-shipment support in this version
  • No bulk CSV import Ìtumọ̀ Yorùbá: — a deliberate security tradeoff, not an oversight; see above
  • No live carrier-API status polling (“in transit” / “delivered” webhooks) Ìtumọ̀ Yorùbá: — just a link to the carrierÌtumọ̀ Yorùbá: ’s own tracking page
  • No tracking column on the My Account orders list Ìtumọ̀ Yorùbá: — tracking is shown on the individual order page only

How to Use

1. Add tracking to an order

Open an orderÌtumọ̀ Yorùbá: ’s edit screen (Screenshot 1), scroll to the “Shipment Tracking” section, choose a carrier, enter the tracking number, and click Update.

2. The customer is notified automatically

The first time a tracking number is saved for an order, a “Your order has shipped” email (Screenshot 2) is sent automatically with a direct tracking link.

3. The customer can see it anytime

The tracking info also appears on the customerÌtumọ̀ Yorùbá: ’s My Account order page (Screenshot 3) and the order-received/thank-you page, for as long as theyÌtumọ̀ Yorùbá: ’re logged in or hold the order key.

4. Resend the notification

If you need to resend the shipped email (e.g. the customer says they never got it), click “Resend shipping notification email” on the order edit screen Ìtumọ̀ Yorùbá: — no need to re-enter the tracking number.

Àwọn àwòrán ìbòjú

Ìgbéwọlẹ̀

  1. Upload the plugin files to the /wp-content/plugins/hdwebmobile-shipment-tracking directory, or install the plugin through the WordPress plugins screen directly.
  2. Activate the plugin through the ‘Plugins’ screen in WordPress. WooCommerce must already be installed and active.
  3. Open any orderÌtumọ̀ Yorùbá: ’s edit screen Ìtumọ̀ Yorùbá: — the Shipment Tracking section appears automatically, no configuration needed.

Àwọn àgbéyẹ̀wò

Kò sí àwọn àgbéyẹ̀wò fún plugin yìí.

Àwọn Olùkópa & Olùgbéejáde

“HDWebmobile Shipment Tracking” jẹ́ ètò ìṣàmúlò orísun ṣíṣí sílẹ̀. Àwọn ènìyàn wọ̀nyí ti ṣe ìkópa sí plugin yìí.

Àwọn Olùkópa

Túmọ̀ “HDWebmobile Shipment Tracking” sí èdè rẹ.

Ṣe o nífẹ̀ẹ́ sí ìdàgbàsókè?

Ṣàwárí koodu, ṣàyẹ̀wò ibi ìpamọ́ SVN, tàbí ṣe àgbékalẹ̀ sí àkọsílẹ̀ ìdàgbàsókè nípasẹ̀ RSS.

Àkọsílẹ̀ àwọn àyípadà

1.0.0

  • Initial release: carrier + tracking number on the order edit screen, automatic shipped-notification email, customer-facing tracking display, strict input sanitization and output escaping, no bulk-import surface.