Title: HDWebmobile Shipment Tracking
Author: HDWebMobile
Published: <strong>23. 8. 2026</strong>
Last modified: 23. 8. 2026

---

Prohledat pluginy

![](https://ps.w.org/hdwebmobile-shipment-tracking/assets/banner-772x250.png?rev
=3661407)

![](https://ps.w.org/hdwebmobile-shipment-tracking/assets/icon-256x256.png?rev=3661430)

# HDWebmobile Shipment Tracking

 Autor: [HDWebMobile](https://profiles.wordpress.org/htrxuan/)

[Stáhnout](https://downloads.wordpress.org/plugin/hdwebmobile-shipment-tracking.1.0.0.zip)

 * [Podrobnosti](https://cs.wordpress.org/plugins/hdwebmobile-shipment-tracking/#description)
 * [Hodnocení](https://cs.wordpress.org/plugins/hdwebmobile-shipment-tracking/#reviews)
 *  [Instalace](https://cs.wordpress.org/plugins/hdwebmobile-shipment-tracking/#installation)
 * [Vývojáři](https://cs.wordpress.org/plugins/hdwebmobile-shipment-tracking/#developers)

 [Podpora](https://wordpress.org/support/plugin/hdwebmobile-shipment-tracking/)

## Popis

HDWebmobile Shipment Tracking adds a simple „Shipment Tracking“ section to the WooCommerce
order edit screen. Pick a carrier, enter the tracking number, and the customer sees
it on their order page (both the classic My Account view and the thank-you page)
and receives a „Your order has shipped“ email with a direct link to track their 
package.

Two real 2026 vulnerabilities were researched in this exact plugin category: a stored
XSS in a competing „Shipment Tracker“ plugin caused by unescaped tracking-number/
carrier input, and a SQL injection in a competing plugin’s CSV bulk-import feature.
This plugin closes both by construction — every tracking field is strictly allowlist-
sanitized on save and escaped on every output, and there is no bulk-import feature
at all in this version.

#### Key Features

 * Add a carrier and tracking number directly on the order edit screen — no separate
   settings page needed
 * Predefined carrier list with automatic tracking-link generation: USPS, UPS, FedEx,
   DHL, GHN, GHTK, Vietnam Post, plus a custom-URL option for any other carrier
 * Automatic „Your order has shipped“ email the moment a tracking number is first
   added, with a manual resend option any time after
 * Tracking shown on the customer’s My Account order page and the order-received/
   thank-you page
 * Strict allowlist sanitization on every field, escaped on every output — closes
   the exact stored-XSS class found in a competing plugin
 * Zero bulk-import surface — closes the exact SQL-injection class found in a competing
   plugin’s CSV import feature

#### Limitations (please read before installing)

 * One tracking number per order — no multi-package/partial-shipment support in 
   this version
 * No bulk CSV import — a deliberate security tradeoff, not an oversight; see above
 * No live carrier-API status polling („in transit“ / „delivered“ webhooks) — just
   a link to the carrier’s own tracking page
 * No tracking column on the My Account orders list — tracking is shown on the individual
   order page only

### How to Use

#### 1. Add tracking to an order

Open an order’s edit screen (Screenshot 1), scroll to the „Shipment Tracking“ section,
choose a carrier, enter the tracking number, and click Update.

#### 2. The customer is notified automatically

The first time a tracking number is saved for an order, a „Your order has shipped“
email (Screenshot 2) is sent automatically with a direct tracking link.

#### 3. The customer can see it anytime

The tracking info also appears on the customer’s My Account order page (Screenshot
3) and the order-received/thank-you page, for as long as they’re logged in or hold
the order key.

#### 4. Resend the notification

If you need to resend the shipped email (e.g. the customer says they never got it),
click „Resend shipping notification email“ on the order edit screen — no need to
re-enter the tracking number.

## Snímky obrazovky

[⌊The Shipment Tracking fields on the admin order edit screen.⌉⌊The Shipment Tracking
fields on the admin order edit screen.⌉[

The Shipment Tracking fields on the admin order edit screen.

[⌊The "Your order has shipped" email.⌉⌊The "Your order has shipped" email.⌉[

The „Your order has shipped“ email.

[⌊The Shipping section on the customer's My Account order page.⌉⌊The Shipping section
on the customer's My Account order page.⌉[

The Shipping section on the customer’s My Account order page.

## Instalace

 1. Upload the plugin files to the `/wp-content/plugins/hdwebmobile-shipment-tracking`
    directory, or install the plugin through the WordPress plugins screen directly.
 2. Activate the plugin through the ‚Plugins‘ screen in WordPress. WooCommerce must
    already be installed and active.
 3. Open any order’s edit screen — the Shipment Tracking section appears automatically,
    no configuration needed.

## Recenze

Pro tento plugin nejsou žádné recenze.

## Autoři

HDWebmobile Shipment Tracking je otevřený software. Následující lidé přispěli k 
vývoji tohoto pluginu.

Spolupracovníci

 *   [ HDWebMobile ](https://profiles.wordpress.org/htrxuan/)

[Přeložte “HDWebmobile Shipment Tracking” do svého jazyka.](https://translate.wordpress.org/projects/wp-plugins/hdwebmobile-shipment-tracking)

### Zajímá vás vývoj?

[Prohledejte kód](https://plugins.trac.wordpress.org/browser/hdwebmobile-shipment-tracking/),
podívejte se do [SVN repozitáře](https://plugins.svn.wordpress.org/hdwebmobile-shipment-tracking/),
nebo se přihlaste k[ odběru protokolu vývoje](https://plugins.trac.wordpress.org/log/hdwebmobile-shipment-tracking/)
pomocí [RSS](https://plugins.trac.wordpress.org/log/hdwebmobile-shipment-tracking/?limit=100&mode=stop_on_copy&format=rss).

## Přehled změn

#### 1.0.0

 * Initial release: carrier + tracking number on the order edit screen, automatic
   shipped-notification email, customer-facing tracking display, strict input sanitization
   and output escaping, no bulk-import surface.

## Meta

 *  Verze **1.0.0**
 *  Poslední aktualizace **před 2 měsíce**
 *  Aktivních instalací **Méně než 10**
 *  Verze WordPressu ** 6.9 nebo novější **
 *  Testováno až do WordPressu **7.1.3**
 *  Verze PHP ** 7.4 nebo novější **
 *  Jazyk
 * [English (US)](https://wordpress.org/plugins/hdwebmobile-shipment-tracking/)
 * Štítků
 * [carrier](https://cs.wordpress.org/plugins/tags/carrier/)[order tracking](https://cs.wordpress.org/plugins/tags/order-tracking/)
   [shipment tracking](https://cs.wordpress.org/plugins/tags/shipment-tracking/)
   [shipping](https://cs.wordpress.org/plugins/tags/shipping/)[woocommerce](https://cs.wordpress.org/plugins/tags/woocommerce/)
 *  [Podrobnosti](https://cs.wordpress.org/plugins/hdwebmobile-shipment-tracking/advanced/)

## Hodnocení

Zatím nebyly zadány žádné recenze.

[Vaše hodnocení](https://wordpress.org/support/plugin/hdwebmobile-shipment-tracking/reviews/#new-post)

[Zobrazit všechny recenze](https://wordpress.org/support/plugin/hdwebmobile-shipment-tracking/reviews/)

## Spolupracovníci

 *   [ HDWebMobile ](https://profiles.wordpress.org/htrxuan/)

## Podpora

Potřebujete pomoc?

 [Fórum podpory](https://wordpress.org/support/plugin/hdwebmobile-shipment-tracking/)

## Dary

Chtěli byste podpořit vývoj tohoto pluginu?

 [ Přispět na tento plugin ](https://paypal.me/htrxuan/20)