
Automated Canada Post – HPOS Supported Security & Risk Analysis
wordpress.org/plugins/a2z-canada-post-automated-shippingCanada Post shipping plugin, integrate seamlessly with Canada Post for real-time shipping rates, label printing, automatic tracking number e-mail gene …
Is Automated Canada Post – HPOS Supported Safe to Use in 2026?
Generally Safe
Score 100/100Automated Canada Post – HPOS Supported has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'a2z-canada-post-automated-shipping' plugin v3.1.0 exhibits a mixed security posture. On the positive side, there are no known CVEs, no REST API routes or AJAX handlers without permission callbacks, and all SQL queries utilize prepared statements. The absence of bundled libraries and a seemingly controlled attack surface are also good indicators.
However, significant concerns arise from the static analysis. The presence of the `unserialize` function is a critical risk, as it can lead to remote code execution if used with untrusted input. Furthermore, the taint analysis reveals flows with unsanitized paths, indicating potential vulnerabilities where user-supplied data might be processed insecurely. The low percentage of properly escaped output (58%) suggests a high likelihood of cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the application.
The lack of any recorded vulnerabilities in its history is a strength, but it cannot completely mitigate the risks identified in the current code. The plugin's strengths lie in its structured approach to database interactions and a limited direct attack surface. Nevertheless, the identified risks, particularly `unserialize` usage and unsanitized taint flows, coupled with poor output escaping, present a substantial security threat that requires immediate attention.
Key Concerns
- Unsanitized taint flows found
- Dangerous unserialize function detected
- Low percentage of properly escaped output
- No nonce checks for entry points
- No capability checks for entry points
Automated Canada Post – HPOS Supported Security Vulnerabilities
Automated Canada Post – HPOS Supported Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Automated Canada Post – HPOS Supported Attack Surface
WordPress Hooks 14
Maintenance & Trust
Automated Canada Post – HPOS Supported Maintenance & Trust
Maintenance Signals
Community Trust
Automated Canada Post – HPOS Supported Alternatives
Canada Post Shipping For WooCommerce
canada-post-shipping-for-woocommerce
Add Canada Post as a shipping option for your customers
Shipping Live rates for Canada Post for WooCommerce
octolize-canada-post-shipping
Offer your customers the Canada Post shipping methods with real-time calculated shipping rates for domestic and international shipping.
Automated Canada Post – HPOS Supported Developer Profile
10 plugins · 610 total installs
How We Detect Automated Canada Post – HPOS Supported
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/a2z-canada-post-automated-shipping/asset/js/hit_canadapost_auto.js/wp-content/plugins/a2z-canada-post-automated-shipping/asset/css/hit_canadapost_auto.css/wp-content/plugins/a2z-canada-post-automated-shipping/controllors/views/hit_canadapost_auto_settings_view.phphttps://track.myshipi.com/HTML / DOM Fingerprints
id="shipi_canadapostcontentFramehit_cp_auto