
PiWeb Flat rate / Conditional shipping for WooCommerce Security & Risk Analysis
wordpress.org/plugins/advanced-free-flat-shipping-woocommerceWooCommerce conditional shipping & WooCommerce Advanced Flat rate shipping rates plugin to Create Advanced Flat rate shipping or Free shipping met …
Is PiWeb Flat rate / Conditional shipping for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100PiWeb Flat rate / Conditional shipping for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "advanced-free-flat-shipping-woocommerce" plugin, version 1.6.6.1, exhibits a mixed security posture. While it demonstrates good practices like using prepared statements for all SQL queries and a high percentage of properly escaped output, there are notable areas of concern. The presence of 3 AJAX handlers without authentication checks represents a significant attack surface that could be exploited by unauthenticated users, potentially leading to unintended actions or data exposure. The taint analysis revealed one flow with an unsanitized path, which, although not rated as critical or high severity, still warrants attention as it could indicate a potential for certain types of input to be processed in an unsafe manner. The vulnerability history shows one previously identified medium severity CVE, a Cross-Site Request Forgery (CSRF), which has since been patched. The fact that there are no currently unpatched vulnerabilities is a positive sign. Overall, while the plugin has strengths in data handling and output escaping, the unprotected AJAX endpoints and the identified unsanitized path are key weaknesses that require remediation to improve its security.
Key Concerns
- Unprotected AJAX handlers found
- Flow with unsanitized path identified
- Past medium severity CVE (CSRF)
PiWeb Flat rate / Conditional shipping for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Advanced Flat rate shipping Woocommerce <= 1.6.4.4 - Cross-Site Request Forgery via enableDisable and deletePost
PiWeb Flat rate / Conditional shipping for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
PiWeb Flat rate / Conditional shipping for WooCommerce Attack Surface
AJAX Handlers 9
WordPress Hooks 57
Maintenance & Trust
PiWeb Flat rate / Conditional shipping for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
PiWeb Flat rate / Conditional shipping for WooCommerce Alternatives
Flat Rate Shipping Method for WooCommerce
woo-extra-flat-rate
Create flexible flat rate shipping methods with custom rules i.e. for specific products or countries where the products will be shipped to.
Codiepress Advanced Rule Based Shipping for WooCommerce, Table Rate Shipping Methods, Weight Based Shipping
advanced-rule-based-shipping
Transform your WooCommerce store with Advanced Rule Based Shipping methods! Enjoy flexible options like table rates, weight-based, and flat rates!
PrangoShip [Quantity Based] for WooCommerce
woo-quantity-based-shipping-rate
Lets you assign shipping rates based on the quantity of items in the cart for your WooCommerce Store.
Weight Based Shipping Table Rate for WooCommerce – Flexible Shipping
flexible-shipping
Weight based shipping methods for WooCommerce. Flexible shipping with table rate rules by cart weight and order value. Accurate rates at checkout.
Weight Based Shipping for WooCommerce
weight-based-shipping-for-woocommerce
Weight Based Shipping is a flexible and widely-used solution to calculate shipping costs based on the total cart weight and value.
PiWeb Flat rate / Conditional shipping for WooCommerce Developer Profile
30 plugins · 93K total installs
How We Detect PiWeb Flat rate / Conditional shipping for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-free-flat-shipping-woocommerce/admin/css/jquery-confirm.min.css/wp-content/plugins/advanced-free-flat-shipping-woocommerce/admin/js/jquery-confirm.min.js/wp-content/plugins/advanced-free-flat-shipping-woocommerce/admin/js/extended-flat-rate-shipping-woocommerce-admin.js/wp-content/plugins/advanced-free-flat-shipping-woocommerce/admin/js/extended-flat-rate-shipping-additional-charges.jsadmin/js/jquery-confirm.min.jsadmin/js/extended-flat-rate-shipping-woocommerce-admin.jsadmin/js/extended-flat-rate-shipping-additional-charges.jsadvanced-free-flat-shipping-woocommerce/admin/css/jquery-confirm.min.css?ver=advanced-free-flat-shipping-woocommerce/admin/js/jquery-confirm.min.js?ver=advanced-free-flat-shipping-woocommerce/admin/js/extended-flat-rate-shipping-woocommerce-admin.js?ver=advanced-free-flat-shipping-woocommerce/admin/js/extended-flat-rate-shipping-additional-charges.js?ver=HTML / DOM Fingerprints
pi-efrs-admin-page<!-- Pi Websolution Shipping Add On Starts --><!-- Pi Websolution Shipping Add On Ends -->data-plugin-namedata-versionpi_efrs_setting_datapi_efrs_pro_data