
Free Shipping Bar: Amount Left for Free Shipping for WooCommerce Security & Risk Analysis
wordpress.org/plugins/amount-left-free-shipping-woocommerceShow progress bar for amount left for free shipping using our fully customizable WordPress plugin
Is Free Shipping Bar: Amount Left for Free Shipping for WooCommerce Safe to Use in 2026?
Generally Safe
Score 98/100Free Shipping Bar: Amount Left for Free Shipping for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin "amount-left-free-shipping-woocommerce" v2.5.3 exhibits a mixed security posture. While the static analysis reveals no immediately exploitable dangerous functions, SQL injection vulnerabilities, or external HTTP requests, several areas raise concerns. A significant portion of output is not properly escaped (46%), which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed. Furthermore, the absence of nonce checks and capability checks for the identified entry points (shortcodes) is a notable weakness, potentially allowing for unauthorized actions or information disclosure if these shortcodes are susceptible to manipulation.
The vulnerability history, with two medium-severity CVEs related to Cross-Site Scripting, reinforces the concern about output escaping. Although these vulnerabilities are listed as patched, the pattern suggests a recurring issue with handling user input securely. The last vulnerability occurring in late 2025 implies the data might be forward-looking or represent a hypothetical scenario, but it still points to past exploitable weaknesses. The zero unpatched CVEs is positive, but the historical context warrants caution.
In conclusion, the plugin has strengths in its use of prepared statements for SQL and the absence of critical taint flows. However, the insufficient output escaping and lack of security checks on its shortcode entry points represent significant potential risks. The historical XSS vulnerabilities underscore the need for rigorous code review and testing, especially concerning how user-generated content is handled.
Key Concerns
- Output escaping is insufficient (46% proper)
- No nonce checks on entry points (shortcodes)
- No capability checks on entry points (shortcodes)
- 2 medium severity CVEs in history (XSS)
Free Shipping Bar: Amount Left for Free Shipping for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Free Shipping Bar: Amount Left for Free Shipping for WooCommerce <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Free Shipping Bar: Amount Left for Free Shipping for WooCommerce <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
Free Shipping Bar: Amount Left for Free Shipping for WooCommerce Release Timeline
Free Shipping Bar: Amount Left for Free Shipping for WooCommerce Code Analysis
Output Escaping
Free Shipping Bar: Amount Left for Free Shipping for WooCommerce Attack Surface
Shortcodes 3
WordPress Hooks 22
Maintenance & Trust
Free Shipping Bar: Amount Left for Free Shipping for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Free Shipping Bar: Amount Left for Free Shipping for WooCommerce Alternatives
Weight Based Shipping for WooCommerce
weight-based-shipping-for-woocommerce
Weight Based Shipping is a flexible and widely-used solution to calculate shipping costs based on the total cart weight and value.
Modern Cart – WooCommerce Side Cart & Popup Cart
modern-cart
Modern Cart gives your store a side cart and free shipping bar so shoppers stay on the page, spend more to unlock rewards, and check out in seconds.
Advanced Free Shipping for WooCommerce
woocommerce-advanced-free-shipping
Advanced Free Shipping for WooCommerce is an plugin which allows you to set up advanced free shipping conditions.
WC Hide Shipping Methods
wc-hide-shipping-methods
This plugin automatically hides all other shipping methods when "Free Shipping" is available, while allowing you to retain "Local Picku …
Hide Shipping Method For WooCommerce
hide-shipping-method-for-woocommerce
Allows store owners to hide shipping methods based on specific conditions!
Free Shipping Bar: Amount Left for Free Shipping for WooCommerce Developer Profile
64 plugins · 137K total installs
How We Detect Free Shipping Bar: Amount Left for Free Shipping for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/amount-left-free-shipping-woocommerce/assets/css/alg-wc-alfs.css/wp-content/plugins/amount-left-free-shipping-woocommerce/assets/js/alg-wc-alfs.jsassets/js/alg-wc-alfs.jsamount-left-free-shipping-woocommerce/assets/css/alg-wc-alfs.css?ver=amount-left-free-shipping-woocommerce/assets/js/alg-wc-alfs.js?ver=HTML / DOM Fingerprints
alg-wc-alfs-messagedata-alg-wc-alfs[alg_get_left_to_free_shipping][alg_wc_left_to_free_shipping][alg_wc_left_to_free_shipping_translate]