API2Cart Live Shipping 4 Woocommerce Security & Risk Analysis

wordpress.org/plugins/api2cart-live-shipping-4-woocommerce

This plugin allows to use of real-time shipping rates provided by third-party shipping services.

30 active installs v1.4.2 PHP 5.6+ WP 4.5+ Updated Apr 30, 2025
api2cartlive-shipping-rateswoocommercewoocommerce-live-shippingwoocommerce-plugin
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is API2Cart Live Shipping 4 Woocommerce Safe to Use in 2026?

Generally Safe

Score 100/100

API2Cart Live Shipping 4 Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "api2cart-live-shipping-4-woocommerce" plugin version 1.4.2 exhibits a strong security posture based on the provided static analysis, with no apparent attack surface exposed through common entry points like AJAX handlers, REST API, shortcodes, or cron events. The absence of dangerous functions and a clean taint analysis with zero unsanitized paths further reinforce this. The vulnerability history is also clean, indicating a potentially well-maintained codebase.

However, significant concerns arise from the code signals. The complete lack of capability checks and nonce checks, combined with the absence of input validation or output escaping on all observed outputs, creates a substantial risk. Furthermore, all SQL queries are performed without prepared statements, leaving the plugin vulnerable to SQL injection attacks. The presence of file operations without context on their security implications also warrants caution. While the plugin has no known CVEs, the internal code analysis reveals potential weaknesses that could be exploited.

In conclusion, while the plugin has a clean vulnerability history and a seemingly small attack surface, the lack of fundamental security practices like proper authentication checks, input sanitization, and secure SQL query execution presents a high risk. The absence of capability checks is particularly alarming in a WordPress plugin context. This suggests that while the plugin may not have been historically targeted or discovered to be vulnerable, its current implementation has significant inherent security flaws that need immediate attention.

Key Concerns

  • No capability checks found
  • No nonce checks found
  • SQL queries not using prepared statements (3/3)
  • Output escaping not performed (1/1)
  • File operations without security context
Vulnerabilities
None known

API2Cart Live Shipping 4 Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

API2Cart Live Shipping 4 Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
5
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared3 total queries

Output Escaping

0% escaped1 total outputs
Attack Surface

API2Cart Live Shipping 4 Woocommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionrest_api_initapi2cart-live-shipping-4-woocommerce.php:56
filterwoocommerce_shipping_methodsapi2cart-live-shipping-4-woocommerce.php:236
actionplugins_loadedapi2cart-live-shipping-4-woocommerce.php:346
actionadmin_noticesapi2cart-live-shipping-4-woocommerce.php:347
Maintenance & Trust

API2Cart Live Shipping 4 Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 30, 2025
PHP min version5.6
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

API2Cart Live Shipping 4 Woocommerce Developer Profile

Developer

3 plugins · 120 total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
452 days
View full developer profile
Detection Fingerprints

How We Detect API2Cart Live Shipping 4 Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
api2cart-live-shipping-4-woocommerce/includes/class-a2c-live-shipping-rest-api-controller.php?ver=api2cart-live-shipping-4-woocommerce/app/A2c_Live_Shipping_Service.php?ver=api2cart-live-shipping-4-woocommerce/app/A2c_Live_Shipping_Exception.php?ver=api2cart-live-shipping-4-woocommerce/includes/class-a2c-live-shipping-rest-api-controller.php?ver=1.4.1api2cart-live-shipping-4-woocommerce/app/A2c_Live_Shipping_Service.php?ver=1.4.1api2cart-live-shipping-4-woocommerce/app/A2c_Live_Shipping_Exception.php?ver=1.4.1

HTML / DOM Fingerprints

JS Globals
A2c_Live_Shipping_Service
REST Endpoints
/wp-json/a2c_ls/v1/services/wp-json/a2c_ls/v1/methods
FAQ

Frequently Asked Questions about API2Cart Live Shipping 4 Woocommerce