
API2Cart Live Shipping 4 Woocommerce Security & Risk Analysis
wordpress.org/plugins/api2cart-live-shipping-4-woocommerceThis plugin allows to use of real-time shipping rates provided by third-party shipping services.
Is API2Cart Live Shipping 4 Woocommerce Safe to Use in 2026?
Generally Safe
Score 100/100API2Cart Live Shipping 4 Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "api2cart-live-shipping-4-woocommerce" plugin version 1.4.2 exhibits a strong security posture based on the provided static analysis, with no apparent attack surface exposed through common entry points like AJAX handlers, REST API, shortcodes, or cron events. The absence of dangerous functions and a clean taint analysis with zero unsanitized paths further reinforce this. The vulnerability history is also clean, indicating a potentially well-maintained codebase.
However, significant concerns arise from the code signals. The complete lack of capability checks and nonce checks, combined with the absence of input validation or output escaping on all observed outputs, creates a substantial risk. Furthermore, all SQL queries are performed without prepared statements, leaving the plugin vulnerable to SQL injection attacks. The presence of file operations without context on their security implications also warrants caution. While the plugin has no known CVEs, the internal code analysis reveals potential weaknesses that could be exploited.
In conclusion, while the plugin has a clean vulnerability history and a seemingly small attack surface, the lack of fundamental security practices like proper authentication checks, input sanitization, and secure SQL query execution presents a high risk. The absence of capability checks is particularly alarming in a WordPress plugin context. This suggests that while the plugin may not have been historically targeted or discovered to be vulnerable, its current implementation has significant inherent security flaws that need immediate attention.
Key Concerns
- No capability checks found
- No nonce checks found
- SQL queries not using prepared statements (3/3)
- Output escaping not performed (1/1)
- File operations without security context
API2Cart Live Shipping 4 Woocommerce Security Vulnerabilities
API2Cart Live Shipping 4 Woocommerce Code Analysis
SQL Query Safety
Output Escaping
API2Cart Live Shipping 4 Woocommerce Attack Surface
WordPress Hooks 4
Maintenance & Trust
API2Cart Live Shipping 4 Woocommerce Maintenance & Trust
Maintenance Signals
Community Trust
API2Cart Live Shipping 4 Woocommerce Alternatives
ShipTime: Discounted Shipping Rates
shiptime-discount-shipping
This plugin provides real-time discounted shipping rates from ShipTime. You can enable real-time rates at check-out and your customers can select from …
Webhook Helper
api2cart-webhook-helper
Enhance Your WooCommerce Integration with Extended Webhook Support
Gelato Integration for WooCommerce
gelato-integration-for-woocommerce
Sell globally, print locally with 100+ production hubs in 32 countries
Hide Price Until Login
hide-price-until-login
Hide product price until the correct password is entered or until login.
Add to Cart Text Changer and Customize Button, Add Custom Icon
woo-add-to-cart-text-change
Easy handle: Add to Cart Text Changer and Customize Button, Add Custom Icon. With icon of shop or cart.
API2Cart Live Shipping 4 Woocommerce Developer Profile
3 plugins · 120 total installs
How We Detect API2Cart Live Shipping 4 Woocommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
api2cart-live-shipping-4-woocommerce/includes/class-a2c-live-shipping-rest-api-controller.php?ver=api2cart-live-shipping-4-woocommerce/app/A2c_Live_Shipping_Service.php?ver=api2cart-live-shipping-4-woocommerce/app/A2c_Live_Shipping_Exception.php?ver=api2cart-live-shipping-4-woocommerce/includes/class-a2c-live-shipping-rest-api-controller.php?ver=1.4.1api2cart-live-shipping-4-woocommerce/app/A2c_Live_Shipping_Service.php?ver=1.4.1api2cart-live-shipping-4-woocommerce/app/A2c_Live_Shipping_Exception.php?ver=1.4.1HTML / DOM Fingerprints
A2c_Live_Shipping_Service/wp-json/a2c_ls/v1/services/wp-json/a2c_ls/v1/methods