AS Product Shipping Security & Risk Analysis

wordpress.org/plugins/as-product-shipping

A WooCommerce shipping plugin with flat rate and weight-based shipping options for individual products.

0 active installs v1.0.1 PHP + WP 5.0+ Updated Aug 29, 2025
ecommerceflat-rateshippingweight-basedwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AS Product Shipping Safe to Use in 2026?

Generally Safe

Score 100/100

AS Product Shipping has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The "as-product-shipping" v1.0.1 plugin exhibits a generally strong security posture based on the provided static analysis. The complete absence of identified CVEs and a history of no recorded vulnerabilities are highly positive indicators. The code also demonstrates good security practices, with 100% of SQL queries using prepared statements, a high percentage of properly escaped output (90%), and the presence of both nonce and capability checks. There are no identified dangerous functions, file operations, or external HTTP requests, further minimizing the attack surface.

However, the static analysis reveals a complete lack of any identified entry points (AJAX handlers, REST API routes, shortcodes, cron events). While this significantly reduces the immediate attack surface, it also makes it impossible to assess the security of any potential interactions if they were to be introduced or if the analysis was incomplete. The absence of taint analysis results (0 flows analyzed) is also a notable gap, as it prevents a deeper understanding of how data might propagate and be mishandled within the plugin's logic. While the plugin's current state appears secure due to its limited functionality and good coding practices, the lack of thoroughly analyzed entry points and taint flows means there's an unknown potential for future vulnerabilities if the plugin's functionality expands or if the analysis itself has limitations.

In conclusion, "as-product-shipping" v1.0.1 scores well on its current implementation and history. The developer appears to be following good security practices for the code that was analyzed. The primary area for concern is the lack of identifiable entry points and the absence of taint analysis, which means the overall security, especially for any unanalyzed code paths or future additions, cannot be fully guaranteed. Despite this, the lack of any past or present critical issues points to a developer who is likely security-conscious.

Key Concerns

  • No identified entry points for analysis
  • No taint analysis performed
  • Output escaping not 100%
Vulnerabilities
None known

AS Product Shipping Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

AS Product Shipping Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
27 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

90% escaped30 total outputs
Attack Surface

AS Product Shipping Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
actioninitas-product-shipping.php:32
actionwoocommerce_initas-product-shipping.php:33
filterwoocommerce_shipping_methodsas-product-shipping.php:48
actionwoocommerce_shipping_initas-product-shipping.php:51
actionplugins_loadedas-product-shipping.php:78
actionadmin_menuincludes\admin\class-as-product-shipping-admin.php:16
actionadd_meta_boxesincludes\admin\class-as-product-shipping-admin.php:19
actionsave_postincludes\admin\class-as-product-shipping-admin.php:20
filtermanage_edit-product_columnsincludes\admin\class-as-product-shipping-admin.php:23
actionmanage_product_posts_custom_columnincludes\admin\class-as-product-shipping-admin.php:24
actionadmin_enqueue_scriptsincludes\admin\class-as-product-shipping-admin.php:27
actionwoocommerce_product_meta_endincludes\frontend\class-as-product-shipping-frontend.php:16
actionwoocommerce_checkout_create_order_line_itemincludes\frontend\class-as-product-shipping-frontend.php:19
actionwoocommerce_order_item_meta_endincludes\frontend\class-as-product-shipping-frontend.php:22
filterwoocommerce_package_ratesincludes\functions\order-functions.php:57
Maintenance & Trust

AS Product Shipping Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 29, 2025
PHP min version
Downloads188

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

AS Product Shipping Developer Profile

Ahmed Shaikh

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AS Product Shipping

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/as-product-shipping/assets/css/admin.css/wp-content/plugins/as-product-shipping/assets/js/admin.js
Script Paths
/wp-content/plugins/as-product-shipping/assets/js/admin.js
Version Parameters
as-product-shipping/assets/css/admin.css?ver=as-product-shipping/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
asprsh-shipping-optionsasprsh-shipping-descriptionasprsh-shipping-fieldasprsh_custom_shipping_enabledasprsh_shipping_type_fieldasprsh_shipping_typeasprsh_custom_shipping_rate_fieldasprsh_custom_shipping_rate+3 more
HTML Comments
<!-- AS Product Shipping Admin --><!-- Admin functionality for the AS Product Shipping plugin. --><!-- Add admin menu --><!-- Add separate metabox for shipping settings -->+13 more
Data Attributes
id="asprsh_custom_shipping_enabled"name="asprsh_custom_shipping_enabled"id="asprsh_shipping_type"name="asprsh_shipping_type"id="asprsh_custom_shipping_rate"name="asprsh_custom_shipping_rate"+2 more
JS Globals
ASPRSH_VERSION
FAQ

Frequently Asked Questions about AS Product Shipping