
Advanced Shipping Methods for WooCommerce Security & Risk Analysis
wordpress.org/plugins/asm-wcOffer shipping methods to customers based on quantities, classes, or categories!
Is Advanced Shipping Methods for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100Advanced Shipping Methods for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "asm-wc" plugin v1.0.0 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, external HTTP requests, and the presence of 100% properly escaped output are significant strengths. Furthermore, the lack of known CVEs and historical vulnerabilities indicates a mature and likely well-maintained codebase.
However, the analysis does reveal areas for improvement. The complete absence of nonce checks and capability checks, despite having an entry point in the form of a shortcode, presents a potential security concern. While the current attack surface is minimal (one shortcode), any future expansion or modification without these fundamental security checks could expose the plugin to vulnerabilities. The lack of taint analysis data is also noted, though this might be a limitation of the analysis tool rather than an inherent flaw in the plugin itself. Overall, the plugin demonstrates good coding practices but could benefit from incorporating standard WordPress security mechanisms to further harden its defense.
The plugin has no recorded vulnerabilities, which is a very positive sign. This suggests that the developers have either been diligent in their security practices or that the plugin's functionality is simple enough to avoid common pitfalls. The lack of any recorded vulnerability types further reinforces this impression. The primary area of concern stems from the static analysis, specifically the missing security checks on its entry points.
Key Concerns
- Shortcode lacks nonce check
- Shortcode lacks capability check
Advanced Shipping Methods for WooCommerce Security Vulnerabilities
Advanced Shipping Methods for WooCommerce Code Analysis
Output Escaping
Advanced Shipping Methods for WooCommerce Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Advanced Shipping Methods for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Shipping Methods for WooCommerce Alternatives
Weight Based Shipping Table Rate for WooCommerce – Flexible Shipping
flexible-shipping
Weight based shipping methods for WooCommerce. Flexible shipping with table rate rules by cart weight and order value. Accurate rates at checkout.
Advanced Free Shipping for WooCommerce
woocommerce-advanced-free-shipping
Advanced Free Shipping for WooCommerce is an plugin which allows you to set up advanced free shipping conditions.
Codiepress Advanced Rule Based Shipping for WooCommerce, Table Rate Shipping Methods, Weight Based Shipping
advanced-rule-based-shipping
Transform your WooCommerce store with Advanced Rule Based Shipping methods! Enjoy flexible options like table rates, weight-based, and flat rates!
Advanced WooCommerce Shipping – Flexible Shipping Cost by Weight, Volume & Quantity – Codiepress
advanced-shipping-cost
Flexible and complex shipping cost solution for WooCommerce. Calculate rates by weight, volume, or quantity with easy-to-define rules.
Advanced Shipping Manager
asm-manager
Advanced Shipping Manager delivers full control over ALL of your shipping rules and methods, no matter how complicated your challenge may be!
Advanced Shipping Methods for WooCommerce Developer Profile
5 plugins · 900 total installs
How We Detect Advanced Shipping Methods for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/asm-wc/admin/css/jquery.timepicker.css/wp-content/plugins/asm-wc/admin/css/asm-wc-admin.css/wp-content/plugins/asm-wc/admin/js/jquery.timepicker.js/wp-content/plugins/asm-wc/admin/js/asm-wc-admin.js/wp-content/plugins/asm-wc/admin/js/jquery.timepicker.js/wp-content/plugins/asm-wc/admin/js/asm-wc-admin.jsasm-wc/admin/css/jquery.timepicker.css?ver=asm-wc/admin/css/asm-wc-admin.css?ver=asm-wc/admin/js/jquery.timepicker.js?ver=asm-wc/admin/js/asm-wc-admin.js?ver=HTML / DOM Fingerprints
asm_wc_togglerdata-asm_wc_togglershippingZoneMethods2LocalizeScript[asm_wc_shipping_method]