Baggage Freight Shipping Australia Security & Risk Analysis

wordpress.org/plugins/baggage-freight

Australia's Best Wordpress Woocommerce Courier Comparison System and Freight Plugin for Domestic and International Shipments.

10 active installs v0.1.0 PHP + WP 3.0.1+ Updated Sep 18, 2014
australiacalculatorcarrierscourierse-commerce
62
C · Use Caution
CVEs total1
Unpatched1
Last CVEJan 8, 2019
Download
Safety Verdict

Is Baggage Freight Shipping Australia Safe to Use in 2026?

Use With Caution

Score 62/100

Baggage Freight Shipping Australia has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Jan 8, 2019Updated 11yr ago
Risk Assessment

The 'baggage-freight' plugin v0.1.0 presents a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and avoids bundled libraries. However, significant concerns arise from critical vulnerabilities, both historically and indicated in the static analysis. The lack of nonce checks and capability checks across its entry points is a major weakness, leaving it susceptible to various attacks. While the attack surface is small, the absence of robust security checks on these entry points amplifies the risk.

The static analysis reveals a critical taint flow with unsanitized paths, indicating a potential for directory traversal or similar path manipulation vulnerabilities. The presence of file operations and external HTTP requests, combined with a very low percentage of properly escaped output, suggests that data processed by these functions could be vulnerable to injection attacks or cross-site scripting (XSS) if not handled with extreme care. The vulnerability history further compounds these concerns, showing a past critical vulnerability related to unrestricted file uploads, and a currently unpatched critical vulnerability.

In conclusion, while the plugin benefits from secure SQL practices and a limited attack surface, the recurring critical vulnerabilities and the current lack of essential security checks (nonces, capabilities) and proper output escaping create a substantial security risk. The unpatched critical vulnerability is the most immediate and severe concern, demanding urgent attention.

Key Concerns

  • Currently unpatched critical CVE
  • Critical severity taint flow
  • No nonce checks
  • No capability checks
  • Low output escaping percentage
  • File operations present
  • External HTTP requests present
Vulnerabilities
1

Baggage Freight Shipping Australia Security Vulnerabilities

CVEs by Year

1 CVE in 2019 · unpatched
2019
Patched Has unpatched

Severity Breakdown

Critical
1

1 total CVE

WF-6130d49f-61b7-4b70-b1a5-036346f82650-baggage-freightcritical · 9.8Unrestricted Upload of File with Dangerous Type

Baggage Freight Shipping Australia <= 0.1.0 - Arbitrary File Upload

Jan 8, 2019Unpatched
Code Analysis
Analyzed Mar 17, 2026

Baggage Freight Shipping Australia Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
29 prepared
Unescaped Output
76
12 escaped
Nonce Checks
0
Capability Checks
0
File Operations
8
External Requests
5
Bundled Libraries
0

SQL Query Safety

100% prepared29 total queries

Output Escaping

14% escaped88 total outputs
Data Flows
5 unsanitized

Data Flow Analysis

5 flows5 with unsanitized paths
<upload-package> (upload-package.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Baggage Freight Shipping Australia Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[baggage_link] baggage_shipping.php:420
WordPress Hooks 4
actionadmin_menubaggage_shipping.php:137
actionwoocommerce_checkout_update_order_metabaggage_shipping.php:416
actionwoocommerce_shipping_initclass-wc-baggagefreight.php:565
filterwoocommerce_shipping_methodsclass-wc-baggagefreight.php:567
Maintenance & Trust

Baggage Freight Shipping Australia Maintenance & Trust

Maintenance Signals

WordPress version tested3.6.1
Last updatedSep 18, 2014
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings3
Active installs10
Developer Profile

Baggage Freight Shipping Australia Developer Profile

Shipster

1 plugin · 10 total installs

67
trust score
Avg Security Score
62/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Baggage Freight Shipping Australia

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/baggage-freight/css/baggage.css/wp-content/plugins/baggage-freight/js/baggage.js
Script Paths
/wp-content/plugins/baggage-freight/js/baggage.js
Version Parameters
baggage-freight/css/baggage.css?ver=baggage-freight/js/baggage.js?ver=

HTML / DOM Fingerprints

JS Globals
window.bf_weightwindow.bf_lengthwindow.bf_widthwindow.bf_heightwindow.bf_unitwindow.bf_description+39 more
Shortcode Output
[baggage_link][baggage_postorder]
FAQ

Frequently Asked Questions about Baggage Freight Shipping Australia