
Biteship Shipping Security & Risk Analysis
wordpress.org/plugins/biteship-shippingPlugin pengiriman WooCommerce dengan berbagai ekspedisi untuk pengiriman Reguler, Instan, dan Kargo.
Is Biteship Shipping Safe to Use in 2026?
Generally Safe
Score 100/100Biteship Shipping has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "biteship-shipping" plugin v1.2.1 exhibits a concerning security posture primarily due to a large number of unprotected entry points. While the code demonstrates good practices in avoiding dangerous functions, executing SQL queries with prepared statements, and generally performing output escaping, the lack of authentication checks on a significant portion of its AJAX handlers and REST API routes represents a substantial risk. This means that potentially sensitive operations or data retrieval could be triggered by unauthenticated users, opening the door to various exploits.
The static analysis reveals a total of 9 entry points, with a striking 8 of them lacking necessary authorization. Specifically, 6 AJAX handlers and 2 REST API routes do not have permission callbacks. This is the most critical finding and significantly elevates the plugin's risk profile. Fortunately, the vulnerability history is clean, with no recorded CVEs, suggesting that either the plugin has been well-maintained in the past, or the vulnerabilities present in the current version have not yet been discovered or publicly disclosed.
In conclusion, while the plugin avoids common pitfalls like raw SQL queries and excessive unescaped output, the numerous unprotected entry points are a major weakness. The absence of any known vulnerabilities is a positive sign, but it should not overshadow the immediate security implications of the exposed AJAX and REST API endpoints. Future versions should prioritize implementing robust authentication and authorization checks for all entry points.
Key Concerns
- 8 unprotected entry points (AJAX/REST API)
- 6 unprotected AJAX handlers
- 2 unprotected REST API routes
- Low output escaping rate (87%)
Biteship Shipping Security Vulnerabilities
Biteship Shipping Code Analysis
Output Escaping
Biteship Shipping Attack Surface
AJAX Handlers 6
REST API Routes 3
WordPress Hooks 39
Maintenance & Trust
Biteship Shipping Maintenance & Trust
Maintenance Signals
Community Trust
Biteship Shipping Alternatives
Bulgarisation for WooCommerce
bulgarisation-for-woocommerce
Всичко необходимо за вашият онлайн магазин за България. Включва облекчен режим за Наредба - H-18 и методи за доставка с Еконт, CVC и Спиди.
The Courier Guy Shipping for WooCommerce
the-courier-guy
This is the official WooCommerce extension to ship products using The Courier Guy.
Spocket ‑ US & EU Dropshipping
spocket
Find fast shipping products from reliable suppliers, import them to your WooCommerce store and manage your orders automatically: all for free.
FlagShip WooCommerce Shipping
flagship-woocommerce-shipping
FlagShip WooCommerce Shipping is an e-shipping courier solution that helps you shipping anything from Canada. Beautifully.
Shipping by City for Woocommerce
shipping-by-city-for-woocommerce
Shipping by city WooCommerce Add-on plug-in.
Biteship Shipping Developer Profile
1 plugin · 400 total installs
How We Detect Biteship Shipping
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/biteship-shipping/admin/css/biteship-admin.css/wp-content/plugins/biteship-shipping/assets/css/frontend.css/wp-content/plugins/biteship-shipping/assets/js/frontend.js/wp-content/plugins/biteship-shipping/assets/js/frontend.jsbiteship-shipping/admin/css/biteship-admin.css?ver=biteship-shipping/assets/css/frontend.css?ver=biteship-shipping/assets/js/frontend.js?ver=HTML / DOM Fingerprints
biteship-admin-fieldbiteship-shipping-sectionbiteship-admin-map-container<!-- Start Biteship Admin Map --><!-- End Biteship Admin Map --><!-- Biteship Shipping Address --><!-- End Biteship Shipping Address -->data-biteship-api-urldata-biteship-api-keydata-biteship-shipping-address-fielddata-biteship-map-latitudedata-biteship-map-longitudebiteship_admin_params/wp-json/biteship/v1/shipments/wp-json/biteship/v1/rates/wp-json/biteship/v1/locations