
Bring Fraktguiden for WooCommerce Security & Risk Analysis
wordpress.org/plugins/bring-fraktguiden-for-woocommerceBring Fraktguiden provides shipping calculation based on rates from bring.no.
Is Bring Fraktguiden for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100Bring Fraktguiden for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "bring-fraktguiden-for-woocommerce" plugin v1.11.7 presents a mixed security posture. While it demonstrates good practices in SQL query handling with 100% prepared statements and a high percentage (90%) of properly escaped outputs, significant concerns arise from its attack surface. All 16 identified AJAX handlers lack authentication checks, creating a wide entry point for potential attacks. Furthermore, the absence of nonce checks on any AJAX actions is a critical oversight that could lead to Cross-Site Request Forgery (CSRF) vulnerabilities.
The taint analysis, while limited in scope with only two flows analyzed, did identify two flows with unsanitized paths. Although classified as not critical or high severity, this indicates a potential for input validation issues. The vulnerability history reveals one past medium-severity CVE, specifically related to Missing Authorization, which aligns with the current findings of unprotected AJAX endpoints. This historical pattern reinforces the concern around insufficient access control.
In conclusion, the plugin has strengths in its data handling but weaknesses in its access control mechanisms. The high number of unprotected AJAX endpoints is the most pressing concern, exacerbated by the lack of nonce checks. While critical taint flows and unpatched vulnerabilities are not currently evident, the historical pattern and static analysis findings warrant careful attention and remediation to mitigate potential security risks.
Key Concerns
- 16 AJAX handlers without auth checks
- 0 Nonce checks on AJAX handlers
- 2 Flows with unsanitized paths
- 1 Medium severity CVE
- 1 Capability check only
- Bundled outdated TCPDF v1.0.004
Bring Fraktguiden for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Bring Fraktguiden for WooCommerce <= 1.11.4 - Missing Authorization
Bring Fraktguiden for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Bring Fraktguiden for WooCommerce Attack Surface
AJAX Handlers 16
WordPress Hooks 77
Scheduled Events 1
Maintenance & Trust
Bring Fraktguiden for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Bring Fraktguiden for WooCommerce Alternatives
Posten Bring Checkout
posten-bring-checkout
Official Posten Bring checkout plugin for WooCommerce
Fraktvalg
fraktvalg
Easily provide shipping estimates for your customers based on their postal code.
Fraktjakt WooCommerce Shipping
fraktjakt-shipping-for-woocommerce
Fraktjakt's all-in-one shipping method plugin for WooCommerce.
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
Bring Fraktguiden for WooCommerce Developer Profile
1 plugin · 500 total installs
How We Detect Bring Fraktguiden for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bring-fraktguiden-for-woocommerce/assets/css/style.css/wp-content/plugins/bring-fraktguiden-for-woocommerce/assets/js/admin.js/wp-content/plugins/bring-fraktguiden-for-woocommerce/assets/js/bring-fraktguiden-checkout.js/wp-content/plugins/bring-fraktguiden-for-woocommerce/assets/js/custom-select.js/wp-content/plugins/bring-fraktguiden-for-woocommerce/assets/js/frontend.js/wp-content/plugins/bring-fraktguiden-for-woocommerce/assets/js/frontend.min.js/wp-content/plugins/bring-fraktguiden-for-woocommerce/assets/js/main.js/wp-content/plugins/bring-fraktguiden-for-woocommerce/assets/js/shipping.js+1 more/wp-content/plugins/bring-fraktguiden-for-woocommerce/assets/js/admin.js/wp-content/plugins/bring-fraktguiden-for-woocommerce/assets/js/bring-fraktguiden-checkout.js/wp-content/plugins/bring-fraktguiden-for-woocommerce/assets/js/custom-select.js/wp-content/plugins/bring-fraktguiden-for-woocommerce/assets/js/frontend.js/wp-content/plugins/bring-fraktguiden-for-woocommerce/assets/js/frontend.min.js/wp-content/plugins/bring-fraktguiden-for-woocommerce/assets/js/main.js+2 morebring-fraktguiden-for-woocommerce/assets/css/style.css?ver=bring-fraktguiden-for-woocommerce/assets/js/admin.js?ver=bring-fraktguiden-for-woocommerce/assets/js/bring-fraktguiden-checkout.js?ver=bring-fraktguiden-for-woocommerce/assets/js/custom-select.js?ver=bring-fraktguiden-for-woocommerce/assets/js/frontend.js?ver=bring-fraktguiden-for-woocommerce/assets/js/frontend.min.js?ver=bring-fraktguiden-for-woocommerce/assets/js/main.js?ver=bring-fraktguiden-for-woocommerce/assets/js/shipping.js?ver=bring-fraktguiden-for-woocommerce/assets/js/shipping.min.js?ver=HTML / DOM Fingerprints
bring_fraktguiden_alternative_datesbring_fraktguiden_date_optionsbring_fraktguiden_map_containerbring_fraktguiden_pickup_point_mapbring_fraktguiden_shipping_options<!-- BEGIN: Bring Fraktguiden --><!-- END: Bring Fraktguiden -->data-bring-product-iddata-bring-service-codedata-map-keydata-pickup-point-map_fraktguiden_checkout