
Checkout Shipping Message Add-on for WooCommerce Security & Risk Analysis
wordpress.org/plugins/checkout-shipping-message-add-on-for-woocommerceThis add-on will allow you to add a custom message to WooCommerce under that shipping totals shipping section of your checkout.
Is Checkout Shipping Message Add-on for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100Checkout Shipping Message Add-on for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "checkout-shipping-message-add-on-for-woocommerce" plugin v1.0.0 reveals a generally strong security posture. The absence of any identified attack surface entry points (AJAX handlers, REST API routes, shortcodes, cron events) is a significant positive. Furthermore, the code exhibits good practices such as 100% of SQL queries using prepared statements and a high percentage (96%) of properly escaped output. The lack of dangerous functions, file operations, external HTTP requests, and critical or high severity taint flows further strengthens this assessment.
However, the complete lack of nonce checks and capability checks across all potential (though currently non-existent) entry points is a notable weakness. While there is no current attack surface, if future development introduces such points without these essential security mechanisms, it could create significant vulnerabilities. The plugin also has no recorded vulnerability history, which is positive, but it's important to note that this can be due to a lack of public disclosure or the plugin's relative newness/obscurity.
In conclusion, the plugin demonstrates a good foundation of secure coding practices, particularly regarding data handling and output sanitization. The absence of known vulnerabilities and a clean taint analysis are excellent indicators. The primary area for concern lies in the absence of built-in security checks like nonces and capability checks, which represent a potential risk if the attack surface expands in future versions.
Key Concerns
- No nonce checks implemented
- No capability checks implemented
- Minor output escaping issue (4% unescaped)
Checkout Shipping Message Add-on for WooCommerce Security Vulnerabilities
Checkout Shipping Message Add-on for WooCommerce Code Analysis
Output Escaping
Checkout Shipping Message Add-on for WooCommerce Attack Surface
WordPress Hooks 4
Maintenance & Trust
Checkout Shipping Message Add-on for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Checkout Shipping Message Add-on for WooCommerce Alternatives
Free Shipping Notice for WooCommerce
free-shipping-notice-for-woocommerce
Displays the remaining price to receive free shipping on the cart and checkout pages.
Change Shipping Label
change-shipping-label
A simple plugin for changing shipping labels in WooCommece cart and checkout.
Lite Shipping Counter & Notice
lite-shipping-counter-notice
Lightweight notice for WooCommerce that shows how much is left to unlock free shipping.
Direct Checkout for WooCommerce
woocommerce-direct-checkout
Formerly "WooCommerce Direct Checkout". This plugin simplifies the entire WooCommerce checkout process to improve your sales rate.
Sliding Cart for WooCommerce by FunnelKit – Skip Cart & Reach WooCommerce Checkout Faster
cart-for-woocommerce
FunnelKit Cart adds a beautiful sliding cart to your WooCommerce store. Let the buyers add items, edit quantity and add upsells on the side cart.
Checkout Shipping Message Add-on for WooCommerce Developer Profile
1 plugin · 30 total installs
How We Detect Checkout Shipping Message Add-on for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/checkout-shipping-message-add-on-for-woocommerce/assets/css/shipping-note.csscheckout-shipping-message-add-on-for-woocommerce/assets/css/shipping-note.css?ver=