City Based Shipping for Bangladesh Security & Risk Analysis

wordpress.org/plugins/city-based-shipping-for-bangladesh

Adds automatic city-based shipping rates for WooCommerce stores in Bangladesh (Dhaka vs outside Dhaka).

10 active installs v1.0.1 PHP 7.4+ WP 5.8+ Updated Unknown
bangladeshcheckoutratesshippingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is City Based Shipping for Bangladesh Safe to Use in 2026?

Generally Safe

Score 100/100

City Based Shipping for Bangladesh has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

Based on the static analysis, the "city-based-shipping-for-bangladesh" plugin version 1.0.1 exhibits a strong security posture. The absence of any identified dangerous functions, unsanitized taint flows, raw SQL queries, file operations, or external HTTP requests is highly commendable. Furthermore, the fact that all identified output is properly escaped and all SQL queries utilize prepared statements demonstrates good coding practices for preventing common web vulnerabilities like cross-site scripting (XSS) and SQL injection.

However, there are a couple of areas that warrant attention. The complete lack of any identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) is unusual for a functional plugin and could indicate an incomplete static analysis or a plugin with very limited functionality. More critically, the plugin has zero recorded vulnerabilities, including CVEs, which is a positive indicator but also means there's no historical data to suggest how the plugin or its developers handle security issues when they arise. The presence of only one capability check could suggest that sensitive operations might not be adequately protected if the plugin's functionality expands beyond what's immediately apparent from the analysis.

In conclusion, the plugin demonstrates excellent adherence to fundamental security principles in its current codebase. The primary areas of concern are the potential for an incomplete attack surface analysis and the lack of historical vulnerability data. While the current code is robust, future updates should continue to prioritize secure coding practices and robust permission checks as functionality evolves.

Key Concerns

  • Zero capability checks found
  • No entry points found (unusual)
Vulnerabilities
None known

City Based Shipping for Bangladesh Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

City Based Shipping for Bangladesh Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
21 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped21 total outputs
Attack Surface

City Based Shipping for Bangladesh Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menucity-based-shipping-for-bangladesh.php:102
actionadmin_initcity-based-shipping-for-bangladesh.php:103
actionwp_enqueue_scriptscity-based-shipping-for-bangladesh.php:105
filterwoocommerce_package_ratescity-based-shipping-for-bangladesh.php:106
Maintenance & Trust

City Based Shipping for Bangladesh Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.4
Downloads213

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

City Based Shipping for Bangladesh Developer Profile

Md Shorov Abedin

2 plugins · 50 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect City Based Shipping for Bangladesh

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/city-based-shipping-for-bangladesh/js/city-based-shipping-for-bangladesh.js
Script Paths
/wp-content/plugins/city-based-shipping-for-bangladesh/js/city-based-shipping-for-bangladesh.js
Version Parameters
city-based-shipping-for-bangladesh/js/city-based-shipping-for-bangladesh.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-city-based-shipping
JS Globals
cityBasedShipping
FAQ

Frequently Asked Questions about City Based Shipping for Bangladesh