City & Zip Based Shipping Rate for WooCommerce Security & Risk Analysis

wordpress.org/plugins/city-zip-based-shipping-rate-for-woocommerce

Flexible WooCommerce shipping by City or ZIP/Postcode — charge fixed, weight-based, quantity or subtotal delivery fees for accurate pricing.

30 active installs v1.0.0 PHP 7.4+ WP 6.2+ Updated Mar 4, 2026
city-based-shippinglocal-deliverypostcode-shippingshipping-ratezip-code-shipping
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is City & Zip Based Shipping Rate for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

City & Zip Based Shipping Rate for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The security posture of the 'city-zip-based-shipping-rate-for-woocommerce' plugin version 1.0.0 appears to be generally good, with a limited attack surface and no critical code signals or taint analysis issues detected. The plugin demonstrates positive security practices by utilizing prepared statements for all SQL queries and having a nonce check in place. The absence of file operations and external HTTP requests also reduces potential vectors for compromise. However, the lack of capability checks on its AJAX handlers is a notable concern, as this means any authenticated user could potentially trigger these actions without proper authorization checks. The limited output escaping (65%) also presents a moderate risk of cross-site scripting (XSS) vulnerabilities if dynamic data is not handled carefully. The plugin's vulnerability history is clean, indicating a good track record, but this can change with future updates. Overall, while the foundation is solid, the missing capability checks and imperfect output escaping are areas that require attention to further strengthen its security.

Key Concerns

  • Missing capability checks on AJAX handlers
  • Insufficient output escaping
Vulnerabilities
None known

City & Zip Based Shipping Rate for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

City & Zip Based Shipping Rate for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
17 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

65% escaped26 total outputs
Attack Surface

City & Zip Based Shipping Rate for WooCommerce Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_city_zip_based_shipping_rate/validate_shipping_calculatorinc\class-main.php:60
noprivwp_ajax_city_zip_based_shipping_rate/validate_shipping_calculatorinc\class-main.php:61
WordPress Hooks 9
actionbefore_woocommerce_initcity-zip-based-shipping-rate-for-woocommerce.php:32
actionadmin_footerinc\class-admin.php:18
actionadmin_footerinc\class-admin.php:19
actionadmin_enqueue_scriptsinc\class-admin.php:20
filterwoocommerce_generate_city_zip_based_shipping_rates_htmlinc\class-admin.php:21
actionwp_enqueue_scriptsinc\class-main.php:56
filterplugin_action_linksinc\class-main.php:57
filterwoocommerce_shipping_methodsinc\class-main.php:58
actioncity_zip_based_shipping_rate/shipping_rate_settings_footerinc\class-shipping-method-options.php:69
Maintenance & Trust

City & Zip Based Shipping Rate for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 4, 2026
PHP min version7.4
Downloads363

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

City & Zip Based Shipping Rate for WooCommerce Developer Profile

Codiepress

8 plugins · 2K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect City & Zip Based Shipping Rate for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/city-zip-based-shipping-rate-for-woocommerce/assets/admin.min.css/wp-content/plugins/city-zip-based-shipping-rate-for-woocommerce/assets/admin.min.js
Script Paths
/wp-content/plugins/city-zip-based-shipping-rate-for-woocommerce/assets/vue.min.js/wp-content/plugins/city-zip-based-shipping-rate-for-woocommerce/assets/sortable.min.js/wp-content/plugins/city-zip-based-shipping-rate-for-woocommerce/assets/vue-sortable.min.js/wp-content/plugins/city-zip-based-shipping-rate-for-woocommerce/assets/admin.min.js
Version Parameters
/wp-content/plugins/city-zip-based-shipping-rate-for-woocommerce/assets/admin.min.css?ver=/wp-content/plugins/city-zip-based-shipping-rate-for-woocommerce/assets/admin.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
city-zip-based-shipping-modalmodal-contentmodal-headerbtn-modal-closemodal-bodymax-shipping-contentmax-zip-codes-contentbulk-import+5 more
HTML Comments
<!-- City & Zip Based Shipping -->
Data Attributes
data-modalv-ifv-elsev-forv-modelv-if+6 more
JS Globals
city_zip_based_shipping_rate
FAQ

Frequently Asked Questions about City & Zip Based Shipping Rate for WooCommerce