
Direct Freight Express Shipping for WooCommerce Security & Risk Analysis
wordpress.org/plugins/direct-freight-express-shippingEffortlessly integrate Direct Freight Express shipping rates into your store and offer real-time shipping costs at checkout for Australian customers.
Is Direct Freight Express Shipping for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Direct Freight Express Shipping for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "direct-freight-express-shipping" plugin, version 1.0.4, exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates good practices by not utilizing dangerous functions, all SQL queries are prepared, and nearly all output is properly escaped, minimizing risks of common web vulnerabilities like SQL injection and cross-site scripting. Furthermore, the absence of shortcodes, cron events, and REST API routes, combined with a low number of total entry points with no unprotected ones, significantly limits the plugin's attack surface. The vulnerability history shows no known CVEs, indicating a clean track record. However, a notable area for concern is the complete lack of capability checks on its single AJAX handler. While it has a nonce check, the absence of a capability check means any authenticated user, regardless of their role or permissions, could potentially interact with this AJAX endpoint. The presence of external HTTP requests, while not inherently a vulnerability, warrants careful monitoring as they can sometimes be a vector for further attacks if not handled securely. Overall, the plugin is well-developed from a security perspective, but the missing capability check on the AJAX handler presents a potential weakness that should be addressed.
Key Concerns
- Missing capability checks on AJAX handler
Direct Freight Express Shipping for WooCommerce Security Vulnerabilities
Direct Freight Express Shipping for WooCommerce Release Timeline
Direct Freight Express Shipping for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
Direct Freight Express Shipping for WooCommerce Attack Surface
AJAX Handlers 1
WordPress Hooks 21
Maintenance & Trust
Direct Freight Express Shipping for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Direct Freight Express Shipping for WooCommerce Alternatives
PiWeb Flat rate / Conditional shipping for WooCommerce
advanced-free-flat-shipping-woocommerce
WooCommerce conditional shipping & WooCommerce Advanced Flat rate shipping rates plugin to Create Advanced Flat rate shipping or Free shipping met …
Plugin BlueX for WooCommerce
bluex-for-woocommerce
Once the plugin is installed, you need to go to the integration section in the woocommerce settings and add the data delivered by blue express. Also,
Table rate shipping for WooCommerce
advanced-table-rate-shipping-for-woocommerce
Table rate shipping a addon plugin for WooCommerce shipping.
Shipi – DHL Express Integration for Woocommerce
a2z-dhl-express-shipping
Seamless DHL Express WooCommerce integration - live rates, automated/manual labels, return labels, pickups, invoices, and tracking.
PrangoShip [Quantity Based] for WooCommerce
woo-quantity-based-shipping-rate
Lets you assign shipping rates based on the quantity of items in the cart for your WooCommerce Store.
Direct Freight Express Shipping for WooCommerce Developer Profile
2 plugins · 10 total installs
How We Detect Direct Freight Express Shipping for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/direct-freight-express-shipping/assets/admin.css/wp-content/plugins/direct-freight-express-shipping/assets/vue.js/wp-content/plugins/direct-freight-express-shipping/assets/vue.min.jshttps://codiepress.com/plugins/direct-freight-express-for-woocommerce-plugin/direct-freight-express-shipping/assets/admin.css?ver=direct-freight-express-shipping/assets/vue.js?ver=direct-freight-express-shipping/assets/vue.min.js?ver=HTML / DOM Fingerprints
direct_freight_express_shipping_php_missing_noticedirect_freight_express_shipping/wp-json/direct_freight_express_shipping/v1/settings