Direct Freight Express Shipping for WooCommerce Security & Risk Analysis

wordpress.org/plugins/direct-freight-express-shipping

Effortlessly integrate Direct Freight Express shipping rates into your store and offer real-time shipping costs at checkout for Australian customers.

10 active installs v1.0.4 PHP 7.4.3+ WP 6.2.0+ Updated Dec 5, 2025
direct-freightshippingshipping-rateswoocommercewoocommerce-shipping
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Direct Freight Express Shipping for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Direct Freight Express Shipping for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "direct-freight-express-shipping" plugin, version 1.0.4, exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates good practices by not utilizing dangerous functions, all SQL queries are prepared, and nearly all output is properly escaped, minimizing risks of common web vulnerabilities like SQL injection and cross-site scripting. Furthermore, the absence of shortcodes, cron events, and REST API routes, combined with a low number of total entry points with no unprotected ones, significantly limits the plugin's attack surface. The vulnerability history shows no known CVEs, indicating a clean track record. However, a notable area for concern is the complete lack of capability checks on its single AJAX handler. While it has a nonce check, the absence of a capability check means any authenticated user, regardless of their role or permissions, could potentially interact with this AJAX endpoint. The presence of external HTTP requests, while not inherently a vulnerability, warrants careful monitoring as they can sometimes be a vector for further attacks if not handled securely. Overall, the plugin is well-developed from a security perspective, but the missing capability check on the AJAX handler presents a potential weakness that should be addressed.

Key Concerns

  • Missing capability checks on AJAX handler
Vulnerabilities
None known

Direct Freight Express Shipping for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Direct Freight Express Shipping for WooCommerce Release Timeline

v1.0.4Current
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Direct Freight Express Shipping for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
98 escaped
Nonce Checks
5
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

98% escaped100 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
save_settings (inc/class-admin.php:40)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Direct Freight Express Shipping for WooCommerce Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_direct_freight_express_shipping/validate_api_keyinc/class-admin.php:24
WordPress Hooks 21
actionadmin_noticesdirect-freight-express-shipping.php:53
actioninitdirect-freight-express-shipping.php:76
actionadmin_footerinc/class-admin.php:18
actionadmin_enqueue_scriptsinc/class-admin.php:19
actionadmin_enqueue_scriptsinc/class-admin.php:20
actionwoocommerce_settings_save_shippinginc/class-admin.php:21
actionwoocommerce_settings_shippinginc/class-admin.php:22
filterwoocommerce_get_sections_shippinginc/class-admin.php:23
actiondirect_freight_express_shipping/settingsinc/class-admin.php:26
actiondirect_freight_express_shipping/settingsinc/class-admin.php:27
actiondirect_freight_express_shipping/settingsinc/class-admin.php:28
actioninitinc/class-main.php:60
filterplugin_action_linksinc/class-main.php:61
filterwoocommerce_shipping_methodsinc/class-main.php:62
actionwoocommerce_after_shipping_rateinc/class-main.php:63
actionwoocommerce_initinc/class-main.php:64
filterwoocommerce_generate_codiepress_missing_conditional_shipping_payments_htmlinc/class-main.php:65
actionwoocommerce_process_product_metainc/class-product.php:20
actionwoocommerce_save_product_variationinc/class-product.php:21
actionwoocommerce_product_options_dimensionsinc/class-product.php:22
actionwoocommerce_variation_options_dimensionsinc/class-product.php:23
Maintenance & Trust

Direct Freight Express Shipping for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 5, 2025
PHP min version7.4.3
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Direct Freight Express Shipping for WooCommerce Developer Profile

Repon Hossain

2 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Direct Freight Express Shipping for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/direct-freight-express-shipping/assets/admin.css/wp-content/plugins/direct-freight-express-shipping/assets/vue.js/wp-content/plugins/direct-freight-express-shipping/assets/vue.min.js
Script Paths
https://codiepress.com/plugins/direct-freight-express-for-woocommerce-plugin/
Version Parameters
direct-freight-express-shipping/assets/admin.css?ver=direct-freight-express-shipping/assets/vue.js?ver=direct-freight-express-shipping/assets/vue.min.js?ver=

HTML / DOM Fingerprints

JS Globals
direct_freight_express_shipping_php_missing_noticedirect_freight_express_shipping
REST Endpoints
/wp-json/direct_freight_express_shipping/v1/settings
FAQ

Frequently Asked Questions about Direct Freight Express Shipping for WooCommerce