
Disable Free Shipping for Heavyweight Orders Security & Risk Analysis
wordpress.org/plugins/disable-free-shipping-for-heavyweight-ordersA WooCommerce plugin that disables or hides selected shipping methods when the cart meets certain conditions (weight, subtotal, etc.).
Is Disable Free Shipping for Heavyweight Orders Safe to Use in 2026?
Generally Safe
Score 100/100Disable Free Shipping for Heavyweight Orders has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "disable-free-shipping-for-heavyweight-orders" v1.4.0 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, reliance on prepared statements for SQL queries, and 100% proper output escaping are excellent indicators of secure coding practices. Furthermore, the presence of nonce checks and the lack of any recorded vulnerabilities in its history contribute to a positive security assessment. The limited attack surface and lack of external HTTP requests also reduce potential exposure vectors.
However, a key area of concern is the complete absence of capability checks on any of its entry points. While the static analysis reports no unprotected entry points (AJAX, REST API, shortcodes), the fact that the sole cron event lacks capability checks presents a potential risk. If this cron event performs any sensitive action or modifies data, an unauthenticated user could potentially trigger it.
In conclusion, the plugin demonstrates good security fundamentals, particularly in its handling of data and output. The primary weakness lies in the lack of authorization checks on its cron event, which, if exploitable, could represent a significant vulnerability. Without further context on what the cron event actually does, it's difficult to quantify the exact risk, but it is the most notable security gap identified.
Key Concerns
- Cron event lacks capability checks
Disable Free Shipping for Heavyweight Orders Security Vulnerabilities
Disable Free Shipping for Heavyweight Orders Release Timeline
Disable Free Shipping for Heavyweight Orders Code Analysis
Output Escaping
Disable Free Shipping for Heavyweight Orders Attack Surface
WordPress Hooks 14
Scheduled Events 1
Maintenance & Trust
Disable Free Shipping for Heavyweight Orders Maintenance & Trust
Maintenance Signals
Community Trust
Disable Free Shipping for Heavyweight Orders Alternatives
Weight Based Shipping Table Rate for WooCommerce – Flexible Shipping
flexible-shipping
Weight based shipping methods for WooCommerce. Flexible shipping with table rate rules by cart weight and order value. Accurate rates at checkout.
Weight Based Shipping for WooCommerce
weight-based-shipping-for-woocommerce
Weight Based Shipping is a flexible and widely-used solution to calculate shipping costs based on the total cart weight and value.
WC – APG Weight Shipping
woocommerce-apg-weight-and-postcodestatecountry-shipping
Add to WooCommerce shipping costs calculating based on weight, size and post code, state (province) and/or customer’s country.
Custom Shipping Methods for WooCommerce – Create Weight based Shipping, Conditional Shipping, Table Rate Shipping and much more
custom-shipping-methods-for-woocommerce
Configure advanced shipping options for your WooCommerce store with custom shipping methods. Be it weight based shipping or volume based shipping or q …
Weight zone shipping for WooCommerce
oik-weight-zone-shipping
Adds shipping zone weight based shipping cost calculations to your WooCommerce store.
Disable Free Shipping for Heavyweight Orders Developer Profile
1 plugin · 0 total installs
How We Detect Disable Free Shipping for Heavyweight Orders
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/disable-free-shipping-for-heavyweight-orders/assets/css/dfsh-frontend.css/wp-content/plugins/disable-free-shipping-for-heavyweight-orders/assets/js/dfsh-frontend.js/wp-content/plugins/disable-free-shipping-for-heavyweight-orders/assets/js/dfsh-frontend.jsdisable-free-shipping-for-heavyweight-orders/assets/css/dfsh-frontend.css?ver=disable-free-shipping-for-heavyweight-orders/assets/js/dfsh-frontend.js?ver=HTML / DOM Fingerprints
dfsh-frontend-messagedata-dfsh-triggerdfsh_frontend_params