Easy Table Rate Shipping for WooCommmerce Security & Risk Analysis

wordpress.org/plugins/easy-table-rate-shipping-for-woocommerce

Table rate shipping extends WooCommerce’s default shipping options letting you calculate shipping costs based on total price, item count, weight, etc

200 active installs v1.3.0 PHP + WP 4.0+ Updated Dec 10, 2023
conditional-shippingfree-shippingtable-rate-shippingwoocommerce-shippingwoocommerce-table-rate-shipping
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Easy Table Rate Shipping for WooCommmerce Safe to Use in 2026?

Generally Safe

Score 85/100

Easy Table Rate Shipping for WooCommmerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "easy-table-rate-shipping-for-woocommerce" plugin v1.3.0 exhibits a generally positive security posture due to a very limited attack surface and a lack of recorded vulnerabilities. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly reduces the potential entry points for attackers. Furthermore, the presence of nonce and capability checks, along with a relatively good percentage of properly escaped output, indicates adherence to some secure coding practices.

However, there are notable areas of concern. The plugin utilizes two SQL queries, neither of which employ prepared statements. This is a significant risk, as it opens the door to potential SQL injection vulnerabilities if user-supplied data is incorporated into these queries without proper sanitization or parameterization. Additionally, the taint analysis revealed two flows with unsanitized paths, although thankfully no critical or high-severity issues were identified in this regard. The presence of external HTTP requests, while not inherently risky, warrants attention to ensure they are handled securely and don't expose the site to further vulnerabilities.

The plugin's vulnerability history is clean, with no recorded CVEs. This is a strong positive indicator, suggesting that the developers have historically maintained a secure codebase or that the plugin hasn't been a target for in-depth vulnerability research. However, the static analysis findings, particularly the raw SQL queries and unsanitized paths, highlight that even without a history of disclosed vulnerabilities, inherent risks can still exist. The conclusion is that while the plugin is currently free of publicly known vulnerabilities and has a limited attack surface, the unescaped SQL queries and unsanitized paths present tangible risks that should be addressed to strengthen its overall security.

Key Concerns

  • Raw SQL queries without prepared statements
  • Taint flows with unsanitized paths
  • External HTTP requests
Vulnerabilities
None known

Easy Table Rate Shipping for WooCommmerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Easy Table Rate Shipping for WooCommmerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
40
71 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

64% escaped111 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

6 flows2 with unsanitized paths
formActionUrl (inc\appsero\src\License.php:713)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Easy Table Rate Shipping for WooCommmerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
actionadmin_noticesaazz-wc-main.php:25
actionplugins_loadedaazz-wc-main.php:28
actionadmin_enqueue_scriptsaazz-wc-main.php:30
actionwoocommerce_shipping_initinc\aazz-wc-shipping-method.php:9
filterwoocommerce_shipping_methodsinc\aazz-wc-shipping-method.php:15
actionswitch_themeinc\appsero\src\Insights.php:134
actionswitch_themeinc\appsero\src\Insights.php:135
actionadmin_footerinc\appsero\src\Insights.php:147
actionadmin_noticesinc\appsero\src\Insights.php:165
actionadmin_initinc\appsero\src\Insights.php:168
filtercron_schedulesinc\appsero\src\Insights.php:174
actionadmin_menuinc\appsero\src\License.php:205
actionafter_switch_themeinc\appsero\src\License.php:704
actionswitch_themeinc\appsero\src\License.php:705
filterpre_set_site_transient_update_pluginsinc\appsero\src\Updater.php:42
filterplugins_apiinc\appsero\src\Updater.php:43
filterpre_set_site_transient_update_themesinc\appsero\src\Updater.php:52
Maintenance & Trust

Easy Table Rate Shipping for WooCommmerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedDec 10, 2023
PHP min version
Downloads10K

Community Trust

Rating40/100
Number of ratings2
Active installs200
Developer Profile

Easy Table Rate Shipping for WooCommmerce Developer Profile

Exlac

3 plugins · 300 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Easy Table Rate Shipping for WooCommmerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easy-table-rate-shipping-for-woocommerce/assets/shipping.css/wp-content/plugins/easy-table-rate-shipping-for-woocommerce/assets/shipping.js
Script Paths
easy-table-rate-shipping-for-woocommerce/assets/shipping.js
Version Parameters
easy-table-rate-shipping-for-woocommerce/assets/shipping.css?ver=easy-table-rate-shipping-for-woocommerce/assets/shipping.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-instance_id
FAQ

Frequently Asked Questions about Easy Table Rate Shipping for WooCommmerce