Edit Shipping Address for WooCommerce Security & Risk Analysis

wordpress.org/plugins/edit-shipping-address-for-woocommerce

This plugin allows customers to update their shipping address for WooCommerce orders after purchase.

0 active installs v1.0.0 PHP 7.4+ WP 6.5+ Updated Jun 9, 2025
address-updateordershippingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Edit Shipping Address for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Edit Shipping Address for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "edit-shipping-address-for-woocommerce" plugin v1.0.0 demonstrates a strong security posture based on the provided static analysis. All identified entry points, which primarily consist of 24 AJAX handlers, are protected by authentication checks, and there are no unauthenticated REST API routes, shortcodes, or cron events. The code utilizes prepared statements for all SQL queries, and a high percentage of output is properly escaped, significantly mitigating the risk of injection and cross-site scripting vulnerabilities. The absence of file operations and critical or high-severity taint flows further reinforces its secure design. The plugin also has no recorded vulnerability history, indicating a proactive approach to security by the developers or a lack of past exploitation.

However, there are a couple of areas that warrant attention. The presence of 13 external HTTP requests, while not inherently a vulnerability, could become a vector for supply chain attacks if any of the external services are compromised. Additionally, the plugin has 14 nonce checks but no capability checks implemented. While nonce checks protect against CSRF attacks, the absence of capability checks means that once authenticated, users might have broader access than intended, especially if the AJAX actions can be leveraged for sensitive operations. This plugin generally follows good security practices, but the capability checks and external requests are minor points to consider for a more robust security implementation.

Key Concerns

  • No capability checks on AJAX handlers
  • 13 external HTTP requests
Vulnerabilities
None known

Edit Shipping Address for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Edit Shipping Address for WooCommerce Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

Edit Shipping Address for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
96 escaped
Nonce Checks
14
Capability Checks
0
File Operations
0
External Requests
13
Bundled Libraries
0

Output Escaping

98% escaped98 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<edit-shipping-address-template> (includes/edit-shipping-address-template.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Edit Shipping Address for WooCommerce Attack Surface

Entry Points24
Unprotected0

AJAX Handlers 24

authwp_ajax_editsafwCreatePaymentSessionincludes/class-edit-shipping-address.php:58
noprivwp_ajax_editsafwCreatePaymentSessionincludes/class-edit-shipping-address.php:62
authwp_ajax_editsafwCalNewShippingincludes/class-edit-shipping-address.php:66
noprivwp_ajax_editsafwCalNewShippingincludes/class-edit-shipping-address.php:70
authwp_ajax_editsafwSaveDataincludes/class-edit-shipping-address.php:74
noprivwp_ajax_editsafwSaveDataincludes/class-edit-shipping-address.php:78
authwp_ajax_editsafwCreateOrderincludes/class-edit-shipping-address.php:82
noprivwp_ajax_editsafwCreateOrderincludes/class-edit-shipping-address.php:86
authwp_ajax_editsafwProcessRefundincludes/class-edit-shipping-address.php:90
noprivwp_ajax_editsafwProcessRefundincludes/class-edit-shipping-address.php:94
authwp_ajax_editsafwGetStripePaymentMethodincludes/class-edit-shipping-address.php:98
noprivwp_ajax_editsafwGetStripePaymentMethodincludes/class-edit-shipping-address.php:102
authwp_ajax_editsafwCreatePayPalOrderincludes/class-edit-shipping-address.php:106
noprivwp_ajax_editsafwCreatePayPalOrderincludes/class-edit-shipping-address.php:110
authwp_ajax_editsafwCompletePayPalPaymentincludes/class-edit-shipping-address.php:114
noprivwp_ajax_editsafwCompletePayPalPaymentincludes/class-edit-shipping-address.php:118
authwp_ajax_editsafwCreateRazorpayOrderincludes/class-edit-shipping-address.php:122
noprivwp_ajax_editsafwCreateRazorpayOrderincludes/class-edit-shipping-address.php:126
authwp_ajax_editsafwCaptureRazorpayPaymentincludes/class-edit-shipping-address.php:130
noprivwp_ajax_editsafwCaptureRazorpayPaymentincludes/class-edit-shipping-address.php:134
authwp_ajax_editsafwGetTempShippingDataincludes/class-edit-shipping-address.php:138
noprivwp_ajax_editsafwGetTempShippingDataincludes/class-edit-shipping-address.php:142
authwp_ajax_editsafwDeleteTempShippingDataincludes/class-edit-shipping-address.php:146
noprivwp_ajax_editsafwDeleteTempShippingDataincludes/class-edit-shipping-address.php:150
WordPress Hooks 11
actionplugins_loadededit-shipping-address-for-woocommerce.php:51
filtertheme_page_templatesedit-shipping-address-for-woocommerce.php:77
actionadmin_menuedit-shipping-address-for-woocommerce.php:168
actionadmin_initedit-shipping-address-for-woocommerce.php:222
actionbefore_woocommerce_initedit-shipping-address-for-woocommerce.php:419
actionadmin_enqueue_scriptsincludes/class-edit-shipping-address.php:40
actionwp_enqueue_scriptsincludes/class-edit-shipping-address.php:44
filtertemplate_includeincludes/class-edit-shipping-address.php:48
actionwoocommerce_order_details_after_order_tableincludes/class-edit-shipping-address.php:52
filterwoocommerce_is_checkoutincludes/class-edit-shipping-address.php:227
filterwoocommerce_available_payment_gatewaysincludes/edit-shipping-address-template.php:249
Maintenance & Trust

Edit Shipping Address for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 9, 2025
PHP min version7.4
Downloads323

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Edit Shipping Address for WooCommerce Developer Profile

brainvireinfo

16 plugins · 7K total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
14 days
View full developer profile
Detection Fingerprints

How We Detect Edit Shipping Address for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/edit-shipping-address-for-woocommerce/assets/css/edit-shipping-address.css/wp-content/plugins/edit-shipping-address-for-woocommerce/assets/js/edit-shipping-address.js
Script Paths
/wp-content/plugins/edit-shipping-address-for-woocommerce/assets/js/edit-shipping-address.js
Version Parameters
edit-shipping-address-for-woocommerce/assets/css/edit-shipping-address.css?ver=edit-shipping-address-for-woocommerce/assets/js/edit-shipping-address.js?ver=

HTML / DOM Fingerprints

CSS Classes
editsafw-edit-shipping-address-formeditsafw-update-address-button
HTML Comments
<!-- Start: editsafw_registerCustomTemplateFromPlugin --><!-- Start: editsafwCreateEditShippingAddressPage --><!-- End: editsafwCreateEditShippingAddressPage --><!-- Start: editsafwDeleteEditShippingAddressPage -->+9 more
Data Attributes
data-plugin-url="/wp-content/plugins/edit-shipping-address-for-woocommerce/"
JS Globals
window.editsafw_params
Shortcode Output
[edit_shipping_address]
FAQ

Frequently Asked Questions about Edit Shipping Address for WooCommerce