ELEX WooCommerce Australia Post Shipping Security & Risk Analysis

wordpress.org/plugins/elex-australia-post-shipping

The Ultimate WooCommerce Australia Post Shipping Plugin from Team ELEXtensions. The plugin integrates Australia Post APIs with WooCommerce.

200 active installs v3.0.8 PHP + WP 3.0.2+ Updated Feb 2, 2026
australia-postaustralia-post-shippingshippingshipping-rateswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ELEX WooCommerce Australia Post Shipping Safe to Use in 2026?

Generally Safe

Score 100/100

ELEX WooCommerce Australia Post Shipping has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "elex-australia-post-shipping" plugin v3.0.8 demonstrates a generally good security posture with no recorded vulnerabilities or critical findings in the static analysis. The complete absence of SQL injection vulnerabilities due to the exclusive use of prepared statements and the lack of file operations are significant strengths. Furthermore, the plugin has a limited attack surface, with only two AJAX handlers and no shortcodes or cron events, which reduces the potential for exploitation. The presence of nonce checks and a reasonable percentage of output escaping also contribute positively to its security.

However, there are areas for improvement. The 24% of outputs that are not properly escaped present a potential Cross-Site Scripting (XSS) risk if user-supplied data is not adequately sanitized before being displayed. While there are no identified critical taint flows, this lack of full output sanitization could still lead to vulnerabilities if exploited. The plugin also makes four external HTTP requests, which, while not inherently a vulnerability, introduces potential risks if the target endpoints are compromised or if sensitive data is transmitted insecurely.

Overall, the plugin appears to be well-maintained with no historical vulnerabilities, suggesting a commitment to security by its developers. The static analysis reveals good practices in critical areas like SQL query handling and attack surface reduction. The primary concern lies in the incomplete output escaping, which, while not a critical finding in this analysis, is a common vector for XSS attacks. Addressing this would further solidify the plugin's security.

Key Concerns

  • Outputs not properly escaped
  • External HTTP requests present
Vulnerabilities
None known

ELEX WooCommerce Australia Post Shipping Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ELEX WooCommerce Australia Post Shipping Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
24
76 escaped
Nonce Checks
5
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
0

Output Escaping

76% escaped100 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<class-elex-australia-post-shipping> (includes\class-elex-australia-post-shipping.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ELEX WooCommerce Australia Post Shipping Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_auspost_get_rates_request_logsaustralia-post-woocommerce-shipping.php:99
authwp_ajax_norpiv_auspost_get_rates_request_logsaustralia-post-woocommerce-shipping.php:100
WordPress Hooks 13
actionplugins_loadedaustralia-post-deprecated-functions.php:10
actionplugins_loadedaustralia-post-woocommerce-shipping.php:67
actioninitaustralia-post-woocommerce-shipping.php:93
actionwoocommerce_shipping_initaustralia-post-woocommerce-shipping.php:95
filterwoocommerce_shipping_methodsaustralia-post-woocommerce-shipping.php:96
filteradmin_enqueue_scriptsaustralia-post-woocommerce-shipping.php:97
actionwp_enqueue_scriptsaustralia-post-woocommerce-shipping.php:98
actionwoocommerce_product_options_shippingaustralia-post-woocommerce-shipping.php:189
actionwoocommerce_process_product_metaaustralia-post-woocommerce-shipping.php:190
actionbefore_woocommerce_initaustralia-post-woocommerce-shipping.php:262
filterwoocommerce_cart_shipping_method_full_labelincludes\class-elex-australia-post-functions.php:10
actionadmin_noticesreview_and_troubleshoot_notify\review-and-troubleshoot-notify-class.php:20
actionadmin_initreview_and_troubleshoot_notify\review-and-troubleshoot-notify-class.php:21
Maintenance & Trust

ELEX WooCommerce Australia Post Shipping Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 2, 2026
PHP min version
Downloads7K

Community Trust

Rating80/100
Number of ratings12
Active installs200
Developer Profile

ELEX WooCommerce Australia Post Shipping Developer Profile

ELEXtensions

22 plugins · 28K total installs

87
trust score
Avg Security Score
98/100
Avg Patch Time
53 days
View full developer profile
Detection Fingerprints

How We Detect ELEX WooCommerce Australia Post Shipping

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/elex-australia-post-shipping/js/auspost_base_cart_checkout_script.js/wp-content/plugins/elex-australia-post-shipping/js/elex-auspost-custom.js/wp-content/plugins/elex-australia-post-shipping/css/bootstrap.css
Script Paths
/wp-content/plugins/elex-australia-post-shipping/js/auspost_base_cart_checkout_script.js/wp-content/plugins/elex-australia-post-shipping/js/elex-auspost-custom.js
Version Parameters
elex-australia-post-shipping/js/auspost_base_cart_checkout_script.js?ver=elex-australia-post-shipping/js/elex-auspost-custom.js?ver=

HTML / DOM Fingerprints

CSS Classes
wf-bootstrap
Data Attributes
elex-auspost-custom
JS Globals
auspost_base_cart_checkout
REST Endpoints
/wp-json/elex-australia-post-shipping
FAQ

Frequently Asked Questions about ELEX WooCommerce Australia Post Shipping