
ELEX ShipEngine UPS & FedEx Shipping Method Security & Risk Analysis
wordpress.org/plugins/elex-shipengine-shipping-methodWooCommerce UPS & FedEx Shipping Method Plugin uses ShipEngine API to Display Live Shipping Rates from UPS & FedEx based on Shipping Address & …
Is ELEX ShipEngine UPS & FedEx Shipping Method Safe to Use in 2026?
Generally Safe
Score 100/100ELEX ShipEngine UPS & FedEx Shipping Method has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The elex-shipengine-shipping-method plugin version 1.2.8 demonstrates a generally good security posture based on the provided static analysis. A significant strength is the absence of any detected critical or high-severity taint flows, indicating that data sanitization and input validation appear to be handled effectively, preventing common injection vulnerabilities. The plugin also boasts a high percentage of properly escaped output and no identified file operations, further reducing the attack surface for cross-site scripting and arbitrary file manipulation.
However, there are areas for improvement. The plugin executes a single SQL query that is not using prepared statements, which, while not inherently a vulnerability if input is rigorously sanitized elsewhere, presents a potential risk of SQL injection if sanitization fails. Furthermore, the lack of capability checks on the sole AJAX handler is a notable concern. While there are nonce checks in place, the absence of authorization checks means that any authenticated user, regardless of their role or permissions, could potentially interact with this AJAX endpoint. The plugin's vulnerability history is clear, with no recorded CVEs, which is a positive indicator of past security diligence or a lack of extensive auditing.
In conclusion, the plugin is reasonably secure, with its strengths lying in its minimal attack surface, lack of critical taint issues, and good output escaping. The primary weaknesses are the non-prepared SQL query and the absence of capability checks on the AJAX handler. Addressing these specific points would significantly enhance the plugin's overall security.
Key Concerns
- Raw SQL query without prepared statements
- AJAX handler without capability checks
ELEX ShipEngine UPS & FedEx Shipping Method Security Vulnerabilities
ELEX ShipEngine UPS & FedEx Shipping Method Code Analysis
SQL Query Safety
Output Escaping
ELEX ShipEngine UPS & FedEx Shipping Method Attack Surface
AJAX Handlers 1
WordPress Hooks 9
Maintenance & Trust
ELEX ShipEngine UPS & FedEx Shipping Method Maintenance & Trust
Maintenance Signals
Community Trust
ELEX ShipEngine UPS & FedEx Shipping Method Alternatives
BLAZING Shipment Tracking
blazing-woocommerce-shipment-tracking
This plugin adds courier and tracking number to the woocommerce order, and a dedicated email to send shipment tracking info to the customer.
Descartes ShipRush Integration
descartes-shiprush-integration
Export orders to My.ShipRush.com and update tracking details.
Shipping Live Rates and Access Points for UPS for WooCommerce
flexible-shipping-ups
Provide auto-calculated UPS rates and Access Point options. Easy 5-minute setup. Show real prices and nearest pickup points at WooCommerce checkout.
Shiptastic Integration for DHL
shiptastic-integration-for-dhl
Connect Shiptastic to the DHL API and create DHL labels to shipments and returns.
Shipping Live Rates for FedEx for WooCommerce
flexible-shipping-fedex
Offer FedEx shipping for WooCommerce with real-time rates via FedEx API. Show live rates at checkout based on weight and addresses.
ELEX ShipEngine UPS & FedEx Shipping Method Developer Profile
22 plugins · 28K total installs
How We Detect ELEX ShipEngine UPS & FedEx Shipping Method
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/elex-shipengine-shipping-method/resources/css/wf_common_style.css/wp-content/plugins/elex-shipengine-shipping-method/resources/css/bootstrap.css/wp-content/plugins/elex-shipengine-shipping-method/resources/js/wf_common.js/wp-content/plugins/elex-shipengine-shipping-method/resources/js/elex_shipengine.js/wp-content/plugins/elex-shipengine-shipping-method/resources/js/notice.js/wp-content/plugins/elex-shipengine-shipping-method/resources/js/wf_common.js/wp-content/plugins/elex-shipengine-shipping-method/resources/js/elex_shipengine.js/wp-content/plugins/elex-shipengine-shipping-method/resources/js/notice.js/wp-content/plugins/elex-shipengine-shipping-method/resources/css/wf_common_style.css?ver=/wp-content/plugins/elex-shipengine-shipping-method/resources/css/bootstrap.css?ver=/wp-content/plugins/elex-shipengine-shipping-method/resources/js/wf_common.js?ver=/wp-content/plugins/elex-shipengine-shipping-method/resources/js/elex_shipengine.js?ver=/wp-content/plugins/elex-shipengine-shipping-method/resources/js/notice.js?ver=1.1.0HTML / DOM Fingerprints
elex_shipengine_cart_checkout/wp-json/elex-shipengine-shipping-method/v1/get-logs