ELEX ShipEngine UPS & FedEx Shipping Method Security & Risk Analysis

wordpress.org/plugins/elex-shipengine-shipping-method

WooCommerce UPS & FedEx Shipping Method Plugin uses ShipEngine API to Display Live Shipping Rates from UPS & FedEx based on Shipping Address & …

70 active installs v1.2.8 PHP + WP 3.0.1+ Updated Feb 2, 2026
fedexshipengineshippingups
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ELEX ShipEngine UPS & FedEx Shipping Method Safe to Use in 2026?

Generally Safe

Score 100/100

ELEX ShipEngine UPS & FedEx Shipping Method has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The elex-shipengine-shipping-method plugin version 1.2.8 demonstrates a generally good security posture based on the provided static analysis. A significant strength is the absence of any detected critical or high-severity taint flows, indicating that data sanitization and input validation appear to be handled effectively, preventing common injection vulnerabilities. The plugin also boasts a high percentage of properly escaped output and no identified file operations, further reducing the attack surface for cross-site scripting and arbitrary file manipulation.

However, there are areas for improvement. The plugin executes a single SQL query that is not using prepared statements, which, while not inherently a vulnerability if input is rigorously sanitized elsewhere, presents a potential risk of SQL injection if sanitization fails. Furthermore, the lack of capability checks on the sole AJAX handler is a notable concern. While there are nonce checks in place, the absence of authorization checks means that any authenticated user, regardless of their role or permissions, could potentially interact with this AJAX endpoint. The plugin's vulnerability history is clear, with no recorded CVEs, which is a positive indicator of past security diligence or a lack of extensive auditing.

In conclusion, the plugin is reasonably secure, with its strengths lying in its minimal attack surface, lack of critical taint issues, and good output escaping. The primary weaknesses are the non-prepared SQL query and the absence of capability checks on the AJAX handler. Addressing these specific points would significantly enhance the plugin's overall security.

Key Concerns

  • Raw SQL query without prepared statements
  • AJAX handler without capability checks
Vulnerabilities
None known

ELEX ShipEngine UPS & FedEx Shipping Method Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ELEX ShipEngine UPS & FedEx Shipping Method Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
4
66 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

94% escaped70 total outputs
Attack Surface

ELEX ShipEngine UPS & FedEx Shipping Method Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_elex_shipengine_get_rates_request_logsshipengine-woocommerce-shipping.php:86
WordPress Hooks 9
actionadmin_noticesreview_and_troubleshoot_notify\review-and-troubleshoot-notify-class.php:20
actionadmin_initreview_and_troubleshoot_notify\review-and-troubleshoot-notify-class.php:21
actionadmin_noticesshipengine-woocommerce-shipping.php:27
actioninitshipengine-woocommerce-shipping.php:80
actionwoocommerce_shipping_initshipengine-woocommerce-shipping.php:82
filterwoocommerce_shipping_methodsshipengine-woocommerce-shipping.php:83
actionadmin_enqueue_scriptsshipengine-woocommerce-shipping.php:84
actionwp_enqueue_scriptsshipengine-woocommerce-shipping.php:85
actionbefore_woocommerce_initshipengine-woocommerce-shipping.php:200
Maintenance & Trust

ELEX ShipEngine UPS & FedEx Shipping Method Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 2, 2026
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs70
Developer Profile

ELEX ShipEngine UPS & FedEx Shipping Method Developer Profile

ELEXtensions

22 plugins · 28K total installs

87
trust score
Avg Security Score
98/100
Avg Patch Time
53 days
View full developer profile
Detection Fingerprints

How We Detect ELEX ShipEngine UPS & FedEx Shipping Method

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/elex-shipengine-shipping-method/resources/css/wf_common_style.css/wp-content/plugins/elex-shipengine-shipping-method/resources/css/bootstrap.css/wp-content/plugins/elex-shipengine-shipping-method/resources/js/wf_common.js/wp-content/plugins/elex-shipengine-shipping-method/resources/js/elex_shipengine.js/wp-content/plugins/elex-shipengine-shipping-method/resources/js/notice.js
Script Paths
/wp-content/plugins/elex-shipengine-shipping-method/resources/js/wf_common.js/wp-content/plugins/elex-shipengine-shipping-method/resources/js/elex_shipengine.js/wp-content/plugins/elex-shipengine-shipping-method/resources/js/notice.js
Version Parameters
/wp-content/plugins/elex-shipengine-shipping-method/resources/css/wf_common_style.css?ver=/wp-content/plugins/elex-shipengine-shipping-method/resources/css/bootstrap.css?ver=/wp-content/plugins/elex-shipengine-shipping-method/resources/js/wf_common.js?ver=/wp-content/plugins/elex-shipengine-shipping-method/resources/js/elex_shipengine.js?ver=/wp-content/plugins/elex-shipengine-shipping-method/resources/js/notice.js?ver=1.1.0

HTML / DOM Fingerprints

JS Globals
elex_shipengine_cart_checkout
REST Endpoints
/wp-json/elex-shipengine-shipping-method/v1/get-logs
FAQ

Frequently Asked Questions about ELEX ShipEngine UPS & FedEx Shipping Method