
ELEX WooCommerce USPS Shipping Method Security & Risk Analysis
wordpress.org/plugins/elex-usps-shipping-methodThe plugin will help you to Automate USPS shipping by displaying LIVE shipping rates on the Cart and Checkout page.
Is ELEX WooCommerce USPS Shipping Method Safe to Use in 2026?
Generally Safe
Score 100/100ELEX WooCommerce USPS Shipping Method has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of elex-usps-shipping-method v3.1.2 indicates a generally good security posture, with a limited attack surface primarily consisting of one AJAX handler, which crucially appears to have proper authentication checks. The absence of unprotected entry points, shortcodes, cron events, and REST API routes without permission callbacks is a strong positive signal. Code signals show a concerning lack of prepared statements for SQL queries, representing a significant potential risk for SQL injection, especially given the presence of file operations and external HTTP requests which could be leveraged in conjunction with unsanitized SQL input. While the vast majority of output is properly escaped and nonce checks are present, the single raw SQL query is a notable weakness. The plugin's history of zero known CVEs is a significant strength, suggesting a well-maintained codebase or limited prior scrutiny. However, the lack of any recorded vulnerabilities does not negate the identified SQL query risk. Overall, while the plugin demonstrates good practices in limiting its attack surface and escaping output, the raw SQL query presents a tangible, albeit isolated, threat that warrants attention.
Key Concerns
- Raw SQL query without prepared statements
ELEX WooCommerce USPS Shipping Method Security Vulnerabilities
ELEX WooCommerce USPS Shipping Method Release Timeline
ELEX WooCommerce USPS Shipping Method Code Analysis
SQL Query Safety
Output Escaping
ELEX WooCommerce USPS Shipping Method Attack Surface
AJAX Handlers 1
WordPress Hooks 9
Maintenance & Trust
ELEX WooCommerce USPS Shipping Method Maintenance & Trust
Maintenance Signals
Community Trust
ELEX WooCommerce USPS Shipping Method Alternatives
Shipping Live Rates for USPS for WooCommerce
flexible-shipping-usps
Offer USPS shipping methods with real-time rates. Show dynamic prices at WooCommerce cart and checkout based on weight and destination.
USPS Shipping for WooCommerce – Live Rates
advanced-usps-shipping-method
Advanced USPS Shipping Allows you to display the USPS live rates.
USPS Simple Shipping for Woocommerce
woo-usps-simple-shipping
USPS Simple provides real-time USPS domestic rates.
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Limit Login Attempts Reloaded – Login Security, 2FA, Brute Force Protection & Firewall
limit-login-attempts-reloaded
Stop password guessing attacks, secure WooCommerce, block bad IPs, block by countries (Pro), and add email 2FA. Lightweight with better performance.
ELEX WooCommerce USPS Shipping Method Developer Profile
22 plugins · 28K total installs
How We Detect ELEX WooCommerce USPS Shipping Method
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/elex-usps-shipping-method/resources/debug_notice.js/wp-content/plugins/elex-usps-shipping-method/resources/wf_common.js/wp-content/plugins/elex-usps-shipping-method/resources/wf_usps_common_style.csswp-content/plugins/elex-usps-shipping-method/resources/debug_notice.jswp-content/plugins/elex-usps-shipping-method/resources/wf_common.jselex-usps-shipping-method/resources/debug_notice.js?ver=elex-usps-shipping-method/resources/wf_common.js?ver=elex-usps-shipping-method/resources/wf_usps_common_style.css?ver=HTML / DOM Fingerprints
elex_usps_console