ELEX WooCommerce USPS Shipping Method Security & Risk Analysis

wordpress.org/plugins/elex-usps-shipping-method

The plugin will help you to Automate USPS shipping by displaying LIVE shipping rates on the Cart and Checkout page.

800 active installs v3.1.2 PHP + WP 3.0.0+ Updated Feb 2, 2026
usps-evsusps-labelusps-ratesusps-shippingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ELEX WooCommerce USPS Shipping Method Safe to Use in 2026?

Generally Safe

Score 100/100

ELEX WooCommerce USPS Shipping Method has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The static analysis of elex-usps-shipping-method v3.1.2 indicates a generally good security posture, with a limited attack surface primarily consisting of one AJAX handler, which crucially appears to have proper authentication checks. The absence of unprotected entry points, shortcodes, cron events, and REST API routes without permission callbacks is a strong positive signal. Code signals show a concerning lack of prepared statements for SQL queries, representing a significant potential risk for SQL injection, especially given the presence of file operations and external HTTP requests which could be leveraged in conjunction with unsanitized SQL input. While the vast majority of output is properly escaped and nonce checks are present, the single raw SQL query is a notable weakness. The plugin's history of zero known CVEs is a significant strength, suggesting a well-maintained codebase or limited prior scrutiny. However, the lack of any recorded vulnerabilities does not negate the identified SQL query risk. Overall, while the plugin demonstrates good practices in limiting its attack surface and escaping output, the raw SQL query presents a tangible, albeit isolated, threat that warrants attention.

Key Concerns

  • Raw SQL query without prepared statements
Vulnerabilities
None known

ELEX WooCommerce USPS Shipping Method Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

ELEX WooCommerce USPS Shipping Method Release Timeline

v3.1.2Current
v3.1.1
v3.1.0
v3.0.7
v3.0.6
v3.0.5
v3.0.4
v3.0.3
v3.0.2
v3.0.1
v3.0.0
v2.0.1
v2.0.0
v1.5.3
v1.5.2
v1.5.1
v1.5.0
v1.4.9
v1.4.8
v1.4.7
Code Analysis
Analyzed Mar 16, 2026

ELEX WooCommerce USPS Shipping Method Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
9
48 escaped
Nonce Checks
7
Capability Checks
0
File Operations
2
External Requests
6
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

84% escaped57 total outputs
Attack Surface

ELEX WooCommerce USPS Shipping Method Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_elex_usps_get_debug_logsusps-woocommerce-shipping.php:63
WordPress Hooks 9
filterwoocommerce_cart_shipping_method_full_labelincludes\class-elex-shipping-usps.php:160
actionadmin_noticesreview_and_troubleshoot_notify\review-and-troubleshoot-notify-class.php:20
actionadmin_initreview_and_troubleshoot_notify\review-and-troubleshoot-notify-class.php:21
actioninitusps-woocommerce-shipping.php:58
actionwoocommerce_shipping_initusps-woocommerce-shipping.php:60
filterwoocommerce_shipping_methodsusps-woocommerce-shipping.php:61
actionadmin_enqueue_scriptsusps-woocommerce-shipping.php:62
actionwp_enqueue_scriptsusps-woocommerce-shipping.php:64
actionbefore_woocommerce_initusps-woocommerce-shipping.php:152
Maintenance & Trust

ELEX WooCommerce USPS Shipping Method Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 2, 2026
PHP min version
Downloads28K

Community Trust

Rating88/100
Number of ratings7
Active installs800
Developer Profile

ELEX WooCommerce USPS Shipping Method Developer Profile

ELEXtensions

22 plugins · 28K total installs

87
trust score
Avg Security Score
98/100
Avg Patch Time
58 days
View full developer profile
Detection Fingerprints

How We Detect ELEX WooCommerce USPS Shipping Method

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/elex-usps-shipping-method/resources/debug_notice.js/wp-content/plugins/elex-usps-shipping-method/resources/wf_common.js/wp-content/plugins/elex-usps-shipping-method/resources/wf_usps_common_style.css
Script Paths
wp-content/plugins/elex-usps-shipping-method/resources/debug_notice.jswp-content/plugins/elex-usps-shipping-method/resources/wf_common.js
Version Parameters
elex-usps-shipping-method/resources/debug_notice.js?ver=elex-usps-shipping-method/resources/wf_common.js?ver=elex-usps-shipping-method/resources/wf_usps_common_style.css?ver=

HTML / DOM Fingerprints

JS Globals
elex_usps_console
FAQ

Frequently Asked Questions about ELEX WooCommerce USPS Shipping Method