EnviFast Shipping Security & Risk Analysis

wordpress.org/plugins/envifast-shipping

Este plugin te ayudará con la gestión de envíos en tu tienda en linea

10 active installs v1.6.0 PHP 7.0+ WP 5.0+ Updated Nov 6, 2024
ecommercelogisticsshippingwoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is EnviFast Shipping Safe to Use in 2026?

Generally Safe

Score 92/100

EnviFast Shipping has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "envifast-shipping" plugin exhibits a generally good security posture based on the provided static analysis. A low attack surface with only one AJAX handler, which fortunately appears to have a nonce check, is a positive indicator. The complete absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. Furthermore, the high percentage of properly escaped output and the presence of a nonce check suggest a developer mindful of common web security pitfalls. The plugin's vulnerability history is also clean, with no known CVEs, indicating a lack of previously identified security flaws.

While the static analysis reveals no critical or high-severity issues in taint flows, and the overall code quality appears strong, a notable concern is the complete absence of capability checks. This means that even though an AJAX handler has a nonce check, any authenticated user, regardless of their role or permissions, could potentially interact with it. This could lead to unintended actions or information disclosure if the AJAX handler performs sensitive operations. The lack of specific permission enforcement on the sole entry point is the primary area for improvement, as it broadens the potential impact of any future, unforeseen vulnerabilities.

In conclusion, the "envifast-shipping" plugin demonstrates a strong foundation in secure coding practices, particularly in its handling of SQL and output. The lack of vulnerability history is also a significant positive. However, the absence of capability checks on its entry point represents a potential weakness that should be addressed to further harden its security. The developer has shown a good understanding of many security principles, but can enhance it by implementing role-based access control for its functionalities.

Key Concerns

  • Missing capability checks on AJAX handler
Vulnerabilities
None known

EnviFast Shipping Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

EnviFast Shipping Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
23 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

88% escaped26 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
send_order_info_to_envifast_ajax_callback (envifast-shipping.php:275)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

EnviFast Shipping Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_wc_es_send_order_to_envifastenvifast-shipping.php:42
WordPress Hooks 11
actionwoocommerce_shipping_initenvifast-shipping.php:29
filterwoocommerce_shipping_methodsenvifast-shipping.php:30
actionwoocommerce_after_shipping_calculatorenvifast-shipping.php:34
actionwoocommerce_after_shipping_rateenvifast-shipping.php:36
actionwoocommerce_order_status_processingenvifast-shipping.php:38
actionadd_meta_boxesenvifast-shipping.php:40
filtermanage_edit-product_columnsenvifast-shipping.php:44
actionmanage_product_posts_custom_columnenvifast-shipping.php:45
filterwoocommerce_add_to_cart_validationenvifast-shipping.php:47
actionwp_enqueue_scriptsenvifast-shipping.php:158
actionwp_enqueue_scriptsenvifast-shipping.php:238
Maintenance & Trust

EnviFast Shipping Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedNov 6, 2024
PHP min version7.0
Downloads960

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

EnviFast Shipping Developer Profile

Add WT

1 plugin · 10 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect EnviFast Shipping

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/envifast-shipping/assets/js/envifast-shipping-admin.js/wp-content/plugins/envifast-shipping/assets/css/envifast-shipping-admin.css
Script Paths
/wp-content/plugins/envifast-shipping/assets/js/envifast-shipping-admin.js
Version Parameters
envifast-shipping/assets/js/envifast-shipping-admin.js?ver=envifast-shipping/assets/css/envifast-shipping-admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
envifast_ready
HTML Comments
<!-- Meta box for showing status of Order info sent to EnviFast or sending it manually --><!-- Ajax call back to process manual sending order details to EnviFast --><!-- Columns for EnviFast ready status to Products in Product List of admin panel --><!-- Validating products being added to cart to make sure it has dimensions and weight set -->
Data Attributes
title
FAQ

Frequently Asked Questions about EnviFast Shipping