Estonian Shipping Methods for WooCommerce Security & Risk Analysis

wordpress.org/plugins/estonian-shipping-methods-for-woocommerce

Extends WooCommerce with most commonly used Estonian shipping methods. All in one.

2K active installs v1.7.2 PHP + WP 4.1+ Updated Mar 24, 2023
dpdestoniashipping-methodsmartpostwoocommerce
63
C · Use Caution
CVEs total1
Unpatched1
Last CVESep 22, 2025
Safety Verdict

Is Estonian Shipping Methods for WooCommerce Safe to Use in 2026?

Use With Caution

Score 63/100

Estonian Shipping Methods for WooCommerce has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Sep 22, 2025Updated 3yr ago
Risk Assessment

The "estonian-shipping-methods-for-woocommerce" plugin, in version 1.7.2, exhibits a mixed security posture. On the positive side, the static analysis reveals no detected attack surface in terms of AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks. Furthermore, the code does not utilize dangerous functions, performs file operations, or generate SQL queries without prepared statements, indicating good development practices in these areas. The high percentage of properly escaped output is also a positive sign.

However, significant concerns arise from the vulnerability history and specific code signals. The existence of one unpatched medium severity CVE of type "Exposure of Sensitive Information to an Unauthorized Actor," with the last vulnerability reported in the future (2025-09-22), is a critical red flag. While the static analysis shows no critical or high taint flows and a limited number of flows overall, the presence of an external HTTP request without further context or sanitization checks could be a potential vector if it interacts with the unpatched vulnerability. The absence of nonce checks and capability checks across the board is a notable weakness, even with the current zero attack surface, as it offers no fallback security if new entry points were introduced or if the current analysis missed something.

In conclusion, while the plugin demonstrates sound practices in avoiding common code vulnerabilities like raw SQL and dangerous functions, the unpatched CVE presents a substantial immediate risk. The lack of comprehensive authorization checks (nonces and capabilities) further compounds this risk by leaving potential gaps for exploitation. This plugin should be treated with caution, and the unpatched vulnerability must be addressed urgently.

Key Concerns

  • Unpatched CVE
  • External HTTP request
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
1

Estonian Shipping Methods for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-58656medium · 5.3Exposure of Sensitive Information to an Unauthorized Actor

Estonian Shipping Methods for WooCommerce <= 1.7.2 - Unauthenticated Sensitive Information Exposure

Sep 22, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Estonian Shipping Methods for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
94 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

92% escaped102 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<class-wc-estonian-shipping-method-terminals> (includes\abstracts\class-wc-estonian-shipping-method-terminals.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Estonian Shipping Methods for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
actionplugins_loadedestonian-shipping-methods-for-woocommerce.php:83
actionwoocommerce_shipping_initestonian-shipping-methods-for-woocommerce.php:101
filterwoocommerce_shipping_methodsestonian-shipping-methods-for-woocommerce.php:104
filterwoocommerce_locate_templateestonian-shipping-methods-for-woocommerce.php:107
filterwoocommerce_locate_core_templateestonian-shipping-methods-for-woocommerce.php:108
actionbefore_woocommerce_initestonian-shipping-methods-for-woocommerce.php:110
actionwoocommerce_after_checkout_validationincludes\abstracts\class-wc-estonian-shipping-method-dpd-shops.php:35
actionwoocommerce_order_details_after_customer_detailsincludes\abstracts\class-wc-estonian-shipping-method-terminals.php:59
actionwoocommerce_email_customer_detailsincludes\abstracts\class-wc-estonian-shipping-method-terminals.php:60
actionwpo_wcpdf_after_order_dataincludes\abstracts\class-wc-estonian-shipping-method-terminals.php:63
actionwc_estonian_shipping_method_show_terminalincludes\abstracts\class-wc-estonian-shipping-method-terminals.php:66
filterwc_estonian_shipping_method_order_terminal_nameincludes\abstracts\class-wc-estonian-shipping-method-terminals.php:67
actionwoocommerce_admin_order_data_after_shipping_addressincludes\abstracts\class-wc-estonian-shipping-method-terminals.php:71
filterwoocommerce_admin_order_preview_get_order_detailsincludes\abstracts\class-wc-estonian-shipping-method-terminals.php:72
actionwoocommerce_review_order_after_shippingincludes\abstracts\class-wc-estonian-shipping-method-terminals.php:75
actionwoocommerce_checkout_update_order_metaincludes\abstracts\class-wc-estonian-shipping-method-terminals.php:76
actionwoocommerce_checkout_update_order_reviewincludes\abstracts\class-wc-estonian-shipping-method-terminals.php:77
actionwoocommerce_after_checkout_validationincludes\abstracts\class-wc-estonian-shipping-method-terminals.php:80
actionwoocommerce_order_status_changedincludes\methods\class-wc-estonian-shipping-method-collect-net.php:69
actionwoocommerce_after_checkout_validationincludes\methods\class-wc-estonian-shipping-method-collect-net.php:72
Maintenance & Trust

Estonian Shipping Methods for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedMar 24, 2023
PHP min version
Downloads24K

Community Trust

Rating78/100
Number of ratings7
Active installs2K
Developer Profile

Estonian Shipping Methods for WooCommerce Developer Profile

Risto Niinemets

4 plugins · 2K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Estonian Shipping Methods for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/estonian-shipping-methods-for-woocommerce/assets/js/frontend/package_select.js/wp-content/plugins/estonian-shipping-methods-for-woocommerce/assets/css/frontend/package_select.css
Script Paths
/wp-content/plugins/estonian-shipping-methods-for-woocommerce/assets/js/frontend/package_select.js
Version Parameters
estonian-shipping-methods-for-woocommerce/assets/js/frontend/package_select.js?ver=estonian-shipping-methods-for-woocommerce/assets/css/frontend/package_select.css?ver=

HTML / DOM Fingerprints

CSS Classes
estonian-shipping-method-package-select
Data Attributes
data-countrydata-plugin-url
JS Globals
estonian_shipping_method_package_select_params
FAQ

Frequently Asked Questions about Estonian Shipping Methods for WooCommerce