Fincart: Shipping Gateway Security & Risk Analysis

wordpress.org/plugins/fincart-shipping-integration

Connect WooCommerce with Fincart to send, track, and manage orders—including labels & manifestos—directly from your store.

0 active installs v1.1.23 PHP + WP 6.2+ Updated Jul 30, 2025
fincartfulfillmentlogisticsshippingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Fincart: Shipping Gateway Safe to Use in 2026?

Generally Safe

Score 100/100

Fincart: Shipping Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The 'fincart-shipping-integration' plugin version 1.1.23 exhibits a strong security posture based on the static analysis. All identified entry points, including AJAX handlers, have proper authentication checks in place. The code demonstrates excellent adherence to secure coding practices with 100% of SQL queries utilizing prepared statements and a high percentage (96%) of output being properly escaped. There are no critical or high severity taint flows identified, and the plugin does not perform file operations or include bundled libraries, reducing common attack vectors.

While the static analysis reveals a clean codebase with no immediate vulnerabilities, it's important to note the presence of one external HTTP request. The specific nature and handling of this request are not detailed, but it represents a potential, albeit small, attack surface if not implemented securely. The plugin's vulnerability history is entirely clean, with no recorded CVEs. This, combined with the robust static analysis, suggests a well-maintained and secure plugin. However, the absence of past vulnerabilities could also mean it hasn't been a significant target or thoroughly scrutinized in the past.

Vulnerabilities
None known

Fincart: Shipping Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Fincart: Shipping Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
4
98 escaped
Nonce Checks
7
Capability Checks
7
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared6 total queries

Output Escaping

96% escaped102 total outputs
Attack Surface

Fincart: Shipping Gateway Attack Surface

Entry Points7
Unprotected0

AJAX Handlers 7

authwp_ajax_fincart_refresh_secret_tokenadmin\class-fincart-admin.php:44
authwp_ajax_fincart_refresh_pickup_locationsadmin\class-fincart-admin.php:47
authwp_ajax_fincart_refresh_cities_areasadmin\class-fincart-admin.php:50
authwp_ajax_fincart_print_labelsincludes\class-fincart-label.php:47
authwp_ajax_fincart_print_manifestoincludes\class-fincart-manifesto.php:44
authwp_ajax_fincart_send_orderincludes\class-fincart-order.php:96
authwp_ajax_fincart_cancel_ordersincludes\class-fincart-order.php:97
WordPress Hooks 46
actionadmin_menuadmin\class-fincart-admin.php:35
actionadmin_enqueue_scriptsadmin\class-fincart-admin.php:38
actionfincart_daily_check_api_tokenadmin\class-fincart-admin.php:41
filterwoocommerce_admin_billing_fieldsadmin\class-fincart-admin.php:53
actionadmin_noticesadmin\class-fincart-admin.php:62
actionadmin_noticesadmin\class-fincart-admin.php:68
actionadmin_initadmin\class-fincart-settings.php:29
actionadmin_noticesadmin\class-fincart-settings.php:30
actionadmin_noticesfincart-shipping-integration.php:51
actionplugins_loadedfincart-shipping-integration.php:83
filterwoocommerce_billing_fieldsincludes\class-fincart-city-select.php:26
filterwoocommerce_shipping_fieldsincludes\class-fincart-city-select.php:27
filterwoocommerce_form_field_cityincludes\class-fincart-city-select.php:28
actionwp_enqueue_scriptsincludes\class-fincart-city-select.php:31
actionbefore_woocommerce_initincludes\class-fincart-city-select.php:34
filterbulk_actions-edit-shop_orderincludes\class-fincart-label.php:37
filterbulk_actions-woocommerce_page_wc-ordersincludes\class-fincart-label.php:38
actionadmin_enqueue_scriptsincludes\class-fincart-label.php:41
actionfincart_add_action_buttons_to_order_metaboxincludes\class-fincart-label.php:44
filterbulk_actions-edit-shop_orderincludes\class-fincart-manifesto.php:37
filterbulk_actions-woocommerce_page_wc-ordersincludes\class-fincart-manifesto.php:38
actionadmin_enqueue_scriptsincludes\class-fincart-manifesto.php:41
actionwoocommerce_thankyouincludes\class-fincart-order.php:50
actionwoocommerce_thankyouincludes\class-fincart-order.php:53
filtermanage_woocommerce_page_wc-orders_columnsincludes\class-fincart-order.php:57
actionmanage_woocommerce_page_wc-orders_custom_columnincludes\class-fincart-order.php:58
filtermanage_edit-shop_order_columnsincludes\class-fincart-order.php:60
actionmanage_shop_order_posts_custom_columnincludes\class-fincart-order.php:61
filterbulk_actions-edit-shop_orderincludes\class-fincart-order.php:64
filterbulk_actions-woocommerce_page_wc-ordersincludes\class-fincart-order.php:65
actionadmin_enqueue_scriptsincludes\class-fincart-order.php:68
actionadmin_enqueue_scriptsincludes\class-fincart-order.php:70
actionadd_meta_boxesincludes\class-fincart-order.php:73
actionwoocommerce_process_shop_order_metaincludes\class-fincart-order.php:76
actionwoocommerce_ajax_order_items_addedincludes\class-fincart-order.php:79
actionwoocommerce_ajax_order_items_removedincludes\class-fincart-order.php:83
actionwoocommerce_saved_order_itemsincludes\class-fincart-order.php:87
actionwoocommerce_order_status_changedincludes\class-fincart-order.php:90
actionwoocommerce_trash_orderincludes\class-fincart-order.php:93
actionrest_api_initincludes\class-fincart-webhook.php:29
filterwoocommerce_get_country_localeincludes\class-fincart-woo-checkout.php:29
filterwoocommerce_statesincludes\class-fincart-woo-checkout.php:30
filterfincart_wc_city_select_citiesincludes\class-fincart-woo-checkout.php:31
filterwoocommerce_billing_fieldsincludes\class-fincart-woo-checkout.php:32
actionwp_enqueue_scriptspublic\class-fincart-public.php:29
actionwoocommerce_view_orderpublic\class-fincart-public.php:32

Scheduled Events 1

fincart_daily_check_api_token
Maintenance & Trust

Fincart: Shipping Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 30, 2025
PHP min version
Downloads337

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Fincart: Shipping Gateway Developer Profile

Fincart

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Fincart: Shipping Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fincart-shipping-integration/assets/css/admin.css/wp-content/plugins/fincart-shipping-integration/assets/js/admin.js
Script Paths
/wp-content/plugins/fincart-shipping-integration/assets/js/admin.js
Version Parameters
fincart-shipping-integration/assets/css/admin.css?ver=fincart-shipping-integration/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
fincart-shipping-admin-wrapfincart-refresh-buttonfincart-shipping-fields
HTML Comments
<!-- Fincart Shipping Integration Admin Wrap Start --><!-- Fincart Shipping Integration Admin Wrap End --><!-- Fincart Admin Settings Page --><!-- Fincart Shipping Integration Admin Menu -->+6 more
Data Attributes
data-noncedata-action
JS Globals
fincart_admin_ajax_object
REST Endpoints
/wp-json/fincart/v1/webhook
FAQ

Frequently Asked Questions about Fincart: Shipping Gateway