
Advanced Shipping Rates for WooCommerce: Flexible Table Rate Shipping Rules Security & Risk Analysis
wordpress.org/plugins/fish-and-shipsAll-in-one Table Rate Shipping: set flexible rules, offer conditional free shipping, define rates by weight, size, volume, volumetric calculations...
Is Advanced Shipping Rates for WooCommerce: Flexible Table Rate Shipping Rules Safe to Use in 2026?
Generally Safe
Score 99/100Advanced Shipping Rates for WooCommerce: Flexible Table Rate Shipping Rules has a strong security track record. Known vulnerabilities have been patched promptly.
The "fish-and-ships" plugin v2.1.7 presents a mixed security posture. While it demonstrates good practices in its SQL query handling, properly escaping a high percentage of outputs, and having no external HTTP requests, significant concerns arise from its attack surface. A total of 9 AJAX handlers are exposed, and alarmingly, all of them lack authentication checks. This creates a wide entry point for potential attackers. Furthermore, the presence of the `unserialize` function, even if not immediately appearing in taint flows as critical or high, is a known risk factor that requires careful handling of serialized data. The plugin's vulnerability history shows one medium severity CVE related to Cross-Site Scripting, which was recently discovered. While currently unpatched, the absence of critical or high severity vulnerabilities in its history might indicate a generally improving security awareness, but the single XSS vulnerability highlights a persistent type of risk that needs vigilance.
Key Concerns
- All AJAX handlers lack authentication checks
- Presence of dangerous function: unserialize
- Medium severity CVE (XSS) in history
- Flows with unsanitized paths
Advanced Shipping Rates for WooCommerce: Flexible Table Rate Shipping Rules Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Fish and Ships <= 1.5.9 - Reflected Cross-Site Scripting
Advanced Shipping Rates for WooCommerce: Flexible Table Rate Shipping Rules Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Advanced Shipping Rates for WooCommerce: Flexible Table Rate Shipping Rules Attack Surface
AJAX Handlers 9
WordPress Hooks 67
Maintenance & Trust
Advanced Shipping Rates for WooCommerce: Flexible Table Rate Shipping Rules Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Shipping Rates for WooCommerce: Flexible Table Rate Shipping Rules Alternatives
Codiepress Advanced Rule Based Shipping for WooCommerce, Table Rate Shipping Methods, Weight Based Shipping
advanced-rule-based-shipping
Transform your WooCommerce store with Advanced Rule Based Shipping methods! Enjoy flexible options like table rates, weight-based, and flat rates!
Calcurates for WooCommerce
calcurates-for-woocommerce
An ultimate multi-carrier shipping plugin for e-commerce that helps manage and display the right shipping methods and rates at checkout
PiWeb Flat rate / Conditional shipping for WooCommerce
advanced-free-flat-shipping-woocommerce
WooCommerce conditional shipping & WooCommerce Advanced Flat rate shipping rates plugin to Create Advanced Flat rate shipping or Free shipping met …
Weight Based Shipping Table Rate for WooCommerce – Flexible Shipping
flexible-shipping
Weight based shipping methods for WooCommerce. Flexible shipping with table rate rules by cart weight and order value. Accurate rates at checkout.
Weight Based Shipping for WooCommerce
weight-based-shipping-for-woocommerce
Weight Based Shipping is a flexible and widely-used solution to calculate shipping costs based on the total cart weight and value.
Advanced Shipping Rates for WooCommerce: Flexible Table Rate Shipping Rules Developer Profile
5 plugins · 3K total installs
How We Detect Advanced Shipping Rates for WooCommerce: Flexible Table Rate Shipping Rules
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fish-and-ships/assets/css/admin.css/wp-content/plugins/fish-and-ships/assets/css/frontend.css/wp-content/plugins/fish-and-ships/assets/js/admin.js/wp-content/plugins/fish-and-ships/assets/js/frontend.js/wp-content/plugins/fish-and-ships/assets/js/admin.js/wp-content/plugins/fish-and-ships/assets/js/frontend.jsfish-and-ships/assets/css/admin.css?ver=fish-and-ships/assets/css/frontend.css?ver=fish-and-ships/assets/js/admin.js?ver=fish-and-ships/assets/js/frontend.js?ver=HTML / DOM Fingerprints
wc_fns_help_tooltip<!-- This is a comment from Fish and Ships -->data-fns-helpwc_fns_ajax_object/wp-json/wc_fns/v1/help/wp-json/wc_fns/v1/logs/wp-json/wc_fns/v1/fields/wp-json/wc_fns/v1/messages/wp-json/wc_fns/v1/freemium