
Shipping Live Rates for USPS for WooCommerce Security & Risk Analysis
wordpress.org/plugins/flexible-shipping-uspsOffer USPS shipping methods with real-time rates. Show dynamic prices at WooCommerce cart and checkout based on weight and destination.
Is Shipping Live Rates for USPS for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100Shipping Live Rates for USPS for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The flexible-shipping-usps plugin v3.2.6 presents a mixed security posture. While the attack surface appears minimal with only one AJAX handler and no REST API routes, shortcodes, or cron events, the presence of dangerous functions like `assert`, `proc_open`, and `unserialize` is a significant concern, indicating potential for serious vulnerabilities if not handled with extreme care.
The code analysis reveals that 100% of its SQL queries are not using prepared statements, a critical flaw that opens the door to SQL injection attacks. Furthermore, a concerningly low 23% of output escaping suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities. Although taint analysis did not reveal any immediate critical or high severity flows, the other identified code weaknesses could easily be exploited.
The plugin's vulnerability history, with two previously disclosed medium-severity CVEs (Insertion of Sensitive Information into Log File and CSRF), and a recent one in April 2024, indicates a pattern of past security oversights. The fact that these are currently unpatched is a red flag, even if they are not classified as critical or high. While the lack of unpatched critical vulnerabilities and the relatively small attack surface are positive points, the prevalence of insecure coding practices, particularly raw SQL queries and insufficient output escaping, coupled with a history of vulnerabilities, points to a moderate to high overall risk.
Key Concerns
- Raw SQL queries without prepared statements
- Low percentage of properly escaped output
- Presence of dangerous functions
- History of medium severity CVEs
Shipping Live Rates for USPS for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
USPS Shipping for WooCommerce – Live Rates <= 1.9.4 - Sensitive Information Exposure
USPS Shipping for WooCommerce – Live Rates <= 1.9.2 - Cross-Site Request Forgery
Shipping Live Rates for USPS for WooCommerce Release Timeline
Shipping Live Rates for USPS for WooCommerce Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Shipping Live Rates for USPS for WooCommerce Attack Surface
AJAX Handlers 1
WordPress Hooks 68
Maintenance & Trust
Shipping Live Rates for USPS for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Shipping Live Rates for USPS for WooCommerce Alternatives
USPS Shipping for WooCommerce – Live Rates
advanced-usps-shipping-method
Advanced USPS Shipping Allows you to display the USPS live rates.
USPS Simple Shipping for Woocommerce
woo-usps-simple-shipping
USPS Simple provides real-time USPS domestic rates.
ELEX WooCommerce USPS Shipping Method
elex-usps-shipping-method
The plugin will help you to Automate USPS shipping by displaying LIVE shipping rates on the Cart and Checkout page.
WooCommerce Shipping
woocommerce-shipping
A free shipping plugin for US merchants to print discounted shipping labels and compare live label rates directly from your WooCommerce dashboard.
XPS Ship Integration
xps-ship-integration
The XPS Ship Integration, a free integration for WooCommerce merchants, is the only integration that gives you all the necessary functionality for shi …
Shipping Live Rates for USPS for WooCommerce Developer Profile
11 plugins · 114K total installs
How We Detect Shipping Live Rates for USPS for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/flexible-shipping-usps/vendor_prefixed/octolize/wp-octolize-brand-assets/dist/css/admin.css/wp-content/plugins/flexible-shipping-usps/vendor_prefixed/octolize/wp-onboarding/assets/css/onboarding.css/wp-content/plugins/flexible-shipping-usps/vendor_prefixed/octolize/wp-onboarding/assets/js/onboarding.js/wp-content/plugins/flexible-shipping-usps/vendor_prefixed/wpdesk/wp-plugin-flow-common/src/plugin-init-php52-free.phpflexible-shipping-usps/vendor_prefixed/octolize/wp-octolize-brand-assets/dist/css/admin.css?ver=flexible-shipping-usps/vendor_prefixed/octolize/wp-onboarding/assets/css/onboarding.css?ver=flexible-shipping-usps/vendor_prefixed/octolize/wp-onboarding/assets/js/onboarding.js?ver=HTML / DOM Fingerprints
octolize-onboarding-container<!-- Template for onboarding container -->data-autostartdata-logo-imgdata-pagedata-ajax-urldata-ajax-noncedata-ajax-action-event+5 moreOctolizeOnboarding