Fraktjakt WooCommerce Shipping Security & Risk Analysis

wordpress.org/plugins/fraktjakt-shipping-for-woocommerce

Fraktjakt's all-in-one shipping method plugin for WooCommerce.

300 active installs v2.6.0 PHP + WP 6.5.0+ Updated Nov 1, 2024
fraktetiketterfraktkopplingorderkopplingshippingwoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Fraktjakt WooCommerce Shipping Safe to Use in 2026?

Generally Safe

Score 92/100

Fraktjakt WooCommerce Shipping has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "fraktjakt-shipping-for-woocommerce" plugin version 2.6.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and has no known historical vulnerabilities. However, significant concerns are raised by the static analysis. The plugin has a single AJAX entry point that lacks any authentication or capability checks, creating a direct path for unauthorized actions if exploited. Furthermore, a substantial portion (80%) of its output is not properly escaped, potentially leading to cross-site scripting (XSS) vulnerabilities. The taint analysis, while indicating no critical or high severity issues in the analyzed flows, did reveal unsanitized paths, which, combined with the unescaped output and unprotected AJAX handler, could be a vector for attacks.

Key Concerns

  • AJAX handler without authentication
  • Significant unescaped output (80%)
  • Taint flows with unsanitized paths
Vulnerabilities
None known

Fraktjakt WooCommerce Shipping Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Fraktjakt WooCommerce Shipping Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
5
Bundled Libraries
0

Output Escaping

20% escaped25 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
fraktjakt_shipping_method_init (fraktjakt-woocommerce-shipping.php:33)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Fraktjakt WooCommerce Shipping Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_fraktjakt_create_order_connectionfraktjakt-woocommerce-shipping.php:1372
WordPress Hooks 15
actionbefore_woocommerce_initfraktjakt-woocommerce-shipping.php:22
actionadmin_noticesfraktjakt-woocommerce-shipping.php:118
actionwp_enqueue_scriptsfraktjakt-woocommerce-shipping.php:760
actionadmin_enqueue_scriptsfraktjakt-woocommerce-shipping.php:761
actionwoocommerce_shipping_initfraktjakt-woocommerce-shipping.php:768
filterwoocommerce_shipping_methodsfraktjakt-woocommerce-shipping.php:774
filterwoocommerce_cart_shipping_method_full_labelfraktjakt-woocommerce-shipping.php:787
actionwoocommerce_order_status_processingfraktjakt-woocommerce-shipping.php:1177
actionwoocommerce_order_status_completedfraktjakt-woocommerce-shipping.php:1178
actionwoocommerce_order_status_processingfraktjakt-woocommerce-shipping.php:1180
actionadd_meta_boxesfraktjakt-woocommerce-shipping.php:1188
filterwoocommerce_admin_order_actionsfraktjakt-woocommerce-shipping.php:1293
filterwoocommerce_email_order_metafraktjakt-woocommerce-shipping.php:1691
actionwoocommerce_review_order_after_shippingfraktjakt-woocommerce-shipping.php:1735
filterwoocommerce_checkout_get_valuefraktjakt-woocommerce-shipping.php:1785
Maintenance & Trust

Fraktjakt WooCommerce Shipping Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedNov 1, 2024
PHP min version
Downloads20K

Community Trust

Rating100/100
Number of ratings4
Active installs300
Developer Profile

Fraktjakt WooCommerce Shipping Developer Profile

Fraktjakt

1 plugin · 300 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Fraktjakt WooCommerce Shipping

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fraktjakt-shipping-for-woocommerce/assets/css/style.css/wp-content/plugins/fraktjakt-shipping-for-woocommerce/assets/js/script.js
Script Paths
/wp-content/plugins/fraktjakt-shipping-for-woocommerce/assets/js/script.js
Version Parameters
fraktjakt-shipping-for-woocommerce/assets/css/style.css?ver=fraktjakt-shipping-for-woocommerce/assets/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
fraktjakt-shipping-method
HTML Comments
/** ---------------------------------------------------Constructor for the Fraktjakt Shipping Method class* @access public* @return void+6 more
Data Attributes
data-fraktjakt-shipping-method
JS Globals
fraktjakt_settings
FAQ

Frequently Asked Questions about Fraktjakt WooCommerce Shipping