
iCARRY Security & Risk Analysis
wordpress.org/plugins/icarryAdds new iCARRY shipping options.
Is iCARRY Safe to Use in 2026?
Generally Safe
Score 100/100iCARRY has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "icarry" v2.7 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its SQL queries and properly escaping a high percentage of its output. The absence of known vulnerabilities (CVEs) and recorded common vulnerability types suggests a history of responsible development or effective patching. The taint analysis also shows no critical or high severity unsanitized paths, which is a significant positive indicator.
However, there are several notable security concerns. The plugin exposes four AJAX handlers without any authentication or capability checks. This represents a substantial attack surface that could allow unauthenticated users to trigger potentially sensitive actions within the plugin. While file operations, external HTTP requests, and nonce checks are present, their effectiveness is undermined by the lack of access control on the AJAX endpoints. The plugin also lacks capability checks entirely, further contributing to the risk associated with its unprotected entry points.
In conclusion, while "icarry" v2.7 benefits from secure data handling in SQL and output escaping, the unprotected AJAX endpoints are a critical weakness. The absence of known vulnerabilities is a positive sign, but it does not mitigate the inherent risk posed by unauthenticated entry points. Developers should prioritize implementing proper authentication and authorization checks on all AJAX handlers to address these significant security concerns.
Key Concerns
- Unprotected AJAX handlers
- No capability checks
iCARRY Security Vulnerabilities
iCARRY Code Analysis
Output Escaping
iCARRY Attack Surface
AJAX Handlers 4
WordPress Hooks 9
Maintenance & Trust
iCARRY Maintenance & Trust
Maintenance Signals
Community Trust
iCARRY Alternatives
Custom Shipping Methods for WooCommerce – Create Weight based Shipping, Conditional Shipping, Table Rate Shipping and much more
custom-shipping-methods-for-woocommerce
Configure advanced shipping options for your WooCommerce store with custom shipping methods. Be it weight based shipping or volume based shipping or q …
Shipping Rate By Cities
shipping-rate-by-cities
Set Custom Shipping Rates For Different Cities On Woocommerce.
Shipping by City for Woocommerce
shipping-by-city-for-woocommerce
Shipping by city WooCommerce Add-on plug-in.
Ade Custom Shipping
ade-custom-shipping
Integrate Ade Custom Shipping to your WooCommerce website and take control of your shipping options.
Freight Shipping Quote – Simplify Shipping Cost Requests
freight-shipping-quote
Freight Shipping Quote allow your customer to request a custom shipping quote before checkout for freight shipping.
iCARRY Developer Profile
1 plugin · 300 total installs
How We Detect iCARRY
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/icarry-shipping-for-woocommerce/assets/js/js.min.js/wp-content/plugins/icarry-shipping-for-woocommerce/assets/js/checkout.js/wp-content/plugins/icarry-shipping-for-woocommerce/assets/css/styles.cssassets/js/js.min.jsassets/js/checkout.jsicarry-shipping-for-woocommerceHTML / DOM Fingerprints
icarry_ajax_objectICarryShippingForWooCommerceVariables/wp-json/icarry-shipping-for-woocommerce