
IH Shipping for Australia Post Security & Risk Analysis
wordpress.org/plugins/ih-shipping-for-auspostA shipping integration that adds real-time Australia Post calculations (Parcel Post) with volumetric box packing.
Is IH Shipping for Australia Post Safe to Use in 2026?
Generally Safe
Score 100/100IH Shipping for Australia Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ih-shipping-for-auspost" plugin, in version 2.0.18, exhibits a remarkably clean static analysis profile. There are no identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that are exposed. Furthermore, the code signals indicate a lack of dangerous functions, no raw SQL queries (all are prepared), no file operations, and no external HTTP requests. This suggests a very limited attack surface and a well-contained codebase from a static analysis perspective.
However, there are some areas that warrant attention. The taint analysis shows zero flows, which is positive, but the fact that only 50% of output is properly escaped is a concern. While the static analysis did not directly identify an exploit, improperly escaped output can lead to Cross-Site Scripting (XSS) vulnerabilities, especially if user-supplied data is involved in the displayed output. The complete absence of nonce checks and capability checks is also notable. While there are no explicit entry points identified, if any functionality were to be added or discovered later, the lack of these fundamental security checks would present a significant risk.
The plugin's vulnerability history is spotless, with zero known CVEs. This is a strong indicator of a well-maintained and secure plugin over time. The absence of any recorded vulnerabilities suggests a proactive approach to security by the developers. Despite the lack of explicit entry points, the partial output escaping and the absence of nonce/capability checks are the primary weaknesses. The overall security posture is good due to the lack of known vulnerabilities and a small attack surface, but these specific areas represent potential risks that should be addressed.
Key Concerns
- Output escaping is only 50% proper
- No nonce checks present
- No capability checks present
IH Shipping for Australia Post Security Vulnerabilities
IH Shipping for Australia Post Code Analysis
Output Escaping
IH Shipping for Australia Post Attack Surface
WordPress Hooks 5
Maintenance & Trust
IH Shipping for Australia Post Maintenance & Trust
Maintenance Signals
Community Trust
IH Shipping for Australia Post Alternatives
Cost Calculator Builder
cost-calculator-builder
WP Cost Calculator is a simple and powerful tool that lets you create price estimation forms. Easily give your clients information about your services …
Australia Post WooCommerce Extension
australian-post-woocommerce-extension
Australia Post WooCommerce Extension integrates Australia Post with WooCommerce, calculating shipping costs and delivery times for customers.
Easyship WooCommerce Shipping Rates
easyship-woocommerce-shipping-rates
Easyship for WooCommerce saves you time and money with live courier rates, seamless checkout, automated taxes & duties, and shipping label creation.
WooReer
wcsdm
WooReer calculates shipping rates based on distance via Google Maps, Mapbox, DistanceMatrix.ai, Geoapify, or HERE.
Product page shipping calculator for WooCommerce
product-page-shipping-calculator-for-woocommerce
This plugin allows you to show the shipping methods available on the product page for WooCommerce, so customers can see if shipping is available to th …
IH Shipping for Australia Post Developer Profile
1 plugin · 0 total installs
How We Detect IH Shipping for Australia Post
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ih-shipping-for-auspost/ih-shipping-for-auspost.php