IH Shipping for Australia Post Security & Risk Analysis

wordpress.org/plugins/ih-shipping-for-auspost

A shipping integration that adds real-time Australia Post calculations (Parcel Post) with volumetric box packing.

0 active installs v2.0.18 PHP 7.2+ WP 5.0+ Updated Jan 27, 2026
auspostaustralia-postparcel-postshippingshipping-calculator
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is IH Shipping for Australia Post Safe to Use in 2026?

Generally Safe

Score 100/100

IH Shipping for Australia Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "ih-shipping-for-auspost" plugin, in version 2.0.18, exhibits a remarkably clean static analysis profile. There are no identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that are exposed. Furthermore, the code signals indicate a lack of dangerous functions, no raw SQL queries (all are prepared), no file operations, and no external HTTP requests. This suggests a very limited attack surface and a well-contained codebase from a static analysis perspective.

However, there are some areas that warrant attention. The taint analysis shows zero flows, which is positive, but the fact that only 50% of output is properly escaped is a concern. While the static analysis did not directly identify an exploit, improperly escaped output can lead to Cross-Site Scripting (XSS) vulnerabilities, especially if user-supplied data is involved in the displayed output. The complete absence of nonce checks and capability checks is also notable. While there are no explicit entry points identified, if any functionality were to be added or discovered later, the lack of these fundamental security checks would present a significant risk.

The plugin's vulnerability history is spotless, with zero known CVEs. This is a strong indicator of a well-maintained and secure plugin over time. The absence of any recorded vulnerabilities suggests a proactive approach to security by the developers. Despite the lack of explicit entry points, the partial output escaping and the absence of nonce/capability checks are the primary weaknesses. The overall security posture is good due to the lack of known vulnerabilities and a small attack surface, but these specific areas represent potential risks that should be addressed.

Key Concerns

  • Output escaping is only 50% proper
  • No nonce checks present
  • No capability checks present
Vulnerabilities
None known

IH Shipping for Australia Post Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

IH Shipping for Australia Post Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped2 total outputs
Attack Surface

IH Shipping for Australia Post Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionbefore_woocommerce_initih-shipping-for-auspost.php:22
actionadmin_noticesih-shipping-for-auspost.php:33
actionplugins_loadedih-shipping-for-auspost.php:37
actionwoocommerce_shipping_initih-shipping-for-auspost.php:99
filterwoocommerce_shipping_methodsih-shipping-for-auspost.php:105
Maintenance & Trust

IH Shipping for Australia Post Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 27, 2026
PHP min version7.2
Downloads92

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

IH Shipping for Australia Post Developer Profile

ihwebsolutions

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect IH Shipping for Australia Post

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ih-shipping-for-auspost/ih-shipping-for-auspost.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about IH Shipping for Australia Post