InXpress-Shipping-Extension Security & Risk Analysis

wordpress.org/plugins/inxpress-shipping-extension

Adds a new shipping method provided by InXpress.

90 active installs v3.5.3 PHP + WP + Updated Apr 10, 2025
woocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is InXpress-Shipping-Extension Safe to Use in 2026?

Generally Safe

Score 92/100

InXpress-Shipping-Extension has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The static analysis of inxpress-shipping-extension v3.5.3 reveals a generally strong security posture. The plugin demonstrates excellent adherence to secure coding practices, with 100% of SQL queries using prepared statements and all identified output being properly escaped. The absence of dangerous functions, file operations, and taint flows with unsanitized paths further contributes to its good standing. The plugin also appears to have a minimal attack surface, with no identifiable AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks.

However, the analysis does highlight a couple of potential areas for concern. The presence of one external HTTP request without explicit mention of verification or sanitization of the returned data could potentially lead to issues if the external resource is compromised or returns malicious content. Furthermore, the complete absence of nonce checks, while potentially acceptable given the reported lack of unprotected entry points, is an unusual oversight for WordPress plugins. It suggests a reliance on other layers of security or an assumption that all entry points are inherently protected, which might not hold true in all future scenarios or when interacting with other plugins.

The vulnerability history is exceptionally clean, with zero recorded CVEs. This indicates a well-maintained and secure plugin over its lifecycle, or at least a lack of publicly discovered vulnerabilities. The combination of strong coding practices and a clean history suggests that inxpress-shipping-extension is likely a secure choice. The primary weakness lies in the potential for the external HTTP request and the complete absence of nonce checks, although the immediate impact of these is mitigated by the current lack of identified vulnerabilities and protected entry points.

Key Concerns

  • External HTTP request without explicit validation
  • Zero nonce checks implemented
Vulnerabilities
None known

InXpress-Shipping-Extension Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

InXpress-Shipping-Extension Release Timeline

v3.5.3Current
v3.5.2
Code Analysis
Analyzed Mar 16, 2026

InXpress-Shipping-Extension Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
7 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped7 total outputs
Attack Surface

InXpress-Shipping-Extension Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterallowed_redirect_hostsincludes\wc-inxpress-action-functions.php:48
actionadmin_menuincludes\wc-inxpress-action-functions.php:115
actionwoocommerce_shipping_initincludes\wc-inxpress-action-functions.php:136
filterwoocommerce_shipping_methodsincludes\wc-inxpress-action-functions.php:159
Maintenance & Trust

InXpress-Shipping-Extension Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 10, 2025
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs90
Developer Profile

InXpress-Shipping-Extension Developer Profile

inxpressdevelopers

1 plugin · 90 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect InXpress-Shipping-Extension

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/inxpress-shipping-extension/assets/js/inxpress-shipping-extension.js/wp-content/plugins/inxpress-shipping-extension/assets/css/inxpress-shipping-extension.css
Script Paths
/wp-content/plugins/inxpress-shipping-extension/assets/js/inxpress-shipping-extension.js
Version Parameters
inxpress-shipping-extension/assets/js/inxpress-shipping-extension.js?ver=inxpress-shipping-extension/assets/css/inxpress-shipping-extension.css?ver=

HTML / DOM Fingerprints

CSS Classes
inxpress_shipping_field
HTML Comments
<!-- Begin WooCommerce InXpress Method --><!-- End WooCommerce InXpress Method --><!-- Base class for all InXpress Shipping methods regardless of carrier --><!-- Main WC_Inxpress_Method Instance. -->+9 more
Data Attributes
data-inxpress-handling-typedata-inxpress-handling-applieddata-inxpress-handling-fee
JS Globals
inxpress_shipping_settings
FAQ

Frequently Asked Questions about InXpress-Shipping-Extension