
InXpress-Shipping-Extension Security & Risk Analysis
wordpress.org/plugins/inxpress-shipping-extensionAdds a new shipping method provided by InXpress.
Is InXpress-Shipping-Extension Safe to Use in 2026?
Generally Safe
Score 92/100InXpress-Shipping-Extension has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of inxpress-shipping-extension v3.5.3 reveals a generally strong security posture. The plugin demonstrates excellent adherence to secure coding practices, with 100% of SQL queries using prepared statements and all identified output being properly escaped. The absence of dangerous functions, file operations, and taint flows with unsanitized paths further contributes to its good standing. The plugin also appears to have a minimal attack surface, with no identifiable AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks.
However, the analysis does highlight a couple of potential areas for concern. The presence of one external HTTP request without explicit mention of verification or sanitization of the returned data could potentially lead to issues if the external resource is compromised or returns malicious content. Furthermore, the complete absence of nonce checks, while potentially acceptable given the reported lack of unprotected entry points, is an unusual oversight for WordPress plugins. It suggests a reliance on other layers of security or an assumption that all entry points are inherently protected, which might not hold true in all future scenarios or when interacting with other plugins.
The vulnerability history is exceptionally clean, with zero recorded CVEs. This indicates a well-maintained and secure plugin over its lifecycle, or at least a lack of publicly discovered vulnerabilities. The combination of strong coding practices and a clean history suggests that inxpress-shipping-extension is likely a secure choice. The primary weakness lies in the potential for the external HTTP request and the complete absence of nonce checks, although the immediate impact of these is mitigated by the current lack of identified vulnerabilities and protected entry points.
Key Concerns
- External HTTP request without explicit validation
- Zero nonce checks implemented
InXpress-Shipping-Extension Security Vulnerabilities
InXpress-Shipping-Extension Release Timeline
InXpress-Shipping-Extension Code Analysis
Output Escaping
InXpress-Shipping-Extension Attack Surface
WordPress Hooks 4
Maintenance & Trust
InXpress-Shipping-Extension Maintenance & Trust
Maintenance Signals
Community Trust
InXpress-Shipping-Extension Alternatives
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Limit Login Attempts Reloaded – Login Security, 2FA, Brute Force Protection & Firewall
limit-login-attempts-reloaded
Stop password guessing attacks, secure WooCommerce, block bad IPs, block by countries (Pro), and add email 2FA. Lightweight with better performance.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
WooPayments: Integrated WooCommerce Payments
woocommerce-payments
Securely accept credit and debit cards on your WooCommerce store. Manage payments without leaving your WordPress dashboard. Only with WooPayments.
WooCommerce PayPal Payments
woocommerce-paypal-payments
PayPal's latest payment processing solution. Accept PayPal, Pay Later, credit/debit cards, alternative digital wallets and bank accounts.
InXpress-Shipping-Extension Developer Profile
1 plugin · 90 total installs
How We Detect InXpress-Shipping-Extension
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/inxpress-shipping-extension/assets/js/inxpress-shipping-extension.js/wp-content/plugins/inxpress-shipping-extension/assets/css/inxpress-shipping-extension.css/wp-content/plugins/inxpress-shipping-extension/assets/js/inxpress-shipping-extension.jsinxpress-shipping-extension/assets/js/inxpress-shipping-extension.js?ver=inxpress-shipping-extension/assets/css/inxpress-shipping-extension.css?ver=HTML / DOM Fingerprints
inxpress_shipping_field<!-- Begin WooCommerce InXpress Method --><!-- End WooCommerce InXpress Method --><!-- Base class for all InXpress Shipping methods regardless of carrier --><!-- Main WC_Inxpress_Method Instance. -->+9 moredata-inxpress-handling-typedata-inxpress-handling-applieddata-inxpress-handling-feeinxpress_shipping_settings