Lite Shipping Counter & Notice Security & Risk Analysis

wordpress.org/plugins/lite-shipping-counter-notice

Lightweight notice for WooCommerce that shows how much is left to unlock free shipping.

0 active installs v1.0.2 PHP 7.4+ WP 6.0+ Updated Feb 17, 2026
cartcheckoutfree-shippingnotification-barwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Lite Shipping Counter & Notice Safe to Use in 2026?

Generally Safe

Score 100/100

Lite Shipping Counter & Notice has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "lite-shipping-counter-notice" v1.0.2 plugin exhibits a generally positive security posture, demonstrating good practices in several key areas. The absence of known CVEs and recorded vulnerabilities is a significant strength, suggesting a well-maintained or less actively targeted codebase. Furthermore, the plugin utilizes prepared statements for all SQL queries and boasts a high percentage of properly escaped output, mitigating common risks like SQL injection and cross-site scripting (XSS).

However, the static analysis does reveal a notable concern: one of the three REST API routes lacks proper permission callbacks. This creates an unprotected entry point that could potentially be exploited by unauthenticated users, leading to unauthorized actions or information disclosure. While taint analysis shows no critical or high-severity vulnerabilities, this unprotected REST API endpoint is a specific risk that needs to be addressed. The absence of nonce checks on AJAX handlers, although not explicitly flagged as a vulnerability by taint analysis in this version, is another area that could be strengthened to further enhance security.

Key Concerns

  • Unprotected REST API route
  • No nonce checks on AJAX handlers
Vulnerabilities
None known

Lite Shipping Counter & Notice Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Lite Shipping Counter & Notice Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
16 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped17 total outputs
Attack Surface
1 unprotected

Lite Shipping Counter & Notice Attack Surface

Entry Points3
Unprotected1

REST API Routes 3

GET/wp-json/lscn/v1/settingsincludes\class-settings.php:355
GET/wp-json/lscn/v1/languagesincludes\class-settings.php:373
GET/wp-json/lscn/v1/settings/allincludes\class-settings.php:384
WordPress Hooks 17
actionwp_enqueue_scriptsincludes\class-blocks-integration.php:257
actionwp_enqueue_scriptsincludes\class-blocks-integration.php:290
actionwpincludes\class-notice.php:37
filterwoocommerce_update_order_review_fragmentsincludes\class-notice.php:40
actionwoocommerce_proceed_to_checkoutincludes\class-notice.php:57
actionwoocommerce_review_order_before_submitincludes\class-notice.php:63
actionadmin_menuincludes\class-settings.php:166
actionadmin_initincludes\class-settings.php:167
actionadmin_enqueue_scriptsincludes\class-settings.php:168
actionadmin_noticeslite-shipping-counter-notice.php:127
actionadmin_initlite-shipping-counter-notice.php:129
actionbefore_woocommerce_initlite-shipping-counter-notice.php:144
actionwoocommerce_blocks_checkout_block_registrationlite-shipping-counter-notice.php:163
actionwoocommerce_blocks_loadedlite-shipping-counter-notice.php:179
actionadmin_initlite-shipping-counter-notice.php:189
actionrest_api_initlite-shipping-counter-notice.php:193
actionplugins_loadedlite-shipping-counter-notice.php:207
Maintenance & Trust

Lite Shipping Counter & Notice Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 17, 2026
PHP min version7.4
Downloads130

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Lite Shipping Counter & Notice Developer Profile

Luis Ruiz

5 plugins · 260 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Lite Shipping Counter & Notice

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lite-shipping-counter-notice/assets/css/frontend.css/wp-content/plugins/lite-shipping-counter-notice/assets/js/frontend.js/wp-content/plugins/lite-shipping-counter-notice/assets/css/admin.css/wp-content/plugins/lite-shipping-counter-notice/assets/js/admin.js
Script Paths
/wp-content/plugins/lite-shipping-counter-notice/assets/js/frontend.js/wp-content/plugins/lite-shipping-counter-notice/assets/js/admin.js
Version Parameters
lite-shipping-counter-notice/assets/css/frontend.css?ver=lite-shipping-counter-notice/assets/js/frontend.js?ver=lite-shipping-counter-notice/assets/css/admin.css?ver=lite-shipping-counter-notice/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
lscn-shipping-noticelscn-shipping-notice-messagelscn-shipping-notice-progress
Data Attributes
data-lscn-enableddata-lscn-free-shipping-threshold
JS Globals
lscn_frontend_paramslscn_admin_params
REST Endpoints
/wp-json/lite-shipping-counter-notice/v1/settings
FAQ

Frequently Asked Questions about Lite Shipping Counter & Notice