Live Rates for ShipStation Security & Risk Analysis

wordpress.org/plugins/live-rates-for-shipstation

Pulls live shipping rates from your favorite carriers connected to 3rd party provider ShipStation.

200 active installs v1.2.5 PHP + WP 6.2+ Updated Mar 12, 2026
fedexshipstationupsuspswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Live Rates for ShipStation Safe to Use in 2026?

Generally Safe

Score 100/100

Live Rates for ShipStation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 22d ago
Risk Assessment

The 'live-rates-for-shipstation' plugin version 1.2.5 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified attack surface entry points that lack authentication or proper permission checks, such as unprotected AJAX handlers, REST API routes, or shortcodes, is a significant positive. Furthermore, the code demonstrates good development practices with all SQL queries utilizing prepared statements and a very high percentage of output being properly escaped. The presence of nonce and capability checks, although limited, indicates an awareness of security principles. The lack of any recorded vulnerabilities or CVEs in its history further reinforces a perception of a secure plugin.

However, the static analysis does reveal areas that, while not immediately critical given the other findings, warrant consideration. The presence of three file operations, without further context, could potentially be an area for scrutiny if not implemented with absolute care regarding file permissions and input sanitization. While taint analysis found no critical or high-severity issues, the absence of any taint flows analyzed at all means that this aspect of the security evaluation might be incomplete or that the analysis tool was unable to identify potential paths for malicious input. The plugin also does not bundle any external libraries, which simplifies the security landscape by removing the risk of outdated or vulnerable dependencies, but also means the plugin is entirely responsible for its own security implementations.

In conclusion, 'live-rates-for-shipstation' v1.2.5 appears to be a secure plugin with robust defenses against common web vulnerabilities. Its clean vulnerability history and strong adherence to secure coding practices in SQL and output handling are commendable. The primary areas for potential concern are the file operations, which require careful implementation, and the limited scope of the taint analysis, which might not capture all potential risks. Overall, the plugin is in a good security state, but vigilance regarding any future updates or expansions of its functionality is always advised.

Key Concerns

  • File operations present without full context
  • Taint analysis incomplete or no flows identified
Vulnerabilities
None known

Live Rates for ShipStation Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Live Rates for ShipStation Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
1
75 escaped
Nonce Checks
2
Capability Checks
1
File Operations
3
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

99% escaped76 total outputs
Attack Surface

Live Rates for ShipStation Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
actionadd_meta_boxescore\admin-edit-order.php:38
actionrest_api_initcore\rest-router.php:38
actionadmin_enqueue_scriptscore\settings-shipstation.php:39
actionadmin_initcore\settings-shipstation.php:40
actionadmin_footercore\settings-shipstation.php:41
actionadmin_enqueue_scriptscore\settings-shipstation.php:42
actionwoocommerce_cart_totals_after_order_totalcore\settings-shipstation.php:43
actionwoocommerce_update_optioncore\settings-shipstation.php:44
actionwoocommerce_update_options_generalcore\settings-shipstation.php:45
filterwoocommerce_shipping_methodscore\settings-shipstation.php:304
filterwoocommerce_settings_api_form_fields_shipstationcore\settings-shipstation.php:305
filterwoocommerce_settings_api_sanitized_fields_shipstationcore\settings-shipstation.php:306
filterwoocommerce_shipstation_export_get_ordercore\settings-shipstation.php:307
filterplugin_action_links_live-rates-for-shipstation/live-rates-for-shipstation.phpcore\settings-shipstation.php:309
actionadmin_footercore\shipping-method-shipstation.php:118
filterhttp_request_timeoutcore\shipping-method-shipstation.php:169
filterwoocommerce_order_item_display_meta_keycore\shipping-method-shipstation.php:170
filterwoocommerce_order_item_display_meta_valuecore\shipping-method-shipstation.php:171
filterwoocommerce_hidden_order_itemmetacore\shipping-method-shipstation.php:172
actionplugins_loadedlive-rates-for-shipstation.php:242
Maintenance & Trust

Live Rates for ShipStation Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 12, 2026
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings5
Active installs200
Developer Profile

Live Rates for ShipStation Developer Profile

IQComputing

2 plugins · 200K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Live Rates for ShipStation

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/live-rates-for-shipstation/core/assets/css/admin.css/wp-content/plugins/live-rates-for-shipstation/core/assets/js/admin.js
Script Paths
/wp-content/plugins/live-rates-for-shipstation/core/assets/js/admin.js
Version Parameters
live-rates-for-shipstation/core/assets/css/admin.css?ver=live-rates-for-shipstation/core/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
iqlrss-admin-notice
JS Globals
iqlrss_admin_data
REST Endpoints
/wp-json/iqlrss/v1/api-verification/wp-json/iqlrss/v1/api-verification/
FAQ

Frequently Asked Questions about Live Rates for ShipStation