
Live Rates for ShipStation Security & Risk Analysis
wordpress.org/plugins/live-rates-for-shipstationPulls live shipping rates from your favorite carriers connected to 3rd party provider ShipStation.
Is Live Rates for ShipStation Safe to Use in 2026?
Generally Safe
Score 100/100Live Rates for ShipStation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'live-rates-for-shipstation' plugin version 1.2.5 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified attack surface entry points that lack authentication or proper permission checks, such as unprotected AJAX handlers, REST API routes, or shortcodes, is a significant positive. Furthermore, the code demonstrates good development practices with all SQL queries utilizing prepared statements and a very high percentage of output being properly escaped. The presence of nonce and capability checks, although limited, indicates an awareness of security principles. The lack of any recorded vulnerabilities or CVEs in its history further reinforces a perception of a secure plugin.
However, the static analysis does reveal areas that, while not immediately critical given the other findings, warrant consideration. The presence of three file operations, without further context, could potentially be an area for scrutiny if not implemented with absolute care regarding file permissions and input sanitization. While taint analysis found no critical or high-severity issues, the absence of any taint flows analyzed at all means that this aspect of the security evaluation might be incomplete or that the analysis tool was unable to identify potential paths for malicious input. The plugin also does not bundle any external libraries, which simplifies the security landscape by removing the risk of outdated or vulnerable dependencies, but also means the plugin is entirely responsible for its own security implementations.
In conclusion, 'live-rates-for-shipstation' v1.2.5 appears to be a secure plugin with robust defenses against common web vulnerabilities. Its clean vulnerability history and strong adherence to secure coding practices in SQL and output handling are commendable. The primary areas for potential concern are the file operations, which require careful implementation, and the limited scope of the taint analysis, which might not capture all potential risks. Overall, the plugin is in a good security state, but vigilance regarding any future updates or expansions of its functionality is always advised.
Key Concerns
- File operations present without full context
- Taint analysis incomplete or no flows identified
Live Rates for ShipStation Security Vulnerabilities
Live Rates for ShipStation Code Analysis
SQL Query Safety
Output Escaping
Live Rates for ShipStation Attack Surface
WordPress Hooks 20
Maintenance & Trust
Live Rates for ShipStation Maintenance & Trust
Maintenance Signals
Community Trust
Live Rates for ShipStation Alternatives
BLAZING Shipment Tracking
blazing-woocommerce-shipment-tracking
This plugin adds courier and tracking number to the woocommerce order, and a dedicated email to send shipment tracking info to the customer.
ReachShip WooCommerce Multi-Carrier & Conditional Shipping
elex-reachship-multi-carrier-conditional-shipping
Multi-carrier WooCommerce shipping plugin to get rates, print labels, pickups & track DHL, FedEx, UPS, USPS, Australia Post via ReachShip API.
Descartes ShipRush Integration
descartes-shiprush-integration
Export orders to My.ShipRush.com and update tracking details.
CartFlows – Funnel Builder & Checkout Plugin for WooCommerce
cartflows
1 WordPress funnel builder & WooCommerce checkout plugin. Boost AOV with one-click upsells, order bumps & high-converting checkout pages.
WooCommerce Shipping
woocommerce-shipping
A free shipping plugin for US merchants to print discounted shipping labels and compare live label rates directly from your WooCommerce dashboard.
Live Rates for ShipStation Developer Profile
2 plugins · 200K total installs
How We Detect Live Rates for ShipStation
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/live-rates-for-shipstation/core/assets/css/admin.css/wp-content/plugins/live-rates-for-shipstation/core/assets/js/admin.js/wp-content/plugins/live-rates-for-shipstation/core/assets/js/admin.jslive-rates-for-shipstation/core/assets/css/admin.css?ver=live-rates-for-shipstation/core/assets/js/admin.js?ver=HTML / DOM Fingerprints
iqlrss-admin-noticeiqlrss_admin_data/wp-json/iqlrss/v1/api-verification/wp-json/iqlrss/v1/api-verification/