Shipping by Machool Security & Risk Analysis

wordpress.org/plugins/machool-for-woocommerce

Connects WooCommerce to Machool to provide realtime shipping rates.

100 active installs v2.0.4 PHP 7.0+ WP 5.2+ Updated Feb 15, 2024
carte-commerceshopstorewoo
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Shipping by Machool Safe to Use in 2026?

Generally Safe

Score 85/100

Shipping by Machool has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The static analysis of machool-for-woocommerce v2.0.4 reveals a generally strong security posture, with no identified vulnerabilities from taint analysis or a history of known CVEs. The absence of a significant attack surface, including AJAX handlers, REST API routes, shortcodes, and cron events without proper authentication or authorization checks, is a positive indicator. The plugin also avoids dangerous functions and file operations. However, there are notable areas for improvement. The use of raw SQL queries without prepared statements for all queries poses a potential risk for SQL injection vulnerabilities. Additionally, the incomplete output escaping means that some data displayed to users might not be properly sanitized, leaving it open to cross-site scripting (XSS) attacks. The presence of external HTTP requests without clear context of their security implications warrants attention. While the plugin has no recorded vulnerabilities, the identified code signals suggest that diligent security practices are not universally applied.

Key Concerns

  • SQL queries not using prepared statements
  • Incomplete output escaping
  • External HTTP requests without context
Vulnerabilities
None known

Shipping by Machool Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Shipping by Machool Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
1
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

50% escaped2 total outputs
Attack Surface

Shipping by Machool Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_menuinc\Api\SettingsApi.php:16
filterplugin_action_linksinc\Base\SettingsLinks.php:13
actionadmin_noticesmachool_woocommerce.php:102
actionwoocommerce_shipping_initmachool_woocommerce.php:518
filterwoocommerce_shipping_methodsmachool_woocommerce.php:526
Maintenance & Trust

Shipping by Machool Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedFeb 15, 2024
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Shipping by Machool Developer Profile

Machool

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Shipping by Machool

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/machool-for-woocommerce/includes/machool-shipping.css/wp-content/plugins/machool-for-woocommerce/includes/machool-shipping.js
Script Paths
/wp-content/plugins/machool-for-woocommerce/includes/machool-shipping.js
Version Parameters
machool-for-woocommerce/includes/machool-shipping.css?ver=machool-for-woocommerce/includes/machool-shipping.js?ver=

HTML / DOM Fingerprints

CSS Classes
machool-shipping-method
Data Attributes
data-machool-api-keydata-machool-store-domain
JS Globals
MachoolShipping
FAQ

Frequently Asked Questions about Shipping by Machool