
MailPlus Shipmate Security & Risk Analysis
wordpress.org/plugins/mailplus-shipmateAs an Australian shipping service, MailPlus Shipmate integrates MailPlus delivery options with WooCommerce, providing real-time shipping rates.
Is MailPlus Shipmate Safe to Use in 2026?
Generally Safe
Score 100/100MailPlus Shipmate has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mailplus-shipmate plugin version 0.2.3 exhibits a concerning security posture primarily due to a significant number of unprotected entry points into the application. All five identified REST API routes lack permission callbacks, meaning any user, regardless of their role or logged-in status, can potentially interact with these endpoints. This large, exposed attack surface is a major security risk.
Despite the lack of critical findings in taint analysis and the absence of recorded vulnerabilities in its history, the unprotected REST API routes present a significant risk. While the plugin uses prepared statements for SQL queries and a high percentage of output is properly escaped, these good practices are undermined by the lack of authorization checks on its API endpoints. The presence of external HTTP requests without explicit analysis of their security implications is also a minor concern. In conclusion, the plugin has some good security foundations with its SQL and output handling, but the critical flaw of unprotected API routes makes it a high-risk component.
The plugin's vulnerability history is clean, which is a positive sign of development quality or a lack of past scrutiny. However, this should not breed complacency. The current static analysis reveals a clear and present danger in the form of unauthenticated access to its REST API. This needs to be addressed immediately to mitigate potential exploitation.
Key Concerns
- REST API routes without permission callbacks
- Large attack surface without authorization
- External HTTP requests without explicit security review
MailPlus Shipmate Security Vulnerabilities
MailPlus Shipmate Code Analysis
Output Escaping
MailPlus Shipmate Attack Surface
REST API Routes 5
WordPress Hooks 11
Maintenance & Trust
MailPlus Shipmate Maintenance & Trust
Maintenance Signals
Community Trust
MailPlus Shipmate Alternatives
Shiprocket
shiprocket
Auto Sync your Woocommerce store orders & ship them at lowest shipping rates. Automate your shipping, save time & money.
Table rate shipping for WooCommerce
advanced-table-rate-shipping-for-woocommerce
Table rate shipping a addon plugin for WooCommerce shipping.
PrangoShip [Quantity Based] for WooCommerce
woo-quantity-based-shipping-rate
Lets you assign shipping rates based on the quantity of items in the cart for your WooCommerce Store.
Bijak
bijak
Add smart freight shipping to WooCommerce with live rate estimates and order integration via the Bijak API.
CODPartner
codpartner
A Platform that covers all logistics needs for COD e-commerce sellers.
MailPlus Shipmate Developer Profile
1 plugin · 0 total installs
How We Detect MailPlus Shipmate
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mailplus-shipmate/assets/css/tracking.css/wp-content/plugins/mailplus-shipmate/assets/js/tracking.jsmailplus-shipmate/assets/css/tracking.css?ver=mailplus-shipmate/assets/js/tracking.js?ver=HTML / DOM Fingerprints
mp-track-boxmp-track-linkmp-infomp-tooltipmp-modal-togglemp-info-overlaymp-modalmp-closedata-modal-targetmailplus_shipmate_tracking_data/wp-json/mailplus-shipmate/v1/track