
Malca-Amit Shipping Services Security & Risk Analysis
wordpress.org/plugins/malca-amit-shipping-servicesMalca-Amit Shipping Services plugin for WooCommerce.
Is Malca-Amit Shipping Services Safe to Use in 2026?
Generally Safe
Score 85/100Malca-Amit Shipping Services has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "malca-amit-shipping-services" plugin v1.03 presents a significant security risk due to a large attack surface composed entirely of unprotected AJAX handlers. While the plugin demonstrates good practices by using prepared statements for all SQL queries and performing file operations, the complete lack of authentication and capability checks on its 16 AJAX entry points is a major concern. The taint analysis did reveal one flow with an unsanitized path, which, although not rated critical or high, suggests a potential for vulnerabilities if user-supplied data is not handled with extreme care.
The plugin's vulnerability history is clean, with no recorded CVEs. This could indicate a lack of historical targeting or a well-maintained codebase in the past. However, the absence of vulnerabilities does not negate the inherent risks identified in the static analysis. The most pressing issue is the open exposure of numerous AJAX actions, which could be leveraged for various attacks, including unauthorized data manipulation or execution of unintended actions, especially if any of these handlers interact with sensitive data or functionality.
In conclusion, while the plugin shows strengths in its database interaction and file handling, the security posture is severely weakened by its unprotected AJAX endpoints. The taint analysis further highlights a potential blind spot. It is strongly recommended that all AJAX handlers be secured with appropriate nonce and capability checks to mitigate the substantial risks associated with its current attack surface.
Key Concerns
- 16 unprotected AJAX handlers
- 1 unsanitized path in taint analysis
- 37% output escaping is low
- 0 capability checks found
Malca-Amit Shipping Services Security Vulnerabilities
Malca-Amit Shipping Services Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Malca-Amit Shipping Services Attack Surface
AJAX Handlers 16
WordPress Hooks 3
Maintenance & Trust
Malca-Amit Shipping Services Maintenance & Trust
Maintenance Signals
Community Trust
Malca-Amit Shipping Services Alternatives
Easyship WooCommerce Shipping Rates
easyship-woocommerce-shipping-rates
Easyship for WooCommerce saves you time and money with live courier rates, seamless checkout, automated taxes & duties, and shipping label creation.
Distance Based Shipping Calculator
distance-based-shipping-calculator
This plugin retrieves the distance between your shipping origins and your customer and applies a rate per unit of distance (mile or kilometer) to calc …
Flat Shipping Rates by Eniture Technology
flat-shipping-rates-by-eniture-technology
The Flat Rate Shipping for WooCommerce plugin is a free add-on plugin that requires the installation and
Cost Calculator Builder
cost-calculator-builder
WP Cost Calculator is a simple and powerful tool that lets you create price estimation forms. Easily give your clients information about your services …
WC Hide Shipping Methods
wc-hide-shipping-methods
This plugin automatically hides all other shipping methods when "Free Shipping" is available, while allowing you to retain "Local Picku …
Malca-Amit Shipping Services Developer Profile
1 plugin · 10 total installs
How We Detect Malca-Amit Shipping Services
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/malca-amit-shipping-services/assets/css/fonts.css/wp-content/plugins/malca-amit-shipping-services/assets/css/font-awesome.min.css/wp-content/plugins/malca-amit-shipping-services/assets/css/common.css/wp-content/plugins/malca-amit-shipping-services/assets/css/style.css/wp-content/plugins/malca-amit-shipping-services/assets/css/jquery.datetimepicker.css/wp-content/plugins/malca-amit-shipping-services/assets/js/jquery.datetimepicker.full.jshttps://www.google.com/recaptcha/api.jsHTML / DOM Fingerprints
MALCA_STORE_URLMALCA_DIRMALCA_FOLDER