Malca-Amit Shipping Services Security & Risk Analysis

wordpress.org/plugins/malca-amit-shipping-services

Malca-Amit Shipping Services plugin for WooCommerce.

10 active installs v1.03 PHP 5.2.4+ WP 3.0.1+ Updated Dec 19, 2022
calculatorshipping-calculatorshipping-extensionshipping-methodshipping-rates
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Malca-Amit Shipping Services Safe to Use in 2026?

Generally Safe

Score 85/100

Malca-Amit Shipping Services has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "malca-amit-shipping-services" plugin v1.03 presents a significant security risk due to a large attack surface composed entirely of unprotected AJAX handlers. While the plugin demonstrates good practices by using prepared statements for all SQL queries and performing file operations, the complete lack of authentication and capability checks on its 16 AJAX entry points is a major concern. The taint analysis did reveal one flow with an unsanitized path, which, although not rated critical or high, suggests a potential for vulnerabilities if user-supplied data is not handled with extreme care.

The plugin's vulnerability history is clean, with no recorded CVEs. This could indicate a lack of historical targeting or a well-maintained codebase in the past. However, the absence of vulnerabilities does not negate the inherent risks identified in the static analysis. The most pressing issue is the open exposure of numerous AJAX actions, which could be leveraged for various attacks, including unauthorized data manipulation or execution of unintended actions, especially if any of these handlers interact with sensitive data or functionality.

In conclusion, while the plugin shows strengths in its database interaction and file handling, the security posture is severely weakened by its unprotected AJAX endpoints. The taint analysis further highlights a potential blind spot. It is strongly recommended that all AJAX handlers be secured with appropriate nonce and capability checks to mitigate the substantial risks associated with its current attack surface.

Key Concerns

  • 16 unprotected AJAX handlers
  • 1 unsanitized path in taint analysis
  • 37% output escaping is low
  • 0 capability checks found
Vulnerabilities
None known

Malca-Amit Shipping Services Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Malca-Amit Shipping Services Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
33
19 escaped
Nonce Checks
8
Capability Checks
0
File Operations
9
External Requests
1
Bundled Libraries
1

Bundled Libraries

jQuery

Output Escaping

37% escaped52 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<download> (include\download.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
16 unprotected

Malca-Amit Shipping Services Attack Surface

Entry Points16
Unprotected16

AJAX Handlers 16

authwp_ajax_malca_logininclude\autoload.php:4
noprivwp_ajax_malca_logininclude\autoload.php:5
authwp_ajax_malca_registerinclude\autoload.php:7
noprivwp_ajax_malca_registerinclude\autoload.php:8
authwp_ajax_MalcaSignOutinclude\autoload.php:10
noprivwp_ajax_MalcaSignOutinclude\autoload.php:11
authwp_ajax_Malca_OrderListinclude\autoload.php:13
noprivwp_ajax_Malca_OrderListinclude\autoload.php:14
authwp_ajax_MalcaPrintLableinclude\autoload.php:16
noprivwp_ajax_MalcaPrintLableinclude\autoload.php:17
authwp_ajax_MalcaBulkPrintLableinclude\autoload.php:19
noprivwp_ajax_MalcaBulkPrintLableinclude\autoload.php:20
authwp_ajax_MalcaReturnLableinclude\autoload.php:22
noprivwp_ajax_MalcaReturnLableinclude\autoload.php:23
authwp_ajax_MalcagetEstimatedCostinclude\autoload.php:25
noprivwp_ajax_MalcagetEstimatedCostinclude\autoload.php:26
WordPress Hooks 3
actioninitinclude\autoload.php:28
actionwoocommerce_admin_order_data_after_billing_addressinclude\functions.php:41
actionadmin_menumalca.php:127
Maintenance & Trust

Malca-Amit Shipping Services Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedDec 19, 2022
PHP min version5.2.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Malca-Amit Shipping Services Developer Profile

liorma

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Malca-Amit Shipping Services

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/malca-amit-shipping-services/assets/css/fonts.css/wp-content/plugins/malca-amit-shipping-services/assets/css/font-awesome.min.css/wp-content/plugins/malca-amit-shipping-services/assets/css/common.css/wp-content/plugins/malca-amit-shipping-services/assets/css/style.css/wp-content/plugins/malca-amit-shipping-services/assets/css/jquery.datetimepicker.css/wp-content/plugins/malca-amit-shipping-services/assets/js/jquery.datetimepicker.full.js
Script Paths
https://www.google.com/recaptcha/api.js

HTML / DOM Fingerprints

JS Globals
MALCA_STORE_URLMALCA_DIRMALCA_FOLDER
FAQ

Frequently Asked Questions about Malca-Amit Shipping Services