
Mojito Shipping Security & Risk Analysis
wordpress.org/plugins/mojito-shippingWeight-based rates for WooCommerce. Simple method shipping support. Correos de Costa Rica web service support for tracking codes. Multisite support.
Is Mojito Shipping Safe to Use in 2026?
Generally Safe
Score 92/100Mojito Shipping has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mojito-shipping plugin exhibits a concerning security posture primarily due to a significant number of unprotected AJAX handlers. While the plugin demonstrates strengths in other areas, such as 100% use of prepared statements for SQL queries and a clean vulnerability history, the lack of authentication checks on 12 AJAX entry points presents a substantial risk. This wide attack surface without proper authorization controls means that any user, potentially even unauthenticated ones, could trigger unintended functionality within these AJAX endpoints. The taint analysis also highlights a weakness, with 13 out of 15 flows having unsanitized paths, although thankfully no critical or high severity issues were identified in this analysis. The presence of bundled Freemius library, version 1.0, could also represent a potential risk if it contains known vulnerabilities. Overall, the plugin has good practices regarding database interactions and a clean historical record, but the critical flaw of numerous unprotected AJAX handlers demands immediate attention to mitigate potential security breaches.
Key Concerns
- Large attack surface without auth checks
- Unsanitized paths in taint flows
- Bundled outdated library (Freemius v1.0)
- Low output escaping coverage
Mojito Shipping Security Vulnerabilities
Mojito Shipping Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Mojito Shipping Attack Surface
AJAX Handlers 12
WordPress Hooks 44
Scheduled Events 4
Maintenance & Trust
Mojito Shipping Maintenance & Trust
Maintenance Signals
Community Trust
Mojito Shipping Alternatives
AfterShip Shipping: Free Shipping Labels for WooCommerce, Discounted Shipping Rates
postmen-woo-shipping
WooCommerce Shipping - Print shipping labels faster, compare costs and delivery time across 60 carrier services to optimize your shipping routes.
Weight Based Shipping Table Rate for WooCommerce – Flexible Shipping
flexible-shipping
Weight based shipping methods for WooCommerce. Flexible shipping with table rate rules by cart weight and order value. Accurate rates at checkout.
Weight Based Shipping for WooCommerce
weight-based-shipping-for-woocommerce
Weight Based Shipping is a flexible and widely-used solution to calculate shipping costs based on the total cart weight and value.
Russian Post and EMS for WooCommerce
russian-post-and-ems-for-woocommerce
The plugin allows you to automatically calculate shipping costs of "Russian Post" or "EMS"
Express, Certified Post, Bike Delivery and Iranian Postal Companies for WooCommerce
woocommerce-iran-post-shipping
Express & Certified Post, Bike Delivery and Iranian Postal Companies for WooCommerce
Mojito Shipping Developer Profile
2 plugins · 390 total installs
How We Detect Mojito Shipping
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mojito-shipping/admin/css/mojito-shipping-admin.css/wp-content/plugins/mojito-shipping/admin/js/mojito-shipping-admin.js/wp-content/plugins/mojito-shipping/includes/class-mojito-shipping.php/wp-content/plugins/mojito-shipping/load-freemius.php/wp-content/plugins/mojito-shipping/admin/js/mojito-shipping-admin.jsmojito-shipping/admin/css/mojito-shipping-admin.css?ver=mojito-shipping/admin/js/mojito-shipping-admin.js?ver=HTML / DOM Fingerprints
mojito-shipping-settings-debugdata-input-iddata-label-idmojito_shipping_fsmojito_shipping