Ajax Free Shipping Bar for WooCommerce Security & Risk Analysis

wordpress.org/plugins/muca-free-shipping-bar-for-woo

Ajax Free Shipping Bar for WooCommerce / Announcement Bar is a free WordPress plugin that gives you ability to add a free shipping bar / announcement …

10 active installs v1.0.1 PHP + WP 4.5+ Updated Unknown
free-announcement-barfree-shipping-barfree-shipping-bar-for-woocommercepromotion-barwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ajax Free Shipping Bar for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Ajax Free Shipping Bar for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

This plugin exhibits a strong security posture in several key areas, demonstrating a commitment to secure coding practices. The absence of any known CVEs, combined with 100% of SQL queries using prepared statements, indicates a generally well-maintained and secure codebase. Furthermore, the static analysis reveals no dangerous functions, file operations, or external HTTP requests, and importantly, it reports zero critical or high severity taint flows. This suggests that the plugin is unlikely to be vulnerable to common injection or data leakage attacks.

However, a significant concern arises from the complete lack of proper output escaping. With 33 total outputs analyzed and 0% properly escaped, this presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed by the plugin that originates from user input or external sources could potentially be manipulated to execute malicious scripts within a user's browser. Additionally, the presence of only one capability check across the entire codebase is a weak point. While there are no identified unprotected entry points in the static analysis, relying on minimal capability checks can leave the plugin susceptible to privilege escalation or unauthorized actions if specific entry points were to be discovered or introduced in future versions.

The plugin's vulnerability history is clean, with no recorded CVEs. This is a positive sign, suggesting proactive security measures or a lack of discovery of vulnerabilities to date. However, the critical finding regarding output escaping means that even without past vulnerabilities, the current codebase is inherently risky due to the unescaped output. The overall security is a mixed bag: strong on preventing known attack vectors like SQL injection and data leakage, but critically weak on preventing XSS, which is a common and impactful vulnerability.

Key Concerns

  • All outputs are unescaped
  • Minimal capability checks
Vulnerabilities
None known

Ajax Free Shipping Bar for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Ajax Free Shipping Bar for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
33
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped33 total outputs
Attack Surface

Ajax Free Shipping Bar for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_initadmin\class.menu.php:27
actionadmin_menuadmin\class.menu.php:32
actioninitmuca-free-shipping-bar-for-woo.php:41
actioninitmuca-free-shipping-bar-for-woo.php:48
actioninitmuca-free-shipping-bar-for-woo.php:52
actionwp_enqueue_scriptsmuca-free-shipping-bar-for-woo.php:61
actionadmin_enqueue_scriptsmuca-free-shipping-bar-for-woo.php:68
actionadmin_enqueue_scriptsmuca-free-shipping-bar-for-woo.php:75
actionwp_headviews\class.head.php:20
filterwoocommerce_add_to_cart_fragmentsviews\class.hooks.php:50
Maintenance & Trust

Ajax Free Shipping Bar for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedUnknown
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Ajax Free Shipping Bar for WooCommerce Developer Profile

MucaSoft

2 plugins · 20 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ajax Free Shipping Bar for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/muca-free-shipping-bar-for-woo/assets/main.css/wp-content/plugins/muca-free-shipping-bar-for-woo/assets/main.js/wp-content/plugins/muca-free-shipping-bar-for-woo/assets/admin.css/wp-content/plugins/muca-free-shipping-bar-for-woo/assets/admin.js/wp-content/plugins/muca-free-shipping-bar-for-woo/assets/admin-color-picker.js
Script Paths
wp-content/plugins/muca-free-shipping-bar-for-woo/assets/main.jswp-content/plugins/muca-free-shipping-bar-for-woo/assets/admin.jswp-content/plugins/muca-free-shipping-bar-for-woo/assets/admin-color-picker.js

HTML / DOM Fingerprints

CSS Classes
mucafsb_head_sticky
FAQ

Frequently Asked Questions about Ajax Free Shipping Bar for WooCommerce