
Shipping Live rates for Australia Post for WooCommerce Security & Risk Analysis
wordpress.org/plugins/octolize-australia-post-shippingOffer your customers the Australia Post shipping methods with real-time calculated shipping rates for domestic and international shipping.
Is Shipping Live rates for Australia Post for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Shipping Live rates for Australia Post for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "octolize-australia-post-shipping" plugin v2.0.17 exhibits a mixed security posture. On the positive side, the attack surface is minimal with only one AJAX handler, and importantly, this handler appears to be protected by authentication. The plugin also demonstrates a reasonable effort in employing prepared statements for SQL queries and includes nonce and capability checks, indicating an awareness of common WordPress security best practices.
However, significant concerns arise from the static code analysis. The presence of 30 "dangerous functions," including `proc_open`, `shell_exec`, and `exec`, is a major red flag, suggesting a high potential for command injection or other severe vulnerabilities if not handled with extreme care and robust input validation. Furthermore, a low percentage (27%) of properly escaped output is alarming, exposing the application to Cross-Site Scripting (XSS) vulnerabilities. The taint analysis, while not reporting critical or high severity issues currently, shows flows with unsanitized paths, which, when combined with the dangerous functions and poor output escaping, creates a precarious situation.
The lack of any recorded vulnerability history is a strength, implying the plugin has been relatively secure in the past. However, this historical data should not be relied upon to mitigate the risks identified in the current code analysis. The current version's codebase presents substantial risks due to the combination of powerful, potentially unsafe functions and inadequate output sanitization.
Key Concerns
- High number of dangerous functions used
- Low percentage of properly escaped output
- Flows with unsanitized paths found
- Bundled outdated Guzzle library
Shipping Live rates for Australia Post for WooCommerce Security Vulnerabilities
Shipping Live rates for Australia Post for WooCommerce Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Shipping Live rates for Australia Post for WooCommerce Attack Surface
AJAX Handlers 1
WordPress Hooks 72
Maintenance & Trust
Shipping Live rates for Australia Post for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Shipping Live rates for Australia Post for WooCommerce Alternatives
ELEX WooCommerce Australia Post Shipping
elex-australia-post-shipping
The Ultimate WooCommerce Australia Post Shipping Plugin from Team ELEXtensions. The plugin integrates Australia Post APIs with WooCommerce.
Australia Post WooCommerce Extension
australian-post-woocommerce-extension
Australia Post WooCommerce Extension integrates Australia Post with WooCommerce, calculating shipping costs and delivery times for customers.
Shippit for WooCommerce
shippit-simplified-australia-shipping
Multi-carrier shipping technology.
ReachShip WooCommerce Multi-Carrier & Conditional Shipping
elex-reachship-multi-carrier-conditional-shipping
Multi-carrier WooCommerce shipping plugin to get rates, print labels, pickups & track DHL, FedEx, UPS, USPS, Australia Post via ReachShip API.
IH Shipping for Australia Post
ih-shipping-for-auspost
A shipping integration that adds real-time Australia Post calculations (Parcel Post) with volumetric box packing.
Shipping Live rates for Australia Post for WooCommerce Developer Profile
11 plugins · 114K total installs
How We Detect Shipping Live rates for Australia Post for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/octolize-australia-post-shipping/vendor_prefixed/octolize/wp-octolize-brand-assets/src/Brand/Assets/../assets/dist/css/admin.css/wp-content/plugins/octolize-australia-post-shipping/vendor_prefixed/octolize/wp-onboarding/assets/css/onboarding.css/wp-content/plugins/octolize-australia-post-shipping/vendor_prefixed/octolize/wp-onboarding/assets/js/onboarding.js/wp-content/plugins/octolize-australia-post-shipping/vendor_prefixed/octolize/wp-octolize-brand-assets/src/Brand/Assets/../assets/dist/css/admin.css/wp-content/plugins/octolize-australia-post-shipping/vendor_prefixed/octolize/wp-onboarding/assets/css/onboarding.css/wp-content/plugins/octolize-australia-post-shipping/vendor_prefixed/octolize/wp-onboarding/assets/js/onboarding.jsoctolize-australia-post-shipping/vendor_prefixed/octolize/wp-octolize-brand-assets/src/Brand/Assets/../assets/dist/css/admin.css?ver=octolize-australia-post-shipping/vendor_prefixed/octolize/wp-onboarding/assets/css/onboarding.css?ver=octolize-australia-post-shipping/vendor_prefixed/octolize/wp-onboarding/assets/js/onboarding.js?ver=HTML / DOM Fingerprints
octolize-onboarding-modalTHIS VARIABLE CAN BE CHANGED AUTOMATICALLYdata-autostartdata-logo-imgdata-pagedata-ajax-urldata-ajax-noncedata-ajax-action-event+2 moreOctolizeOnboarding