
Shipping Cost on Product Page Calculator for WooCommerce Security & Risk Analysis
wordpress.org/plugins/octolize-shipping-cost-on-product-pageDisplay shipping costs on product pages. Allow customers to calculate shipping based on their address before checkout. Improve UX and boost sales!
Is Shipping Cost on Product Page Calculator for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Shipping Cost on Product Page Calculator for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The octolize-shipping-cost-on-product-page plugin, version 1.5.15, exhibits a generally positive security posture, particularly concerning its limited attack surface and the absence of known vulnerabilities. The plugin has zero recorded CVEs, indicating a history of responsible development or a lack of targeting. The static analysis reveals a minimal attack surface with only one AJAX handler, and importantly, this handler is protected by nonce and capability checks, which is a significant strength. The lack of direct REST API routes, shortcodes, or cron events further reduces potential entry points. However, there are areas for improvement. The presence of the 'proc_open' function, while not inherently a vulnerability, is a high-risk function that should be handled with extreme caution and robust sanitization. Furthermore, the significant percentage of SQL queries (100%) not using prepared statements is a major concern, posing a substantial risk of SQL injection vulnerabilities. The relatively low percentage of properly escaped output (39%) also suggests potential cross-site scripting (XSS) vulnerabilities. While taint analysis shows no critical or high severity flows, this is likely due to the limited number of flows analyzed and the lack of sanitization on the SQL queries. In conclusion, the plugin benefits from a small attack surface and a clean vulnerability history, but the use of raw SQL queries and insufficient output escaping are critical weaknesses that require immediate attention to prevent serious security compromises.
Key Concerns
- Raw SQL queries without prepared statements
- Low percentage of properly escaped output
- Use of dangerous function 'proc_open'
Shipping Cost on Product Page Calculator for WooCommerce Security Vulnerabilities
Shipping Cost on Product Page Calculator for WooCommerce Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Shipping Cost on Product Page Calculator for WooCommerce Attack Surface
AJAX Handlers 1
WordPress Hooks 43
Maintenance & Trust
Shipping Cost on Product Page Calculator for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Shipping Cost on Product Page Calculator for WooCommerce Alternatives
Product page shipping calculator for WooCommerce
product-page-shipping-calculator-for-woocommerce
This plugin allows you to show the shipping methods available on the product page for WooCommerce, so customers can see if shipping is available to th …
Cost Calculator Builder
cost-calculator-builder
WP Cost Calculator is a simple and powerful tool that lets you create price estimation forms. Easily give your clients information about your services …
Easyship WooCommerce Shipping Rates
easyship-woocommerce-shipping-rates
Easyship for WooCommerce saves you time and money with live courier rates, seamless checkout, automated taxes & duties, and shipping label creation.
WooReer
wcsdm
WooReer calculates shipping rates based on distance via Google Maps, Mapbox, DistanceMatrix.ai, Geoapify, or HERE.
Distance Based Shipping Calculator
distance-based-shipping-calculator
This plugin retrieves the distance between your shipping origins and your customer and applies a rate per unit of distance (mile or kilometer) to calc …
Shipping Cost on Product Page Calculator for WooCommerce Developer Profile
11 plugins · 114K total installs
How We Detect Shipping Cost on Product Page Calculator for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/octolize-shipping-cost-on-product-page/dist/upsell-metabox.css/wp-content/plugins/octolize-shipping-cost-on-product-page/dist/app.css/wp-content/plugins/octolize-shipping-cost-on-product-page/dist/app.js/wp-content/plugins/octolize-shipping-cost-on-product-page/dist/app.jsoctolize-shipping-cost-on-product-page/dist/app.css?ver=octolize-shipping-cost-on-product-page/dist/app.js?ver=HTML / DOM Fingerprints
octolize-shipping-calculator-wrapperoctolize-shipping-calculator-formoctolize-shipping-calculator-fieldsShipping Calculatorshipping calculatordata-ajax-url__jsOctolizeCostOnProductPage