
OmniShip Rates and Shipping for WooCommerce Security & Risk Analysis
wordpress.org/plugins/omniship-rates-and-shipping-for-woocommerceOmniShip allows for shipping and labels via USPS, USPS, PostMates, LTL trucking, and International.
Is OmniShip Rates and Shipping for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100OmniShip Rates and Shipping for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of omniship-rates-and-shipping-for-woocommerce v1.1.9 indicates a generally strong security posture. The plugin exhibits excellent adherence to secure coding practices, with no observed dangerous functions, file operations, or raw SQL queries. A high percentage of output is properly escaped, and the absence of vulnerabilities in its history suggests a well-maintained and secure codebase. The limited external HTTP requests also reduce potential attack vectors.
However, several areas warrant attention. The complete lack of nonce checks and capability checks across all entry points (AJAX handlers, REST API routes, shortcodes, cron events) is a significant concern. While the current analysis shows zero unprotected entry points, this absence of built-in authorization mechanisms leaves the plugin vulnerable to potential CSRF attacks or unauthorized access if new entry points are introduced or if existing ones are indirectly exposed without proper checks. The zero taint analysis flows, while positive, could be due to the limited scope of the analysis or the specific code paths examined; a more comprehensive analysis might reveal subtle issues.
In conclusion, the plugin demonstrates good core security development practices, but the absence of explicit nonce and capability checks on its entry points represents a notable weakness. The strong track record of no known vulnerabilities is a positive indicator, but the lack of these fundamental security checks means the plugin could be susceptible to attacks in certain scenarios, especially if its attack surface grows or if specific attack vectors are not yet accounted for in the static analysis.
Key Concerns
- Missing Nonce Checks
- Missing Capability Checks
- External HTTP Requests
OmniShip Rates and Shipping for WooCommerce Security Vulnerabilities
OmniShip Rates and Shipping for WooCommerce Code Analysis
Output Escaping
OmniShip Rates and Shipping for WooCommerce Attack Surface
WordPress Hooks 7
Maintenance & Trust
OmniShip Rates and Shipping for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
OmniShip Rates and Shipping for WooCommerce Alternatives
WooCommerce Shipping
woocommerce-shipping
A free shipping plugin for US merchants to print discounted shipping labels and compare live label rates directly from your WooCommerce dashboard.
Shipping Live Rates and Access Points for UPS for WooCommerce
flexible-shipping-ups
Provide auto-calculated UPS rates and Access Point options. Easy 5-minute setup. Show real prices and nearest pickup points at WooCommerce checkout.
Shiptastic Integration for DHL
shiptastic-integration-for-dhl
Connect Shiptastic to the DHL API and create DHL labels to shipments and returns.
PostNL for WooCommerce
woo-postnl
The official PostNL plugin allows you to automate your e-commerce order process. Covering shipping services from PostNL Netherlands and Belgium.
Easyship WooCommerce Shipping Rates
easyship-woocommerce-shipping-rates
Easyship for WooCommerce saves you time and money with live courier rates, seamless checkout, automated taxes & duties, and shipping label creation.
OmniShip Rates and Shipping for WooCommerce Developer Profile
1 plugin · 0 total installs
How We Detect OmniShip Rates and Shipping for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/omniship-rates-and-shipping-for-woocommerce/includes/omniship.php/wp-content/plugins/omniship-rates-and-shipping-for-woocommerce/templates/includeBillingAddressArea.php/wp-content/plugins/omniship-rates-and-shipping-for-woocommerce/templates/includeCheckout.php/wp-content/plugins/omniship-rates-and-shipping-for-woocommerce/templates/includeShippingAddressArea.php/wp-content/plugins/omniship-rates-and-shipping-for-woocommerce/templates/settingsPage.phpomniship-rates-and-shipping-for-woocommerce/includes/omniship.php?ver=omniship-rates-and-shipping-for-woocommerce/templates/includeBillingAddressArea.php?ver=omniship-rates-and-shipping-for-woocommerce/templates/includeCheckout.php?ver=omniship-rates-and-shipping-for-woocommerce/templates/includeShippingAddressArea.php?ver=omniship-rates-and-shipping-for-woocommerce/templates/settingsPage.php?ver=HTML / DOM Fingerprints
omnishipLabelPostomnishipTextPost