OmniShip Rates and Shipping for WooCommerce Security & Risk Analysis

wordpress.org/plugins/omniship-rates-and-shipping-for-woocommerce

OmniShip allows for shipping and labels via USPS, USPS, PostMates, LTL trucking, and International.

0 active installs v1.1.9 PHP 5.4+ WP 4.0+ Updated Nov 10, 2020
labelspostmatesshippingupswoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is OmniShip Rates and Shipping for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

OmniShip Rates and Shipping for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The static analysis of omniship-rates-and-shipping-for-woocommerce v1.1.9 indicates a generally strong security posture. The plugin exhibits excellent adherence to secure coding practices, with no observed dangerous functions, file operations, or raw SQL queries. A high percentage of output is properly escaped, and the absence of vulnerabilities in its history suggests a well-maintained and secure codebase. The limited external HTTP requests also reduce potential attack vectors.

However, several areas warrant attention. The complete lack of nonce checks and capability checks across all entry points (AJAX handlers, REST API routes, shortcodes, cron events) is a significant concern. While the current analysis shows zero unprotected entry points, this absence of built-in authorization mechanisms leaves the plugin vulnerable to potential CSRF attacks or unauthorized access if new entry points are introduced or if existing ones are indirectly exposed without proper checks. The zero taint analysis flows, while positive, could be due to the limited scope of the analysis or the specific code paths examined; a more comprehensive analysis might reveal subtle issues.

In conclusion, the plugin demonstrates good core security development practices, but the absence of explicit nonce and capability checks on its entry points represents a notable weakness. The strong track record of no known vulnerabilities is a positive indicator, but the lack of these fundamental security checks means the plugin could be susceptible to attacks in certain scenarios, especially if its attack surface grows or if specific attack vectors are not yet accounted for in the static analysis.

Key Concerns

  • Missing Nonce Checks
  • Missing Capability Checks
  • External HTTP Requests
Vulnerabilities
None known

OmniShip Rates and Shipping for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

OmniShip Rates and Shipping for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
60 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

92% escaped65 total outputs
Attack Surface

OmniShip Rates and Shipping for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionwoocommerce_checkout_update_order_metatemplates\includeBillingAddressArea.php:4
actionwoocommerce_admin_order_data_after_billing_addresstemplates\includeBillingAddressArea.php:13
actionwoocommerce_shipping_inittemplates\includeCheckout.php:178
filterwoocommerce_shipping_methodstemplates\includeCheckout.php:186
actionwoocommerce_admin_order_data_after_shipping_addresstemplates\includeShippingAddressArea.php:4
actionadmin_menutemplates\settingsPage.php:3
actionadmin_inittemplates\settingsPage.php:11
Maintenance & Trust

OmniShip Rates and Shipping for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedNov 10, 2020
PHP min version5.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

OmniShip Rates and Shipping for WooCommerce Developer Profile

transportlogic

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect OmniShip Rates and Shipping for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/omniship-rates-and-shipping-for-woocommerce/includes/omniship.php/wp-content/plugins/omniship-rates-and-shipping-for-woocommerce/templates/includeBillingAddressArea.php/wp-content/plugins/omniship-rates-and-shipping-for-woocommerce/templates/includeCheckout.php/wp-content/plugins/omniship-rates-and-shipping-for-woocommerce/templates/includeShippingAddressArea.php/wp-content/plugins/omniship-rates-and-shipping-for-woocommerce/templates/settingsPage.php
Version Parameters
omniship-rates-and-shipping-for-woocommerce/includes/omniship.php?ver=omniship-rates-and-shipping-for-woocommerce/templates/includeBillingAddressArea.php?ver=omniship-rates-and-shipping-for-woocommerce/templates/includeCheckout.php?ver=omniship-rates-and-shipping-for-woocommerce/templates/includeShippingAddressArea.php?ver=omniship-rates-and-shipping-for-woocommerce/templates/settingsPage.php?ver=

HTML / DOM Fingerprints

CSS Classes
omnishipLabelPostomnishipTextPost
FAQ

Frequently Asked Questions about OmniShip Rates and Shipping for WooCommerce