
Packages Configuration for WooCommerce Security & Risk Analysis
wordpress.org/plugins/packages-configuration-for-woocommerceSplit up the items in your customer's cart to offer multiple shipping method selections for a single order
Is Packages Configuration for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100Packages Configuration for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "packages-configuration-for-woocommerce" v1.2.5 exhibits a generally positive security posture based on the provided static analysis and vulnerability history. The absence of any identified CVEs, coupled with a clean taint analysis, suggests that the plugin has not historically been a source of significant security flaws. The code analysis further reinforces this, showing no dangerous functions, no direct SQL queries (all prepared statements), no file operations, and no external HTTP requests, all of which are good security practices. The attack surface is also commendably low with zero entry points identified.
However, there are areas that warrant attention. The output escaping is only 50% proper, indicating a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not consistently sanitized before being displayed. Furthermore, the complete absence of nonce checks and capability checks across all identified entry points (even though there are zero identified) is a concern. While the current attack surface is zero, if any entry points were to be introduced or discovered in the future, the lack of these fundamental security mechanisms would leave them unprotected. The plugin's strengths lie in its secure handling of database operations and avoidance of risky functions. The primary weakness identified is the output escaping, and the potential for future insecure development practices due to the lack of built-in checks.
Key Concerns
- Output escaping is only 50% proper
- No nonce checks on any entry points
- No capability checks on any entry points
Packages Configuration for WooCommerce Security Vulnerabilities
Packages Configuration for WooCommerce Code Analysis
Output Escaping
Packages Configuration for WooCommerce Attack Surface
WordPress Hooks 10
Maintenance & Trust
Packages Configuration for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Packages Configuration for WooCommerce Alternatives
MyParcel
woocommerce-myparcel
Export your WooCommerce orders to MyParcel (www.myparcel.nl) and print labels directly from the WooCommerce admin
Shipping Packages for WooCommerce – Dropship from multiple locations like AliExpress, eBay, Amazon, Etsy
wc-shipping-packages
Offer separate shipping from multiple vendors by grouping products in the cart into packages, so they can be shipped with different shipping methods.
Multiple Packages for WooCommerce
multiple-packages-for-woocommerce
Split up the items in your customer's cart to offer multiple shipping method selections for a single order
Free Shipping Per Package For WooCommerce
wc-free-shipping-per-package
The most Advanced Free Shipping Per Package for WooCommerce plugin that allows you to define flexible Free Shipping scenarios for individual Cart ship …
Weight Based Shipping Table Rate for WooCommerce – Flexible Shipping
flexible-shipping
Weight based shipping methods for WooCommerce. Flexible shipping with table rate rules by cart weight and order value. Accurate rates at checkout.
Packages Configuration for WooCommerce Developer Profile
6 plugins · 910 total installs
How We Detect Packages Configuration for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/packages-configuration-for-woocommerce/classes/Academe_Multiple_Packages.php/wp-content/plugins/packages-configuration-for-woocommerce/classes/Academe_Multiple_Packages_Settings.php