Pineparks Pseudo Shipping for Woocommerce Security & Risk Analysis

wordpress.org/plugins/pineparks-pseudo-shipping

Pineparks Pseudo Shipping: Preview shipping methods, reduce checkout confusion and lower checkout abandonment.

0 active installs v1.0.1 PHP + WP 5.0+ Updated Mar 5, 2023
pineparkspseudoshippingwoowoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Pineparks Pseudo Shipping for Woocommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Pineparks Pseudo Shipping for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

Based on the provided static analysis, the "pineparks-pseudo-shipping" plugin v1.0.1 exhibits a strong security posture regarding its attack surface and handling of sensitive operations. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits potential entry points for attackers. Furthermore, the complete utilization of prepared statements for SQL queries and the lack of file operations or external HTTP requests are excellent security practices. The vulnerability history also shows no recorded CVEs, indicating a generally secure past. However, a notable concern is the moderate percentage of output escaping (67%). While not critically high, any unescaped output, even if not immediately exploitable, can pose a Cross-Site Scripting (XSS) risk if user-supplied data is involved in those outputs. The complete absence of nonce and capability checks, while mitigated by the limited attack surface, represents a potential weakness should new entry points be introduced or existing ones become more complex in future versions.

In conclusion, the plugin currently appears to be very secure due to its minimal attack surface and sound data handling. The main area for improvement lies in ensuring 100% output escaping to eliminate any potential XSS vulnerabilities. The lack of checks is less of an immediate risk given the current architecture but should be monitored and addressed if the plugin's functionality expands. The clean vulnerability history is a positive indicator of the developer's attention to security.

Key Concerns

  • Output escaping is not 100% proper
  • No nonce checks on any entry points
  • No capability checks on any entry points
Vulnerabilities
None known

Pineparks Pseudo Shipping for Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Pineparks Pseudo Shipping for Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped3 total outputs
Attack Surface

Pineparks Pseudo Shipping for Woocommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwoocommerce_shipping_initshipping-method.php:9
filterwoocommerce_shipping_methodsshipping-method.php:10
filterwoocommerce_after_shipping_rateshipping-method.php:12
Maintenance & Trust

Pineparks Pseudo Shipping for Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedMar 5, 2023
PHP min version
Downloads653

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Pineparks Pseudo Shipping for Woocommerce Developer Profile

Pineparks

4 plugins · 30 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Pineparks Pseudo Shipping for Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pineparks-pseudo-shipping/shipping/abstract-woo-pseudo-shipping.php/wp-content/plugins/pineparks-pseudo-shipping/shipping/pseudo-shipping.php/wp-content/plugins/pineparks-pseudo-shipping/shipping-method.php/wp-content/plugins/pineparks-pseudo-shipping/functions.php

HTML / DOM Fingerprints

CSS Classes
method-description
FAQ

Frequently Asked Questions about Pineparks Pseudo Shipping for Woocommerce