Postcode Shipping Rates- WooCommerce Security & Risk Analysis

wordpress.org/plugins/postcode-shipping

Postcode Shipping is a clean, powerful shipping rates plugin that helps you define multiple rates based on Quantity/Order on countrys/states/postcodes …

100 active installs v2.1.2 PHP + WP 3.5+ Updated Oct 14, 2014
postcoderatesshippingtaxzip
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Postcode Shipping Rates- WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Postcode Shipping Rates- WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "postcode-shipping" plugin v2.1.2 exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, unsanitized taint flows, or unescaped output signals excellent development practices in these areas. Furthermore, the plugin has no recorded vulnerabilities, including critical or high severity ones, which indicates a history of secure code and effective maintenance.

Despite the overwhelmingly positive static analysis and vulnerability history, the primary concern lies in the complete lack of any identified entry points (AJAX handlers, REST API routes, shortcodes, cron events). While this might suggest a very simple or integrated functionality, it also means there are no explicit points where security checks like capability checks or nonce checks *could* be implemented and thus were not found. This absence of measurable security checks, even if not strictly required due to a lack of traditional entry points, is a slight weakness in demonstrating a defense-in-depth approach. However, given the other positive indicators, this is a minor point.

In conclusion, "postcode-shipping" v2.1.2 appears to be a secure plugin with no immediate exploitable vulnerabilities identified. The developers have demonstrated good practices in handling data and preventing common web vulnerabilities. The only area for potential improvement, albeit minor in this context, would be the explicit inclusion of security checks if any new entry points were ever introduced.

Key Concerns

  • No capability checks found
  • No nonce checks found
Vulnerabilities
None known

Postcode Shipping Rates- WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Postcode Shipping Rates- WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped5 total outputs
Attack Surface

Postcode Shipping Rates- WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwoocommerce_shipping_initpostcode_shipping.php:812
filterwoocommerce_shipping_methodspostcode_shipping.php:826
Maintenance & Trust

Postcode Shipping Rates- WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedOct 14, 2014
PHP min version
Downloads18K

Community Trust

Rating68/100
Number of ratings10
Active installs100
Developer Profile

Postcode Shipping Rates- WooCommerce Developer Profile

Rizwan ahammad

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Postcode Shipping Rates- WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/postcode-shipping/css/admin/postcode-shipping.css/wp-content/plugins/postcode-shipping/js/admin/postcode-shipping.js/wp-content/plugins/postcode-shipping/js/frontend/postcode-shipping.js
Version Parameters
postcode-shipping/css/admin/postcode-shipping.css?ver=postcode-shipping/js/admin/postcode-shipping.js?ver=postcode-shipping/js/frontend/postcode-shipping.js?ver=

HTML / DOM Fingerprints

CSS Classes
woocommerce_flatrate_perpostcode
Data Attributes
data-method_id="woocommerce_flatrate_perpostcode"
FAQ

Frequently Asked Questions about Postcode Shipping Rates- WooCommerce