WP E-commerce Postcode Shipping Module Security & Risk Analysis

wordpress.org/plugins/postcode-shipping-module

WP E-commerce Postcode Shipping Module is a plugin which allows to calculate the shipping cost by postcode/zipcode.

10 active installs v1.4.0 PHP + WP 2.0+ Updated Jun 20, 2022
e-commercepostcode-shippingshippingwp-e-commercezipcode-shipping
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP E-commerce Postcode Shipping Module Safe to Use in 2026?

Generally Safe

Score 85/100

WP E-commerce Postcode Shipping Module has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The postcode-shipping-module plugin v1.4.0 exhibits a seemingly strong security posture based on the provided static analysis. The absence of direct entry points like AJAX handlers, REST API routes, shortcodes, and cron events, combined with the lack of observed dangerous functions, SQL injection risks (all queries use prepared statements), and file operations, is a positive indicator. Furthermore, the plugin has no recorded vulnerability history, which suggests a history of secure development or diligent patching if vulnerabilities were ever discovered.

However, a significant concern is the low percentage of properly escaped output (53%). This indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed. While taint analysis did not reveal any issues, this is likely due to the limited scope of the analysis or the absence of detectable flows in the specific code paths examined. The complete absence of capability checks and nonce checks, while not immediately problematic given the lack of entry points, represents a potential weakness if the plugin's functionality were to expand or if new entry points were introduced in future versions without corresponding security measures.

In conclusion, the plugin benefits from a limited attack surface and a clean vulnerability history. However, the poor output escaping is a critical area of concern that introduces a tangible risk of XSS. The lack of capability and nonce checks, while not a current direct exploit, points to a potential for future security gaps. The overall security is moderately concerning due to the output escaping issue, despite the absence of more severe vulnerabilities.

Key Concerns

  • Low output escaping percentage
  • No capability checks
  • No nonce checks
Vulnerabilities
None known

WP E-commerce Postcode Shipping Module Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WP E-commerce Postcode Shipping Module Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

WP E-commerce Postcode Shipping Module Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

53% escaped15 total outputs
Attack Surface

WP E-commerce Postcode Shipping Module Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

WP E-commerce Postcode Shipping Module Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedJun 20, 2022
PHP min version
Downloads4K

Community Trust

Rating20/100
Number of ratings1
Active installs10
Developer Profile

WP E-commerce Postcode Shipping Module Developer Profile

Tomas

12 plugins · 7K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
526 days
View full developer profile
Detection Fingerprints

How We Detect WP E-commerce Postcode Shipping Module

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wpsc-button-roundwpsc-button-minuswpsc-button-plustable-rate
Data Attributes
name='wpsc_shipping_postcoderate_layer[]'name='wpsc_shipping_postcoderate_shipping[]'
FAQ

Frequently Asked Questions about WP E-commerce Postcode Shipping Module