AfterShip Shipping: Free Shipping Labels for WooCommerce, Discounted Shipping Rates Security & Risk Analysis

wordpress.org/plugins/postmen-woo-shipping

WooCommerce Shipping - Print shipping labels faster, compare costs and delivery time across 60 carrier services to optimize your shipping routes.

200 active installs v1.3.15 PHP + WP 4.4+ Updated Sep 9, 2025
ecommerce-shippinguspsweight-based-shippingwoocommercewoocommerce-shipping
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AfterShip Shipping: Free Shipping Labels for WooCommerce, Discounted Shipping Rates Safe to Use in 2026?

Generally Safe

Score 100/100

AfterShip Shipping: Free Shipping Labels for WooCommerce, Discounted Shipping Rates has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The static analysis of postmen-woo-shipping v1.3.15 reveals a mixed security posture. On the positive side, there are no identified dangerous functions, all SQL queries are properly prepared, and there are no external HTTP requests or bundled libraries, which are generally good practices. The plugin also implements capability checks, indicating some level of authorization is considered.

However, several areas raise concerns. The taint analysis indicates two flows with unsanitized paths, which is a significant risk as it suggests potential for injection vulnerabilities if these paths are exposed to user input. Furthermore, the output escaping is only 47% proper, meaning a substantial portion of dynamic output is not being sanitized, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities. The complete absence of nonce checks, especially with an attack surface of 0 reported entry points (which is unusual and might be an artifact of the analysis scope), warrants caution. If any entry points exist that are not properly secured, the lack of nonces would be a critical flaw.

The vulnerability history is a strong positive point, with zero known CVEs, suggesting a history of relatively secure development. However, this cannot entirely offset the risks identified in the static analysis, particularly the unsanitized paths and poor output escaping. The conclusion is that while the plugin has a clean vulnerability record and avoids some common pitfalls like raw SQL and bundled libraries, the identified taint flows and significant amount of unescaped output present clear and actionable security risks that require immediate attention.

Key Concerns

  • Unsanitized paths in taint analysis
  • Low percentage of properly escaped output
  • No nonce checks detected
Vulnerabilities
None known

AfterShip Shipping: Free Shipping Labels for WooCommerce, Discounted Shipping Rates Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AfterShip Shipping: Free Shipping Labels for WooCommerce, Discounted Shipping Rates Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
3 prepared
Unescaped Output
17
15 escaped
Nonce Checks
0
Capability Checks
8
File Operations
2
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared3 total queries

Output Escaping

47% escaped32 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
settingsPage (PostmenWoocommercePlugin_OptionsManager.php:292)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

AfterShip Shipping: Free Shipping Labels for WooCommerce, Discounted Shipping Rates Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
filterpostmen_api_check_authenticationapi\class-postmen-api-authentication.php:39
actionpre_get_usersapi\class-postmen-api-authentication.php:104
filterpostmen_api_endpointsapi\class-postmen-api-resource.php:38
actionadmin_noticespostmen-woocommerce-plugin.php:57
actionplugins_loadedipostmen-woocommerce-plugin.php:84
filterquery_varsPostmenWoocommercePlugin_API.php:24
actioninitPostmenWoocommercePlugin_API.php:27
actionparse_requestPostmenWoocommercePlugin_API.php:30
actionadmin_initPostmenWoocommercePlugin_OptionsManager.php:276
actionshow_user_profilePostmenWoocommercePlugin_Plugin.php:103
actionedit_user_profilePostmenWoocommercePlugin_Plugin.php:104
actionpersonal_options_updatePostmenWoocommercePlugin_Plugin.php:105
actionedit_user_profile_updatePostmenWoocommercePlugin_Plugin.php:106
actionwp_footerPostmenWoocommercePlugin_ShortCodeScriptLoader.php:40
filtercomments_clausesPostmenWoocommercePlugin_Utilities.php:60
Maintenance & Trust

AfterShip Shipping: Free Shipping Labels for WooCommerce, Discounted Shipping Rates Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedSep 9, 2025
PHP min version
Downloads31K

Community Trust

Rating82/100
Number of ratings17
Active installs200
Developer Profile

AfterShip Shipping: Free Shipping Labels for WooCommerce, Discounted Shipping Rates Developer Profile

AfterShip & Automizely

4 plugins · 9K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect AfterShip Shipping: Free Shipping Labels for WooCommerce, Discounted Shipping Rates

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/postmen-woo-shipping/postmen-woocommerce-plugin_init.php/wp-content/plugins/postmen-woo-shipping/PostmenWoocommercePlugin_Plugin.php/wp-content/plugins/postmen-woo-shipping/PostmenWoocommercePlugin_Utilities.php/wp-content/plugins/postmen-woo-shipping/PostmenWoocommercePlugin_API.php/wp-content/plugins/postmen-woo-shipping/PostmenWoocommercePlugin_LifeCycle.php

HTML / DOM Fingerprints

HTML Comments
WordPress Plugin Template Copyright (C) 2016 Michael Simpson http://plugin.michael-simpson.com/?page_id=31 http://plugin.michael-simpson.com/?page_id=101+2 more
JS Globals
PostmenWoocommercePlugin_minimalRequiredPhpVersion
FAQ

Frequently Asked Questions about AfterShip Shipping: Free Shipping Labels for WooCommerce, Discounted Shipping Rates