Custom Location Restrictor for WooCommerce Security & Risk Analysis

wordpress.org/plugins/region-or-zip-code-restriction

The plugin restricts Billing/Shipping for custom states and custom zip codes.

80 active installs v1.0.1 PHP + WP 4.0.0+ Updated Feb 11, 2026
checkoutlocationrestrictionshippingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Custom Location Restrictor for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Custom Location Restrictor for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The region-or-zip-code-restriction plugin v1.0.1 exhibits an exceptionally strong security posture based on the provided static analysis and vulnerability history. The absence of any identified attack surface entry points, coupled with a complete lack of dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, or insecure use of nonces and capabilities, indicates a well-secured codebase. Taint analysis revealing zero flows, especially with no unsanitized paths, further solidifies this assessment.

The plugin's vulnerability history is also pristine, with zero recorded CVEs of any severity. This suggests either a consistently secure development process or a lack of significant attention from vulnerability researchers, which in itself can be an indicator of a robust security implementation. The combination of a minimal attack surface, secure coding practices evident in the analysis, and a clear vulnerability-free history presents a low-risk profile.

While the plugin appears to be highly secure, the complete lack of any attack surface entry points (AJAX, REST API, shortcodes, cron) is noteworthy. This could mean the plugin is purely functional and doesn't require user interaction via these common WordPress mechanisms, or it might suggest a limited scope of functionality. Nevertheless, based on the presented data, this plugin represents a strong example of secure WordPress plugin development.

Vulnerabilities
None known

Custom Location Restrictor for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Custom Location Restrictor for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Custom Location Restrictor for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwoocommerce_after_checkout_validationclasses\class-rpr-public.php:25
filterwoocommerce_get_sections_shippingclasses\class-rpr-woocommerce.php:33
filterwoocommerce_get_settings_shippingclasses\class-rpr-woocommerce.php:34
Maintenance & Trust

Custom Location Restrictor for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 11, 2026
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs80
Developer Profile

Custom Location Restrictor for WooCommerce Developer Profile

wpspin

6 plugins · 1K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
22 days
View full developer profile
Detection Fingerprints

How We Detect Custom Location Restrictor for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/region-or-zip-code-restriction/assets/css/style.css/wp-content/plugins/region-or-zip-code-restriction/assets/js/wpspins-rpr-admin.js/wp-content/plugins/region-or-zip-code-restriction/assets/js/wpspins-rpr.js
Script Paths
/wp-content/plugins/region-or-zip-code-restriction/assets/js/wpspins-rpr-admin.js/wp-content/plugins/region-or-zip-code-restriction/assets/js/wpspins-rpr.js
Version Parameters
region-or-zip-code-restriction/assets/css/style.css?ver=region-or-zip-code-restriction/assets/js/wpspins-rpr-admin.js?ver=region-or-zip-code-restriction/assets/js/wpspins-rpr.js?ver=

HTML / DOM Fingerprints

JS Globals
WPX_CLZ_VERSIONWPX_CLZ_NAMEWPX_CLZ_PLUGIN_NAMEWPX_CLZ_PLUGIN_FILEWPX_CLZ_PLUGIN_PATHWPX_CLZ_PLUGIN_URL
FAQ

Frequently Asked Questions about Custom Location Restrictor for WooCommerce