
Selloship Security & Risk Analysis
wordpress.org/plugins/selloshipAuto Sync your woocommerce store orders & ship them at lowest shipping rates. Automate your shipping, save time & money.
Is Selloship Safe to Use in 2026?
Generally Safe
Score 92/100Selloship has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The selloship plugin v1.5.16 exhibits a concerning security posture primarily due to significant weaknesses in its authentication and data sanitization. While the absence of known CVEs and the use of prepared statements for SQL queries are positive indicators, they are overshadowed by critical vulnerabilities present in the plugin's code. The static analysis reveals a substantial attack surface with two AJAX handlers, both lacking any form of authentication checks. This means any authenticated user, regardless of their role or permissions, could potentially trigger these handlers, leading to unauthorized actions. Furthermore, the taint analysis identified one flow with unsanitized paths, which, although not classified as critical or high severity, still represents a potential risk for data manipulation or unintended behavior. The low percentage of properly escaped output (13%) suggests a high likelihood of cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the user interface. The lack of nonce checks on AJAX handlers further exacerbates the risk of CSRF attacks. In conclusion, despite a clean vulnerability history and good practices in SQL query handling, the exposed AJAX endpoints without authentication, potential XSS issues due to poor output escaping, and unsanitized data flows present significant security risks that require immediate attention. The plugin's design appears to prioritize functionality over robust security measures.
Key Concerns
- AJAX handlers without auth checks
- Unsanitized path flow
- Low output escaping percentage
- Nonce checks missing on AJAX
- Capability checks missing
Selloship Security Vulnerabilities
Selloship Code Analysis
Output Escaping
Data Flow Analysis
Selloship Attack Surface
AJAX Handlers 2
WordPress Hooks 18
Scheduled Events 1
Maintenance & Trust
Selloship Maintenance & Trust
Maintenance Signals
Community Trust
Selloship Alternatives
User role based shipping methods
user-role-based-shipping-method
Display WooCommerce shipping methods based on User Role and Country. Globally compatible.
Conditional Shipping for WooCommerce: Restrict Shipping Options by Anything
wpfactory-conditional-shipping-for-woocommerce
Set conditions for WooCommerce shipping methods to show up.
COD24 Shipping For Woocommerce
cod24-shipping
Add Cod24 shipping methods To Woocommerce
Яндекс Доставка
yandex-go-delivery
Яндекс Доставка — это сервис, который помогает бизнесам отправлять заказы клиентам внутри города и между городами.
Terminal Africa
terminal-africa
Terminal Africa Shipping Method Plugin for WooCommerce
Selloship Developer Profile
1 plugin · 100 total installs
How We Detect Selloship
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/selloship/css/selloship.css/wp-content/plugins/selloship/js/selloship.js/wp-content/plugins/selloship/js/selloship-order-data.js/wp-content/plugins/selloship/js/selloship-tracking-order.js/wp-content/plugins/selloship/js/selloship-shipping-calculator.js/wp-content/plugins/selloship/js/selloship.js/wp-content/plugins/selloship/js/selloship-order-data.js/wp-content/plugins/selloship/js/selloship-tracking-order.js/wp-content/plugins/selloship/js/selloship-shipping-calculator.jsselloship/css/selloship.css?ver=selloship/js/selloship.js?ver=selloship/js/selloship-order-data.js?ver=selloship/js/selloship-tracking-order.js?ver=selloship/js/selloship-shipping-calculator.js?ver=HTML / DOM Fingerprints
selloship-shipping-calculator-wrapper<!-- SelloShip order Id --><!-- Common Classes. -->data-order-iddata-tracking-urldata-product-idsdata-product-quantitydata-customer-iddata-shipping-address+3 moreselloship_ajax_objectselloship_order_data_objectselloship_tracking_objectselloship_shipping_calculator_object/wp-json/selloship/v1/track_order/wp-json/selloship/v1/order_status<div class="selloship-shipping-calculator">