Sendbox-Shipping Security & Risk Analysis

wordpress.org/plugins/sendbox-shipping

This is a woocommerce plugin that allows you ship form your store in nigeria to anywhere in the world. Sendbox-Shipping is a woocommerce plugin create …

40 active installs v5.5.5 PHP 7.4+ WP 6.0+ Updated Mar 11, 2026
international-shippinglocal-shippingshippingshipping-zones
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sendbox-Shipping Safe to Use in 2026?

Generally Safe

Score 100/100

Sendbox-Shipping has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 23d ago
Risk Assessment

The 'sendbox-shipping' plugin v5.5.5 exhibits a mixed security posture. While it demonstrates strong practices in output escaping (98%) and avoids dangerous functions, file operations, and bundled libraries, a significant concern arises from its attack surface. The plugin exposes six AJAX handlers without authentication checks, presenting a substantial risk of unauthorized access and manipulation of sensitive data or functionality. The absence of taint analysis results is neutral, but the lack of any recorded vulnerabilities in its history is a positive indicator of past development efforts. However, the presence of raw SQL queries (60% not using prepared statements) alongside the unprotected AJAX handlers significantly elevates the risk of SQL injection vulnerabilities. Overall, the plugin has strengths in certain areas but requires immediate attention to secure its AJAX endpoints and improve SQL query practices to mitigate potential security breaches.

Key Concerns

  • 6 AJAX handlers without auth checks
  • 40% SQL queries not using prepared statements
Vulnerabilities
None known

Sendbox-Shipping Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Sendbox-Shipping Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
2 prepared
Unescaped Output
2
101 escaped
Nonce Checks
6
Capability Checks
7
File Operations
0
External Requests
7
Bundled Libraries
0

SQL Query Safety

40% prepared5 total queries

Output Escaping

98% escaped103 total outputs
Attack Surface
6 unprotected

Sendbox-Shipping Attack Surface

Entry Points7
Unprotected6

AJAX Handlers 6

authwp_ajax_connect_to_sendboxsrc\Plugin.php:69
authwp_ajax_save_fields_by_ajaxsrc\Plugin.php:70
authwp_ajax_request_shipmentssrc\Plugin.php:71
authwp_ajax_request_statessrc\Plugin.php:72
authwp_ajax_wooss_reset_pluginsrc\Plugin.php:73
authwp_ajax_wooss_diagnosesrc\Plugin.php:74

REST API Routes 1

POST/wp-json/wooss/v2/shippingsrc\Webhook\Handler.php:8
WordPress Hooks 15
actionadmin_noticessrc\Plugin.php:30
actionwoocommerce_shipping_initsrc\Plugin.php:43
filterwoocommerce_shipping_methodssrc\Plugin.php:47
actionadmin_enqueue_scriptssrc\Plugin.php:59
actionadmin_enqueue_scriptssrc\Plugin.php:60
actionwoocommerce_settings_tabs_shippingsrc\Plugin.php:63
actionadd_meta_boxessrc\Plugin.php:66
actionwoocommerce_thankyousrc\Plugin.php:79
actionrest_api_initsrc\Plugin.php:84
actionwoocommerce_blocks_loadedsrc\Plugin.php:88
actionwoocommerce_blocks_checkout_block_registrationsrc\Plugin.php:90
actionwoocommerce_blocks_cart_block_registrationsrc\Plugin.php:96
actionadmin_initsrc\Plugin.php:107
actionbefore_woocommerce_initwooss.php:34
actionplugins_loadedwooss.php:63
Maintenance & Trust

Sendbox-Shipping Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 11, 2026
PHP min version7.4
Downloads4K

Community Trust

Rating100/100
Number of ratings3
Active installs40
Developer Profile

Sendbox-Shipping Developer Profile

sendbox

1 plugin · 40 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sendbox-Shipping

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sendbox-shipping/assets/css/admin-order.css/wp-content/plugins/sendbox-shipping/assets/css/admin-settings.css/wp-content/plugins/sendbox-shipping/assets/js/admin-order.js/wp-content/plugins/sendbox-shipping/assets/js/admin-settings.js
Script Paths
/wp-content/plugins/sendbox-shipping/assets/js/admin-order.js/wp-content/plugins/sendbox-shipping/assets/js/admin-settings.js
Version Parameters
sendbox-shipping/assets/css/admin-order.css?ver=sendbox-shipping/assets/css/admin-settings.css?ver=sendbox-shipping/assets/js/admin-order.js?ver=sendbox-shipping/assets/js/admin-settings.js?ver=

HTML / DOM Fingerprints

JS Globals
wooss_ajax
REST Endpoints
/wp-json/wooss/v2/shipping
FAQ

Frequently Asked Questions about Sendbox-Shipping