Shift8 Woocommerce Postal Blocker Security & Risk Analysis

wordpress.org/plugins/shift8-woocommerce-postal-blocker

Plugin that allows you to input a list of postal / zip codes to block from ordering on your Woocommerce site. You can determine if you want to hide a …

10 active installs v1.04 PHP + WP 3.0.1+ Updated Jul 17, 2019
blacklistblockpostalwoocommercewoocommerce-blacklist
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Shift8 Woocommerce Postal Blocker Safe to Use in 2026?

Generally Safe

Score 85/100

Shift8 Woocommerce Postal Blocker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "shift8-woocommerce-postal-blocker" plugin v1.04 exhibits an exceptionally clean static analysis profile. The absence of any detected dangerous functions, direct SQL queries, file operations, or external HTTP requests, coupled with 100% proper output escaping and the lack of taint flows, suggests a strong adherence to secure coding practices. The plugin also has no recorded vulnerability history, indicating a stable and well-maintained codebase. Furthermore, the attack surface appears to be zero, with no AJAX handlers, REST API routes, shortcodes, or cron events, meaning there are no readily available entry points for external interaction. The complete lack of capability checks and nonce checks, while not ideal in isolation, is less concerning given the absence of any discernible attack surface or sensitive operations. Overall, this plugin presents a very low security risk based on the provided data.

Vulnerabilities
None known

Shift8 Woocommerce Postal Blocker Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Shift8 Woocommerce Postal Blocker Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Shift8 Woocommerce Postal Blocker Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped9 total outputs
Attack Surface

Shift8 Woocommerce Postal Blocker Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_enqueue_scriptscomponents/enqueuing.php:17
filterwoocommerce_available_payment_gatewayscomponents/functions.php:35
filterwoocommerce_settings_tabs_arraycomponents/settings.php:14
actionwoocommerce_settings_tabs_settings_tab_shift8components/settings.php:15
actionwoocommerce_update_options_settings_tab_shift8components/settings.php:16
actionadmin_noticesshift8-wooblock.php:26
Maintenance & Trust

Shift8 Woocommerce Postal Blocker Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedJul 17, 2019
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Shift8 Woocommerce Postal Blocker Developer Profile

shift8

16 plugins · 950 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Shift8 Woocommerce Postal Blocker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shift8-woocommerce-postal-blocker/components/css/shift8_wooblock_admin.css/wp-content/plugins/shift8-woocommerce-postal-blocker/components/js/shift8_wooblock_admin.js
Script Paths
/wp-content/plugins/shift8-woocommerce-postal-blocker/components/js/shift8_wooblock_admin.js
Version Parameters
shift8_wooblock_cssshift8_wooblock_script

HTML / DOM Fingerprints

JS Globals
the_ajax_script
FAQ

Frequently Asked Questions about Shift8 Woocommerce Postal Blocker