Ship2Anywhere Plugin Security & Risk Analysis

wordpress.org/plugins/ship-2-anywhere

Ship2Anywhere Multi Carrier Shipping and Logistics Technology able to seamlessly integrate into your Woo cart.

0 active installs v1.0.1 PHP + WP 4.4+ Updated Jun 9, 2022
e-commerceecommercesalessellstore
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Ship2Anywhere Plugin Safe to Use in 2026?

Generally Safe

Score 85/100

Ship2Anywhere Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "ship-2-anywhere" v1.0.1 plugin exhibits a generally strong security posture based on the provided static analysis. There are no identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication or proper permission checks. The code also avoids dangerous functions and file operations, and all SQL queries are executed using prepared statements. This indicates a good understanding of secure coding practices regarding data access and interaction with WordPress core functionalities.

However, there are a couple of areas that present potential concerns. The low percentage of properly escaped output (62%) suggests a risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is not consistently sanitized before being displayed. Additionally, the presence of external HTTP requests, while not inherently insecure, warrants careful review to ensure these requests are not being made to untrusted sources or in a way that could be manipulated. The complete lack of recorded vulnerability history is a positive indicator, suggesting a history of responsible development or a lack of targeted attacks. Despite the minor concerns with output escaping and external requests, the plugin's overall design, with no apparent attack surface and secure data handling, presents a relatively low risk profile.

Key Concerns

  • Low percentage of output escaping
  • Presence of external HTTP requests
Vulnerabilities
None known

Ship2Anywhere Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Ship2Anywhere Plugin Release Timeline

v1.0.1Current
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

Ship2Anywhere Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
13 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

62% escaped21 total outputs
Attack Surface

Ship2Anywhere Plugin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 18
actionadmin_initincludes\class-ship2anywhere-custom-order-fields-shop-order.php:6
filtermanage_edit-shop_order_columnsincludes\class-ship2anywhere-custom-order-fields-shop-order.php:7
filtermanage_shop_order_posts_custom_columnincludes\class-ship2anywhere-custom-order-fields-shop-order.php:8
actionadmin_menuincludes\class-ship2anywhere-custom-order-fields.php:16
actionwoocommerce_email_after_order_tableincludes\class-ship2anywhere-custom-order-fields.php:17
actionwp_insert_postincludes\class-ship2anywhere-custom-order-fields.php:18
filterwoocommerce_shipping_methodsincludes\class-ship2anywhere-shipping-rules.php:19
filterwoocommerce_rest_prepare_product_objectincludes\class-ship2anywhere-webhook.php:6
actionwoocommerce_webhook_payloadincludes\class-ship2anywhere-webhook.php:7
actionplugin_loadedincludes\class-ship2anywhere.php:39
actionadmin_enqueue_scriptsincludes\class-ship2anywhere.php:46
actionadmin_enqueue_scriptsincludes\class-ship2anywhere.php:47
actionplugins_loadedincludes\class-ship2anywhere.php:48
filterplugin_row_metaincludes\class-ship2anywhere.php:51
actionwp_enqueue_scriptsincludes\class-ship2anywhere.php:58
actionwp_enqueue_scriptsincludes\class-ship2anywhere.php:59
actionplugins_loadedincludes\class-ship2anywhere.php:60
filterwoocommerce_default_address_fieldspublic\class-ship2anywhere-public.php:33
Maintenance & Trust

Ship2Anywhere Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJun 9, 2022
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Ship2Anywhere Plugin Developer Profile

developership2anywhere

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ship2Anywhere Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ship-2-anywhere/admin/css/ship2anywhere-admin.css/wp-content/plugins/ship-2-anywhere/public/css/ship2anywhere-public.css/wp-content/plugins/ship-2-anywhere/public/js/ship2anywhere-public.js
Script Paths
/wp-content/plugins/ship-2-anywhere/admin/js/ship2anywhere-admin.js
Version Parameters
ship2anywhere-admin.css?ver=ship2anywhere-public.css?ver=ship2anywhere-admin.js?ver=ship2anywhere-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
ship2anywhere-admin-wrap
Data Attributes
data-plugin-name="ship2anywhere"data-plugin-version="1.0.1"
JS Globals
ship2anywhere_public_ajax_object
REST Endpoints
/wp-json/ship2anywhere/v1/shipping-methods
Shortcode Output
[ship2anywhere_shipping_widget]
FAQ

Frequently Asked Questions about Ship2Anywhere Plugin