ShipBlink: EasyPost Live Checkout Rates & Labels Security & Risk Analysis

wordpress.org/plugins/shipblink-easypost-live-checkout-rates-labels

Simplifying ecommerce shipping for WooCommerce merchants. Live Checkout Rates, Batch Labels powered by EasyPost

40 active installs v1.0.4 PHP 7.2+ WP 4.0+ Updated Jan 15, 2026
batch-labelscheckout-ratesshippingweight-based-shippingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is ShipBlink: EasyPost Live Checkout Rates & Labels Safe to Use in 2026?

Generally Safe

Score 100/100

ShipBlink: EasyPost Live Checkout Rates & Labels has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The static analysis of the "shipblink-easypost-live-checkout-rates-labels" v1.0.4 plugin reveals a generally strong security posture. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly minimizes the plugin's attack surface. The code also demonstrates good practices by not utilizing dangerous functions, performing all SQL queries using prepared statements, and properly escaping all identified output. Furthermore, there are no file operations or indications of taint flows, suggesting a lack of common vulnerabilities related to data handling and file manipulation. The absence of any recorded vulnerabilities, past or present, further supports this positive assessment.

However, a notable concern arises from the complete absence of nonce checks and capability checks. This means that any functionality exposed by the plugin, even if it's not explicitly listed in the attack surface metrics, might be callable by unauthenticated or unauthorized users. While the current attack surface is zero, any future additions or hidden functionalities could be exploited without proper authorization mechanisms. The plugin also makes three external HTTP requests, which, while not inherently a vulnerability, represent potential vectors for issues like Server-Side Request Forgery (SSRF) if not handled with extreme care regarding the URLs being requested and the data they might process. The plugin also bundles no libraries, which is good in that it avoids known vulnerabilities in outdated bundled code, but it also means the plugin relies entirely on the WordPress core and potentially other themes/plugins for its dependencies.

In conclusion, the plugin exhibits excellent coding practices in terms of SQL, output escaping, and avoiding dangerous functions. Its minimal attack surface is a significant strength. The primary weakness lies in the lack of authorization checks, which could become a critical issue if new functionalities are added without them. The external HTTP requests, while not a direct vulnerability in this analysis, warrant careful monitoring and secure implementation.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • External HTTP requests present
Vulnerabilities
None known

ShipBlink: EasyPost Live Checkout Rates & Labels Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ShipBlink: EasyPost Live Checkout Rates & Labels Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

100% escaped3 total outputs
Attack Surface

ShipBlink: EasyPost Live Checkout Rates & Labels Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actioncurrent_screenshipblink-easypost-live-checkout-rates-labels.php:28
actionwoocommerce_shipping_initshipblink-easypost-live-checkout-rates-labels.php:42
filterwoocommerce_shipping_methodsshipblink-easypost-live-checkout-rates-labels.php:53
actionadmin_noticessrc\class-selcrlshipblinkmerchantchecker.php:33
actionwoocommerce_after_shipping_ratesrc\class-selcrlwcshipblinkmethod.php:71
Maintenance & Trust

ShipBlink: EasyPost Live Checkout Rates & Labels Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 15, 2026
PHP min version7.2
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs40
Developer Profile

ShipBlink: EasyPost Live Checkout Rates & Labels Developer Profile

Sam (ShipBlink)

1 plugin · 40 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ShipBlink: EasyPost Live Checkout Rates & Labels

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shipblink-easypost-live-checkout-rates-labels/assets/css/shipblink-selcrl-admin.css/wp-content/plugins/shipblink-easypost-live-checkout-rates-labels/assets/css/shipblink-selcrl-frontend.css/wp-content/plugins/shipblink-easypost-live-checkout-rates-labels/assets/js/shipblink-selcrl-admin.js/wp-content/plugins/shipblink-easypost-live-checkout-rates-labels/assets/js/shipblink-selcrl-frontend.js
Version Parameters
shipblink-easypost-live-checkout-rates-labels/assets/css/shipblink-selcrl-admin.css?ver=shipblink-easypost-live-checkout-rates-labels/assets/css/shipblink-selcrl-frontend.css?ver=shipblink-easypost-live-checkout-rates-labels/assets/js/shipblink-selcrl-admin.js?ver=shipblink-easypost-live-checkout-rates-labels/assets/js/shipblink-selcrl-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
shipblink-selcrl-admin-cssshipblink-selcrl-frontend-css
FAQ

Frequently Asked Questions about ShipBlink: EasyPost Live Checkout Rates & Labels