ShipBob Express Rates Security & Risk Analysis

wordpress.org/plugins/shipbob-express-rates

Dynamically provide an affordable two-day ground shipping option for customers who qualify for it.

60 active installs v2.7.0 PHP 7.0+ WP 4.7+ Updated May 20, 2024
expressratesshipbobshippingwoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ShipBob Express Rates Safe to Use in 2026?

Generally Safe

Score 92/100

ShipBob Express Rates has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "shipbob-express-rates" plugin v2.7.0 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL queries, exclusively using prepared statements, and has a clean vulnerability history with no recorded CVEs. The absence of critical or high severity taint flows and dangerous functions is also encouraging.

However, there are notable concerns. The taint analysis revealed four flows with unsanitized paths, all classified as high severity, indicating potential risks. While the attack surface appears minimal with zero entry points detected, the static analysis also flagged zero nonce checks and zero capability checks across the plugin. This absence of robust authorization and input validation mechanisms, especially in conjunction with the identified unsanitized path flows, represents a significant weakness. The low percentage of properly escaped output (79%) further adds to the potential for cross-site scripting (XSS) vulnerabilities.

In conclusion, while the plugin benefits from a lack of known historical vulnerabilities and secure SQL practices, the presence of high-severity taint flows with unsanitized paths and the pervasive lack of authorization and output escaping checks are significant security concerns that require immediate attention. The plugin's potential attack surface may be larger than initially indicated by the reported zero entry points, given the findings in taint analysis and output escaping.

Key Concerns

  • High severity taint flows with unsanitized paths
  • Unescaped output found (21% of total outputs)
  • Zero capability checks
  • Zero nonce checks
Vulnerabilities
None known

ShipBob Express Rates Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ShipBob Express Rates Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
30 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

79% escaped38 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
get_input (app\Services\Request.php:102)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ShipBob Express Rates Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actionadmin_initapp\Controllers\AdminController.php:24
actionadmin_menuapp\Controllers\AdminController.php:27
actionadmin_initapp\Controllers\AdminController.php:30
actionadmin_initapp\Controllers\InstallController.php:75
actionwoocommerce_shipping_initapp\Controllers\PluginController.php:71
actionwoocommerce_order_status_completedapp\Controllers\PluginController.php:72
filterscript_loader_tagapp\Controllers\PluginController.php:85
filterstyle_loader_tagapp\Controllers\PluginController.php:86
filterwoocommerce_shipping_methodsapp\Controllers\PluginController.php:89
actionplugins_loadedapp\Kernel.php:83
actioninitapp\Kernel.php:84
actionadmin_enqueue_scriptsapp\Services\Assets.php:176
actionwp_enqueue_scriptsapp\Services\Assets.php:178
actionadmin_initplugin.php:35
Maintenance & Trust

ShipBob Express Rates Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMay 20, 2024
PHP min version7.0
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

ShipBob Express Rates Developer Profile

shipbob

1 plugin · 60 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ShipBob Express Rates

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shipbob-express-rates/assets/css/shipbob-express-rates.css/wp-content/plugins/shipbob-express-rates/assets/js/shipbob-express-rates.js
Script Paths
/wp-content/plugins/shipbob-express-rates/assets/js/shipbob-express-rates.js
Version Parameters
shipbob-express-rates/assets/css/shipbob-express-rates.css?ver=shipbob-express-rates/assets/js/shipbob-express-rates.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about ShipBob Express Rates