
ShipBob Express Rates Security & Risk Analysis
wordpress.org/plugins/shipbob-express-ratesDynamically provide an affordable two-day ground shipping option for customers who qualify for it.
Is ShipBob Express Rates Safe to Use in 2026?
Generally Safe
Score 92/100ShipBob Express Rates has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "shipbob-express-rates" plugin v2.7.0 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL queries, exclusively using prepared statements, and has a clean vulnerability history with no recorded CVEs. The absence of critical or high severity taint flows and dangerous functions is also encouraging.
However, there are notable concerns. The taint analysis revealed four flows with unsanitized paths, all classified as high severity, indicating potential risks. While the attack surface appears minimal with zero entry points detected, the static analysis also flagged zero nonce checks and zero capability checks across the plugin. This absence of robust authorization and input validation mechanisms, especially in conjunction with the identified unsanitized path flows, represents a significant weakness. The low percentage of properly escaped output (79%) further adds to the potential for cross-site scripting (XSS) vulnerabilities.
In conclusion, while the plugin benefits from a lack of known historical vulnerabilities and secure SQL practices, the presence of high-severity taint flows with unsanitized paths and the pervasive lack of authorization and output escaping checks are significant security concerns that require immediate attention. The plugin's potential attack surface may be larger than initially indicated by the reported zero entry points, given the findings in taint analysis and output escaping.
Key Concerns
- High severity taint flows with unsanitized paths
- Unescaped output found (21% of total outputs)
- Zero capability checks
- Zero nonce checks
ShipBob Express Rates Security Vulnerabilities
ShipBob Express Rates Code Analysis
Output Escaping
Data Flow Analysis
ShipBob Express Rates Attack Surface
WordPress Hooks 14
Maintenance & Trust
ShipBob Express Rates Maintenance & Trust
Maintenance Signals
Community Trust
ShipBob Express Rates Alternatives
Plugin BlueX for WooCommerce
bluex-for-woocommerce
Once the plugin is installed, you need to go to the integration section in the woocommerce settings and add the data delivered by blue express. Also,
Shipping Live Rates for DHL Express for WooCommerce
flexible-shipping-dhl-express
Display real-time DHL Express shipping live rates in your WooCommerce store. Connect with DHL Express API for accurate shipping costs.
Shipi – DHL Express Integration for Woocommerce
a2z-dhl-express-shipping
Seamless DHL Express WooCommerce integration - live rates, automated/manual labels, return labels, pickups, invoices, and tracking.
Printful Integration for WooCommerce
printful-shipping-for-woocommerce
Grow your store with the top print-on-demand dropshipping plugin
WC Hide Shipping Methods
wc-hide-shipping-methods
This plugin automatically hides all other shipping methods when "Free Shipping" is available, while allowing you to retain "Local Picku …
ShipBob Express Rates Developer Profile
1 plugin · 60 total installs
How We Detect ShipBob Express Rates
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shipbob-express-rates/assets/css/shipbob-express-rates.css/wp-content/plugins/shipbob-express-rates/assets/js/shipbob-express-rates.js/wp-content/plugins/shipbob-express-rates/assets/js/shipbob-express-rates.jsshipbob-express-rates/assets/css/shipbob-express-rates.css?ver=shipbob-express-rates/assets/js/shipbob-express-rates.js?ver=