Shipi – Multi-Carrier Shipping Plugin for WooCommerce Security & Risk Analysis

wordpress.org/plugins/shipi

🚀 Ship smarter and faster! Shipi helps you connect global shipping carriers with WooCommerce for real-time rates, shipping label generation, and track …

10 active installs v1.3.2 PHP 5.6+ WP 4.0.1+ Updated Feb 10, 2026
dhlfedexshipping-labelshipping-rateswoocommerce-shipping
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Shipi – Multi-Carrier Shipping Plugin for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Shipi – Multi-Carrier Shipping Plugin for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "shipi" plugin version 1.3.2 exhibits a generally strong security posture based on the provided static analysis. A significant strength is the absence of any identified vulnerabilities in its history, suggesting a history of responsible development and security practices. Furthermore, the code analysis reveals a clean slate with no dangerous functions, no raw SQL queries, and no file operations, all of which are excellent indicators of secure coding. The high percentage of properly escaped output (92%) and the presence of nonce checks further bolster its security. However, there are minor areas for improvement. The plugin does have an attack surface with 4 entry points, and while they are reported as protected, the absence of capability checks on these points is a potential weakness. It's crucial to ensure that these entry points are robustly protected against unauthorized access, even if initial checks are in place. The external HTTP requests, while not inherently a vulnerability, represent an area where careful validation of the remote source would be paramount to prevent potential supply chain attacks. In conclusion, "shipi" v1.3.2 is a well-developed plugin from a security perspective, but the lack of explicit capability checks on its entry points warrants attention to ensure comprehensive protection.

Key Concerns

  • No capability checks on entry points
Vulnerabilities
None known

Shipi – Multi-Carrier Shipping Plugin for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Shipi – Multi-Carrier Shipping Plugin for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
66 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
5
Bundled Libraries
0

Output Escaping

92% escaped72 total outputs
Attack Surface

Shipi – Multi-Carrier Shipping Plugin for WooCommerce Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 3

authwp_ajax_get_order_details_shipishipi.php:101
authwp_ajax_get_tracking_shipishipi.php:102
authwp_ajax_shipi_connect_accountshipi.php:105

REST API Routes 1

POST/wp-json/shipi/v1/update-shipment/includes\rest-api.php:14
WordPress Hooks 21
actionrest_api_initincludes\rest-api.php:10
filterwoocommerce_shipping_methodsincludes\shipping-class.php:148
actionbefore_woocommerce_initshipi.php:23
actionwoocommerce_shipping_initshipi.php:82
actionadd_meta_boxesshipi.php:87
actionadmin_menushipi.php:88
filtermanage_woocommerce_page_wc-orders_columnsshipi.php:91
actionmanage_woocommerce_page_wc-orders_custom_columnshipi.php:92
filtermanage_edit-shop_order_columnsshipi.php:94
actionmanage_shop_order_posts_custom_columnshipi.php:95
actionwoocommerce_thankyoushipi.php:97
actionwoocommerce_order_details_after_order_tableshipi.php:98
actionadmin_enqueue_scriptsshipi.php:99
actionadmin_footershipi.php:100
actionwoocommerce_admin_order_data_after_shipping_addressshipi.php:103
actionadd_meta_boxesshipi.php:104
actionwoocommerce_product_options_general_product_datashipi.php:108
actionwoocommerce_process_product_metashipi.php:110
actionwoocommerce_product_after_variable_attributesshipi.php:113
actionwoocommerce_save_product_variationshipi.php:115
actionwp_initialize_siteshipi.php:1394
Maintenance & Trust

Shipi – Multi-Carrier Shipping Plugin for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 10, 2026
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Shipi – Multi-Carrier Shipping Plugin for WooCommerce Developer Profile

Aarsiv Groups

10 plugins · 610 total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Shipi – Multi-Carrier Shipping Plugin for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shipi/assets/css/admin.css/wp-content/plugins/shipi/assets/js/admin.js
Script Paths
/wp-content/plugins/shipi/assets/js/admin.js
Version Parameters
shipi/style.css?ver=shipi/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
shipi-settingsshipi-configuration-page
Data Attributes
data-shipi-order-id
JS Globals
shipi_ajax_objectshipi_vars
REST Endpoints
/wp-json/shipi/v1/connect-account/wp-json/shipi/v1/get-order-details/wp-json/shipi/v1/get-tracking
FAQ

Frequently Asked Questions about Shipi – Multi-Carrier Shipping Plugin for WooCommerce