
Shipit Security & Risk Analysis
wordpress.org/plugins/shipitShipit Calculator Mensajeros de envío
Is Shipit Safe to Use in 2026?
Generally Safe
Score 100/100Shipit has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "shipit" plugin version 9.6.1 exhibits a generally positive security posture based on the static analysis provided. It boasts a contained attack surface with all identified entry points (REST API routes and cron events) either lacking authentication checks or having them in place. Furthermore, the absence of known CVEs and a clean vulnerability history are strong indicators of responsible development and patching practices. The plugin also avoids dangerous functions and file operations, which are common vectors for exploitation.
However, several areas warrant attention and represent potential weaknesses. The significant number of SQL queries (20) with only 5% using prepared statements is a considerable risk, exposing the plugin to SQL injection vulnerabilities. Similarly, the low percentage of properly escaped output (26%) suggests a high likelihood of cross-site scripting (XSS) vulnerabilities. The complete lack of nonce checks, while not directly tied to AJAX handlers in this analysis, is a concerning omission for general WordPress security best practices. The plugin also makes external HTTP requests, which could be a vector for SSRF if not handled with extreme care and validation.
Key Concerns
- Low percentage of prepared statements for SQL queries
- Low percentage of properly escaped output
- No nonce checks implemented
- External HTTP requests made
Shipit Security Vulnerabilities
Shipit Code Analysis
SQL Query Safety
Output Escaping
Shipit Attack Surface
REST API Routes 4
WordPress Hooks 46
Scheduled Events 2
Maintenance & Trust
Shipit Maintenance & Trust
Maintenance Signals
Community Trust
Shipit Alternatives
Cost Calculator Builder
cost-calculator-builder
WP Cost Calculator is a simple and powerful tool that lets you create price estimation forms. Easily give your clients information about your services …
Easyship WooCommerce Shipping Rates
easyship-woocommerce-shipping-rates
Easyship for WooCommerce saves you time and money with live courier rates, seamless checkout, automated taxes & duties, and shipping label creation.
WooReer
wcsdm
WooReer calculates shipping rates based on distance via Google Maps, Mapbox, DistanceMatrix.ai, Geoapify, or HERE.
Product page shipping calculator for WooCommerce
product-page-shipping-calculator-for-woocommerce
This plugin allows you to show the shipping methods available on the product page for WooCommerce, so customers can see if shipping is available to th …
Shippit for WooCommerce
shippit-simplified-australia-shipping
Multi-carrier shipping technology.
Shipit Developer Profile
1 plugin · 400 total installs
How We Detect Shipit
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shipit/shipit.php/wp-content/plugins/shipit/src/class.settings-api.php/wp-content/plugins/shipit/src/shipit_service/http_client.php/wp-content/plugins/shipit/src/shipit_service/core.php/wp-content/plugins/shipit/src/shipit_service/opit.php/wp-content/plugins/shipit/src/shipit_service/integration.php+31 moreHTML / DOM Fingerprints
Shipit_Settings_Admin