Shipping-Based Products for woocommerce and Ali2Woo Security & Risk Analysis

wordpress.org/plugins/shipment-based-product-for-ali2woo

Hide the “add to cart” button for products imported from ALiexpress and which have no shipping methods for the customer's delivery address.

10 active installs v1.0.2 PHP 5.3+ WP 5.3.2+ Updated Nov 19, 2024
aliexpressdropshipdropshippingwoowoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Shipping-Based Products for woocommerce and Ali2Woo Safe to Use in 2026?

Generally Safe

Score 92/100

Shipping-Based Products for woocommerce and Ali2Woo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The static analysis of "shipment-based-product-for-ali2woo" v1.0.2 indicates a strong security posture in terms of identified code signals. The absence of dangerous functions, properly escaped output, and the exclusive use of prepared statements for SQL queries are all positive indicators. Furthermore, the zero-count for file operations and external HTTP requests, coupled with no reported CVEs or vulnerability history, suggests a mature and secure codebase. The lack of any taint analysis findings further reinforces this impression, indicating no identified pathways for unsanitized data to reach sensitive sinks.

However, a significant concern arises from the complete absence of capability checks and nonce checks. While the current attack surface appears to be zero, this lack of authorization and CSRF protection means that if any new entry points were introduced in future versions without proper checks, they would be immediately unprotected and vulnerable. The static analysis revealing zero entry points is a strength, but the fundamental lack of foundational security checks like nonce and capability checks represents a potential weakness that could be exploited if the attack surface were to change.

In conclusion, the plugin exhibits excellent coding practices regarding data handling and SQL security. The lack of historical vulnerabilities is a very positive sign. The primary area of concern is the complete absence of authorization and CSRF protection mechanisms. While not exploitable with the current zero-attack-surface, this is a critical omission that leaves the plugin susceptible to future attacks should new entry points be added without these safeguards.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Shipping-Based Products for woocommerce and Ali2Woo Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Shipping-Based Products for woocommerce and Ali2Woo Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped8 total outputs
Attack Surface

Shipping-Based Products for woocommerce and Ali2Woo Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
actionwp_enqueue_scriptsincludes\class-wc-ali-front.php:17
actionwoocommerce_single_product_summaryincludes\class-wc-ali-front.php:18
actionwoocommerce_simple_add_to_cartincludes\class-wc-ali-front.php:29
actionwoocommerce_variable_add_to_cartincludes\class-wc-ali-front.php:30
actionwoocommerce_grouped_add_to_cartincludes\class-wc-ali-front.php:31
actionwoocommerce_external_add_to_cartincludes\class-wc-ali-front.php:32
actionadmin_menuincludes\class-wc-ali-settings.php:53
actionadmin_initincludes\class-wc-ali-settings.php:54
actionadmin_enqueue_scriptsincludes\class-wc-ali-settings.php:55
actionadmin_initwc-aliexpress-shipping-based-product.php:77
actionadmin_initwc-aliexpress-shipping-based-product.php:79
actionadmin_noticeswc-aliexpress-shipping-based-product.php:81
actionplugins_loadedwc-aliexpress-shipping-based-product.php:83
actioninitwc-aliexpress-shipping-based-product.php:85
actionwpwc-aliexpress-shipping-based-product.php:252
Maintenance & Trust

Shipping-Based Products for woocommerce and Ali2Woo Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 19, 2024
PHP min version5.3
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Shipping-Based Products for woocommerce and Ali2Woo Developer Profile

Younes

5 plugins · 180 total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Shipping-Based Products for woocommerce and Ali2Woo

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shipment-based-product-for-ali2woo/assets/js/frontend.js/wp-content/plugins/shipment-based-product-for-ali2woo/assets/css/frontend.css
Script Paths
/wp-content/plugins/shipment-based-product-for-ali2woo/assets/js/frontend.js
Version Parameters
/wp-content/plugins/shipment-based-product-for-ali2woo/assets/js/frontend.js?ver=/wp-content/plugins/shipment-based-product-for-ali2woo/assets/css/frontend.css?ver=

HTML / DOM Fingerprints

CSS Classes
wc-ali-shipping-method-product-wrapper
JS Globals
wc_ali_frontend_params
FAQ

Frequently Asked Questions about Shipping-Based Products for woocommerce and Ali2Woo