
Shipping by Rules for WooCommerce Security & Risk Analysis
wordpress.org/plugins/shipping-by-rules-for-woocommerceDescribe (even complex) shipping costs with simple general rules on the order properties (amount, postcode, weight, #products and/or articles etc.).
Is Shipping by Rules for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100Shipping by Rules for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "shipping-by-rules-for-woocommerce" v2.0.6 plugin exhibits a mixed security posture. On the positive side, it demonstrates strong practices regarding SQL queries, utilizing prepared statements exclusively, and shows a good adherence to nonce and capability checks for its entry points. There are no identified critical or high severity taint flows, and the absence of known vulnerabilities in its history is also encouraging. However, a significant concern arises from its attack surface. The plugin exposes two AJAX handlers, both of which lack authentication checks. This represents a clear risk, as any unauthenticated user could potentially interact with these handlers. While the taint analysis found no critical or high severity issues, the presence of flows with unsanitized paths, even if not immediately exploitable to critical levels, warrants attention as it indicates potential avenues for unexpected behavior or information leakage. The 71% output escaping rate, while not critically low, suggests that there are still opportunities for cross-site scripting (XSS) vulnerabilities if untrusted data is being rendered without proper sanitization. In conclusion, the plugin has several strong security foundations, particularly in database interaction and internal authorization mechanisms. Nevertheless, the unprotected AJAX endpoints are a notable weakness that requires immediate attention to prevent potential exploits. The partial output escaping also presents a moderate risk that should be addressed.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths found
- Output escaping is not 100%
Shipping by Rules for WooCommerce Security Vulnerabilities
Shipping by Rules for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
Shipping by Rules for WooCommerce Attack Surface
AJAX Handlers 2
WordPress Hooks 23
Maintenance & Trust
Shipping by Rules for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Shipping by Rules for WooCommerce Alternatives
Advanced Shipment Tracking for WooCommerce
woo-advanced-shipment-tracking
Add shipment tracking info to WooCommerce orders, send tracking numbers to customers via email, and let them track deliveries from My Account.
Shiprocket
shiprocket
Auto Sync your Woocommerce store orders & ship them at lowest shipping rates. Automate your shipping, save time & money.
Shiptastic for WooCommerce
shiptastic-for-woocommerce
Shiptastic for WooCommerce is your all-in-one shipping and fulfillment solution for WooCommerce.
AfterShip Tracking – All-In-One WooCommerce Order Tracking (Free plan available)
aftership-woocommerce-tracking
Track orders in one place. shipment tracking, automated notifications, order lookup, branded tracking page, delivery day prediction
Partial Shipment for Woocommerce
wc-partial-shipment
Partially ship an order in woocommerce and display shipment details on view order page.
Shipping by Rules for WooCommerce Developer Profile
1 plugin · 500 total installs
How We Detect Shipping by Rules for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shipping-by-rules-for-woocommerce/js/admin.js/wp-content/plugins/shipping-by-rules-for-woocommerce/css/admin.css/wp-content/plugins/shipping-by-rules-for-woocommerce/js/admin.jsshipping-by-rules-for-woocommerce/js/admin.js?ver=shipping-by-rules-for-woocommerce/css/admin.css?ver=HTML / DOM Fingerprints
shipping_by_rules_settingsONLY IN BASIC VERSION: Purchase linkvar openshipping_admin_params