
Shipping Calculator Customizer for WooCommerce Security & Risk Analysis
wordpress.org/plugins/shipping-calculator-customizer-for-woocommerceCustomize WooCommerce shipping calculator on cart page. Beautifully.
Is Shipping Calculator Customizer for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Shipping Calculator Customizer for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "shipping-calculator-customizer-for-woocommerce" v2.0.1 exhibits a seemingly strong security posture based on the provided static analysis results. The absence of any identified dangerous functions, SQL queries using prepared statements, file operations, or external HTTP requests is a positive indicator. Furthermore, the zero reported CVEs and lack of past vulnerabilities suggest a history of security consciousness from the developers. The attack surface is reported as zero, with no AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the potential for external exploitation.
However, there are significant concerns arising from the analysis. The fact that there are zero capability checks and zero nonce checks across all entry points (even though the attack surface is reported as zero) is a critical oversight. If any entry points were to be discovered or introduced in future versions, their lack of authentication and authorization checks would create immediate vulnerabilities. Additionally, the low rate of properly escaped output (33%) indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data may be directly reflected in the output without proper sanitization.
While the plugin has a clean vulnerability history and appears to use secure practices for database interactions, the identified weaknesses in output escaping and the complete absence of capability and nonce checks are serious flaws. The reported zero attack surface might be misleading if not meticulously verified, and even with a zero attack surface, the identified output sanitization issue remains a pressing concern. A comprehensive security audit focusing on the identified output escaping concerns and exploring potential undiscovered entry points is highly recommended.
Key Concerns
- Low rate of properly escaped output
- Zero capability checks
- Zero nonce checks
Shipping Calculator Customizer for WooCommerce Security Vulnerabilities
Shipping Calculator Customizer for WooCommerce Release Timeline
Shipping Calculator Customizer for WooCommerce Code Analysis
Output Escaping
Shipping Calculator Customizer for WooCommerce Attack Surface
WordPress Hooks 16
Maintenance & Trust
Shipping Calculator Customizer for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Shipping Calculator Customizer for WooCommerce Alternatives
Easyship WooCommerce Shipping Rates
easyship-woocommerce-shipping-rates
Easyship for WooCommerce saves you time and money with live courier rates, seamless checkout, automated taxes & duties, and shipping label creation.
Product page shipping calculator for WooCommerce
product-page-shipping-calculator-for-woocommerce
This plugin allows you to show the shipping methods available on the product page for WooCommerce, so customers can see if shipping is available to th …
WooReer
wcsdm
WooReer calculates shipping rates based on distance via Google Maps, Mapbox, DistanceMatrix.ai, Geoapify, or HERE.
Shipping Cost on Product Page Calculator for WooCommerce
octolize-shipping-cost-on-product-page
Display shipping costs on product pages. Allow customers to calculate shipping based on their address before checkout. Improve UX and boost sales!
Gellum Delivery Calculator for WooCommerce
gellum-delivery-calculator
Calculates shipping costs for WooCommerce based on GPS distance with GeoJSON limited areas. Shortcode [gellumdcw_map]
Shipping Calculator Customizer for WooCommerce Developer Profile
15 plugins · 510 total installs
How We Detect Shipping Calculator Customizer for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shipping-calculator-customizer-for-woocommerce/includes/css/alg-wc-shipping-calculator.css/wp-content/plugins/shipping-calculator-customizer-for-woocommerce/includes/js/alg-wc-shipping-calculator.js/wp-content/plugins/shipping-calculator-customizer-for-woocommerce/includes/css/alg-wc-shipping-calculator-force-block-open.cssshipping-calculator-customizer-for-woocommerce/includes/css/alg-wc-shipping-calculator.css?ver=shipping-calculator-customizer-for-woocommerce/includes/js/alg-wc-shipping-calculator.js?ver=shipping-calculator-customizer-for-woocommerce/includes/css/alg-wc-shipping-calculator-force-block-open.css?ver=HTML / DOM Fingerprints
shipping-calculator-buttonalg_wc_shipping_calculator_object