Shipping Calculator Customizer for WooCommerce Security & Risk Analysis

wordpress.org/plugins/shipping-calculator-customizer-for-woocommerce

Customize WooCommerce shipping calculator on cart page. Beautifully.

10 active installs v2.0.1 PHP + WP 4.4+ Updated May 24, 2025
calculatorshippingshipping-calculatorwoo-commercewoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Shipping Calculator Customizer for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Shipping Calculator Customizer for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12mo ago
Risk Assessment

The plugin "shipping-calculator-customizer-for-woocommerce" v2.0.1 exhibits a seemingly strong security posture based on the provided static analysis results. The absence of any identified dangerous functions, SQL queries using prepared statements, file operations, or external HTTP requests is a positive indicator. Furthermore, the zero reported CVEs and lack of past vulnerabilities suggest a history of security consciousness from the developers. The attack surface is reported as zero, with no AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the potential for external exploitation.

However, there are significant concerns arising from the analysis. The fact that there are zero capability checks and zero nonce checks across all entry points (even though the attack surface is reported as zero) is a critical oversight. If any entry points were to be discovered or introduced in future versions, their lack of authentication and authorization checks would create immediate vulnerabilities. Additionally, the low rate of properly escaped output (33%) indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data may be directly reflected in the output without proper sanitization.

While the plugin has a clean vulnerability history and appears to use secure practices for database interactions, the identified weaknesses in output escaping and the complete absence of capability and nonce checks are serious flaws. The reported zero attack surface might be misleading if not meticulously verified, and even with a zero attack surface, the identified output sanitization issue remains a pressing concern. A comprehensive security audit focusing on the identified output escaping concerns and exploring potential undiscovered entry points is highly recommended.

Key Concerns

  • Low rate of properly escaped output
  • Zero capability checks
  • Zero nonce checks
Vulnerabilities
None known

Shipping Calculator Customizer for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Shipping Calculator Customizer for WooCommerce Release Timeline

v2.0.1Current
v2.0.0
Code Analysis
Analyzed Apr 16, 2026

Shipping Calculator Customizer for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

33% escaped3 total outputs
Attack Surface

Shipping Calculator Customizer for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
filterwoocommerce_shipping_show_shipping_calculatorincludes/class-alg-wc-scc-core.php:26
filterwoocommerce_shipping_calculator_enable_countryincludes/class-alg-wc-scc-core.php:33
filterwoocommerce_shipping_calculator_enable_stateincludes/class-alg-wc-scc-core.php:38
filterwoocommerce_shipping_calculator_enable_cityincludes/class-alg-wc-scc-core.php:43
filterwoocommerce_shipping_calculator_enable_postcodeincludes/class-alg-wc-scc-core.php:48
actionwp_enqueue_scriptsincludes/class-alg-wc-scc-core.php:55
actionwp_enqueue_scriptsincludes/class-alg-wc-scc-core.php:61
actionwoocommerce_before_shipping_calculatorincludes/class-alg-wc-scc-core.php:67
actionwoocommerce_after_shipping_calculatorincludes/class-alg-wc-scc-core.php:71
actioninitincludes/class-alg-wc-scc.php:73
actionbefore_woocommerce_initincludes/class-alg-wc-scc.php:76
filterwoocommerce_get_settings_pagesincludes/class-alg-wc-scc.php:155
actionadmin_initincludes/class-alg-wc-scc.php:159
filterwoocommerce_get_sections_alg_wc_shipping_calculator_customizerincludes/settings/class-alg-wc-scc-settings-section.php:40
actionadmin_noticesincludes/settings/class-alg-wc-settings-scc.php:82
actionplugins_loadedshipping-calculator-customizer-for-woocommerce.php:58
Maintenance & Trust

Shipping Calculator Customizer for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 24, 2025
PHP min version
Downloads394

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Shipping Calculator Customizer for WooCommerce Developer Profile

Algoritmika

15 plugins · 510 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Shipping Calculator Customizer for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shipping-calculator-customizer-for-woocommerce/includes/css/alg-wc-shipping-calculator.css/wp-content/plugins/shipping-calculator-customizer-for-woocommerce/includes/js/alg-wc-shipping-calculator.js/wp-content/plugins/shipping-calculator-customizer-for-woocommerce/includes/css/alg-wc-shipping-calculator-force-block-open.css
Version Parameters
shipping-calculator-customizer-for-woocommerce/includes/css/alg-wc-shipping-calculator.css?ver=shipping-calculator-customizer-for-woocommerce/includes/js/alg-wc-shipping-calculator.js?ver=shipping-calculator-customizer-for-woocommerce/includes/css/alg-wc-shipping-calculator-force-block-open.css?ver=

HTML / DOM Fingerprints

CSS Classes
shipping-calculator-button
JS Globals
alg_wc_shipping_calculator_object
FAQ

Frequently Asked Questions about Shipping Calculator Customizer for WooCommerce