
Shipping Manager For WooCommerce Security & Risk Analysis
wordpress.org/plugins/shipping-manager-for-woocommerceEasily add custom cities with rates, convert city to dropdown, create WooCommerce shipping zones (Pro), hide checkout fields, rename labels
Is Shipping Manager For WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Shipping Manager For WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'shipping-manager-for-woocommerce' plugin v1.6.2 exhibits a generally strong security posture based on the provided static analysis. The absence of identified attack surface points like AJAX handlers, REST API routes, shortcodes, and cron events, especially without authentication checks, is a significant positive. Furthermore, the complete absence of direct SQL queries and the use of prepared statements for all queries indicate robust database interaction practices. The plugin also avoids file operations and external HTTP requests, which are common vectors for vulnerabilities.
However, there are a few areas that warrant attention. While the overall output escaping is reasonably good at 70%, the 30% of outputs that are not properly escaped could potentially lead to cross-site scripting (XSS) vulnerabilities if sensitive data is displayed without adequate sanitization. The taint analysis revealing one flow with unsanitized paths, even without a critical or high severity classification, suggests a potential, albeit minor, risk of data manipulation or unintended behavior if this flow is exploitable. The presence of bundled libraries, Select2 v3.4.8 and Freemius v1.0, which are older versions, could introduce vulnerabilities if known exploits exist for these specific versions, although no specific issues are flagged in the provided data. The complete lack of vulnerability history is a strong indicator of good past security practices, but it doesn't guarantee future immunity.
In conclusion, the plugin demonstrates good security fundamentals by minimizing its attack surface and employing safe database practices. The primary concerns are the unescaped outputs and the single unsanitized path identified in the taint analysis, which, although not critically severe, represent potential weaknesses. The use of outdated bundled libraries also represents a minor risk that should be monitored. The absence of any recorded CVEs is a positive indicator, suggesting a commitment to security from the developer, but the identified code signals still present a small attack surface for potential security issues.
Key Concerns
- Unsanitized path in taint analysis
- 30% of outputs not properly escaped
- Bundled outdated library (Select2 v3.4.8)
- Bundled outdated library (Freemius v1.0)
Shipping Manager For WooCommerce Security Vulnerabilities
Shipping Manager For WooCommerce Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Shipping Manager For WooCommerce Attack Surface
WordPress Hooks 13
Maintenance & Trust
Shipping Manager For WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Shipping Manager For WooCommerce Alternatives
Cities Shipping Zones for WooCommerce
cities-shipping-zones-for-woocommerce
WooCommerce plugin for turning the state field into a dropdown city field. To be used as Shipping Zones.
WC City Select
wc-city-select
City Select for WooCommerce. Show a dropdown select as the cities input.
Country State City Dropdown CF7
country-state-city-auto-dropdown
Add country state city dropdown CF7 in contact form 7 plugin. In PRO you can use these features on any type of form.
RY City Select for WooCommerce
ry-wc-city-select
Show a dropdown select as the cities input on WooCommerce. Auto set the postcode for selected city.
City Dropdown For Woocommerce
city-dropdown-for-woocommerce
This Plugin change Woocommerce City input into a dropdown, based on states. Works only with Romania country!
Shipping Manager For WooCommerce Developer Profile
4 plugins · 7K total installs
How We Detect Shipping Manager For WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shipping-manager-for-woocommerce/assets/css/wcsm-admin-style.css/wp-content/plugins/shipping-manager-for-woocommerce/assets/js/wcsm-back.js/wp-content/plugins/shipping-manager-for-woocommerce/assets/css/select2.css/wp-content/plugins/shipping-manager-for-woocommerce/assets/js/select2.js/wp-content/plugins/shipping-manager-for-woocommerce/assets/js/wcsm-front.js/wp-content/plugins/shipping-manager-for-woocommerce/assets/js/wcsm-back.js/wp-content/plugins/shipping-manager-for-woocommerce/assets/js/select2.js/wp-content/plugins/shipping-manager-for-woocommerce/assets/js/wcsm-front.jsHTML / DOM Fingerprints
wcsm-settings