Shipping per Neighborhood for WooCommerce Security & Risk Analysis

wordpress.org/plugins/shipping-per-neighborhood-for-woocommerce

This plugin add shipping method for manage deliveries by neighborhoods. You can add a table with all cities, neighborhoods and prices for each.

200 active installs v1.2.9 PHP 7.0+ WP 5.5+ Updated Jan 12, 2026
shippingshipping-methodshipping-neighborhoodwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Shipping per Neighborhood for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Shipping per Neighborhood for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The static analysis of 'shipping-per-neighborhood-for-woocommerce' v1.2.9 reveals a generally strong security posture. The absence of dangerous functions, file operations, external HTTP requests, and the consistent use of prepared statements for SQL queries are commendable practices. The high percentage of properly escaped output further mitigates the risk of common web vulnerabilities. Furthermore, the plugin exhibits no known CVEs and has a clean vulnerability history, suggesting a commitment to security from the developers.

However, a significant concern arises from the complete lack of nonces and capability checks across all entry points. While the static analysis reports zero entry points overall, this absence is a critical oversight. Should any entry points be discovered or introduced in future versions, they would be entirely unprotected against various attacks like Cross-Site Request Forgery (CSRF) and unauthorized actions. The taint analysis also showing zero flows, while positive in that no issues were found, could be limited by the analysis scope and the zero reported entry points.

In conclusion, while the current version of the plugin demonstrates excellent adherence to secure coding practices in several key areas and lacks a history of vulnerabilities, the complete omission of nonce and capability checks represents a substantial potential weakness. This could be a blind spot that attackers might exploit if new vulnerabilities are introduced or if the attack surface is underestimated. The plugin is currently well-protected by its lack of exposed functionality, but this protection is fragile and relies on no new attack vectors being added.

Key Concerns

  • Missing nonce checks on all entry points
  • Missing capability checks on all entry points
Vulnerabilities
None known

Shipping per Neighborhood for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Shipping per Neighborhood for WooCommerce Release Timeline

v1.2.9Current
v1.2.8
v1.2.7
v1.2.6
v1.2.5
v1.2.4
v1.2.3
v1.2.2
v1.2.1
v1.2
v1.1
v1.0
Code Analysis
Analyzed Mar 16, 2026

Shipping per Neighborhood for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
54 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

92% escaped59 total outputs
Attack Surface

Shipping per Neighborhood for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 24
filterwoocommerce_formatted_address_replacementsincludes\class-manage-essential-fields.php:20
filterwoocommerce_admin_billing_fieldsincludes\class-manage-essential-fields.php:23
filterwoocommerce_admin_shipping_fieldsincludes\class-manage-essential-fields.php:24
filterwoocommerce_order_formatted_billing_addressincludes\class-manage-essential-fields.php:25
filterwoocommerce_order_formatted_shipping_addressincludes\class-manage-essential-fields.php:26
filterwoocommerce_localisation_address_formatsincludes\class-manage-essential-fields.php:29
filterwoocommerce_customer_meta_fieldsincludes\class-manage-essential-fields.php:32
filterwoocommerce_user_column_billing_addressincludes\class-manage-essential-fields.php:33
filterwoocommerce_user_column_shipping_addressincludes\class-manage-essential-fields.php:34
actionwoocommerce_shipping_zone_method_deletedincludes\class-manage-essential-fields.php:37
filterwoocommerce_locate_templateincludes\class-shipping-extras.php:20
filterwoocommerce_cart_shipping_packagesincludes\class-shipping-extras.php:23
actionwoocommerce_calculated_shippingincludes\class-shipping-extras.php:26
actionwoocommerce_checkout_update_order_reviewincludes\class-shipping-extras.php:29
filterwoocommerce_billing_fieldsincludes\class-shipping-extras.php:32
filterwoocommerce_shipping_fieldsincludes\class-shipping-extras.php:33
filterwoocommerce_form_field_selectincludes\class-shipping-extras.php:36
actionadmin_noticesshipping-per-neighborhood-for-woocommerce.php:100
actionadmin_noticesshipping-per-neighborhood-for-woocommerce.php:105
actionplugins_loadedshipping-per-neighborhood-for-woocommerce.php:109
actionadmin_noticesshipping-per-neighborhood-for-woocommerce.php:110
filterwoocommerce_shipping_methodsshipping-per-neighborhood-for-woocommerce.php:131
actionadmin_enqueue_scriptsshipping-per-neighborhood-for-woocommerce.php:132
actionadmin_initshipping-per-neighborhood-for-woocommerce.php:133
Maintenance & Trust

Shipping per Neighborhood for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 12, 2026
PHP min version7.0
Downloads7K

Community Trust

Rating98/100
Number of ratings13
Active installs200
Developer Profile

Shipping per Neighborhood for WooCommerce Developer Profile

Eduardo Villão

5 plugins · 9K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Shipping per Neighborhood for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shipping-per-neighborhood-for-woocommerce/assets/css/admin-options.css/wp-content/plugins/shipping-per-neighborhood-for-woocommerce/assets/js/admin-options.js
Version Parameters
shipping-per-neighborhood-for-woocommerce/assets/js/admin-options.js?ver=shipping-per-neighborhood-for-woocommerce/assets/css/admin-options.css?ver=

HTML / DOM Fingerprints

CSS Classes
wsn_options
HTML Comments
<!-- 1 Disable country --><!-- add_filter ('woocommerce_shipping_calculator_enable_country', '__return_false'); --><!-- 2 Disable State --><!-- add_filter ('woocommerce_shipping_calculator_enable_state', '__return_false'); -->+4 more
Data Attributes
data-wsn_id
JS Globals
wsn_admin_options_params
FAQ

Frequently Asked Questions about Shipping per Neighborhood for WooCommerce