
Shipping Rate By Zipcodes Security & Risk Analysis
wordpress.org/plugins/shipping-rate-by-zipcodesSet Custom Shipping Rates By Different Zipcodes For WooCommerce.
Is Shipping Rate By Zipcodes Safe to Use in 2026?
Generally Safe
Score 100/100Shipping Rate By Zipcodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'shipping-rate-by-zipcodes' plugin version 2.0.1 exhibits a generally strong security posture based on the provided static analysis. It demonstrates good practices by having a zero attack surface with unprotected entry points, no dangerous functions, and a reasonable rate of prepared SQL statements. Furthermore, the high percentage of properly escaped output and the presence of nonce and capability checks are positive indicators of secure coding. The plugin also benefits from a clean vulnerability history with no known CVEs, suggesting a track record of security awareness.
However, the analysis does reveal areas that warrant caution. While the total number of SQL queries is moderate, 45% of them are not using prepared statements, which presents a potential risk for SQL injection vulnerabilities if these queries handle user-supplied data without further sanitization. The presence of file operations, even without explicit external HTTP requests, could be a vector for directory traversal or unauthorized file access if not handled with extreme care. Despite a clean history, the absence of any recorded vulnerabilities does not guarantee future immunity, and ongoing vigilance is always recommended.
In conclusion, the plugin appears to be well-developed from a security perspective, with a limited attack surface and good implementation of core security features. The primary concern lies with the non-prepared SQL queries, which, while not evidenced as exploited, represent a latent risk. The file operations should also be closely scrutinized. The lack of past vulnerabilities is a positive sign but should not lead to complacency.
Key Concerns
- SQL queries without prepared statements
- File operations present
Shipping Rate By Zipcodes Security Vulnerabilities
Shipping Rate By Zipcodes Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Shipping Rate By Zipcodes Attack Surface
WordPress Hooks 10
Maintenance & Trust
Shipping Rate By Zipcodes Maintenance & Trust
Maintenance Signals
Community Trust
Shipping Rate By Zipcodes Alternatives
City & Zip Based Shipping Rate for WooCommerce
city-zip-based-shipping-rate-for-woocommerce
Flexible WooCommerce shipping by City or ZIP/Postcode — charge fixed, weight-based, quantity or subtotal delivery fees for accurate pricing.
Printful Integration for WooCommerce
printful-shipping-for-woocommerce
Grow your store with the top print-on-demand dropshipping plugin
WC Hide Shipping Methods
wc-hide-shipping-methods
This plugin automatically hides all other shipping methods when "Free Shipping" is available, while allowing you to retain "Local Picku …
Gelato Integration for WooCommerce
gelato-integration-for-woocommerce
Sell globally, print locally with 100+ production hubs in 32 countries
Sendcloud Shipping
sendcloud-connected-shipping
SendCloud helps to grow your online store by optimizing the shipping process. Shipping packages has never been that easy!
Shipping Rate By Zipcodes Developer Profile
5 plugins · 3K total installs
How We Detect Shipping Rate By Zipcodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shipping-rate-by-zipcodes/assets/css/shipping_rate_by_zipcodes.css/wp-content/plugins/shipping-rate-by-zipcodes/assets/js/shipping_rate_by_zipcodes.js/wp-content/plugins/shipping-rate-by-zipcodes/assets/js/shipping_rate_by_zipcodes.jsshipping-rate-by-zipcodes/assets/css/shipping_rate_by_zipcodes.css?ver=shipping-rate-by-zipcodes/assets/js/shipping_rate_by_zipcodes.js?ver=HTML / DOM Fingerprints
shiprate-wrap<!-- Shipping Rate By Zipcodes Pro --><!-- Heading --><!-- Feature Grid -->data-shipping-method-idshipping_rate_by_zipcodes_admin_params