Shipping Rate By Zipcodes Security & Risk Analysis

wordpress.org/plugins/shipping-rate-by-zipcodes

Set Custom Shipping Rates By Different Zipcodes For WooCommerce.

90 active installs v2.0.1 PHP 7.2+ WP 5.1+ Updated Jan 31, 2026
custom-ratepost-codepostcode-shippingshipping-ratezipcode-shipping
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Shipping Rate By Zipcodes Safe to Use in 2026?

Generally Safe

Score 100/100

Shipping Rate By Zipcodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The 'shipping-rate-by-zipcodes' plugin version 2.0.1 exhibits a generally strong security posture based on the provided static analysis. It demonstrates good practices by having a zero attack surface with unprotected entry points, no dangerous functions, and a reasonable rate of prepared SQL statements. Furthermore, the high percentage of properly escaped output and the presence of nonce and capability checks are positive indicators of secure coding. The plugin also benefits from a clean vulnerability history with no known CVEs, suggesting a track record of security awareness.

However, the analysis does reveal areas that warrant caution. While the total number of SQL queries is moderate, 45% of them are not using prepared statements, which presents a potential risk for SQL injection vulnerabilities if these queries handle user-supplied data without further sanitization. The presence of file operations, even without explicit external HTTP requests, could be a vector for directory traversal or unauthorized file access if not handled with extreme care. Despite a clean history, the absence of any recorded vulnerabilities does not guarantee future immunity, and ongoing vigilance is always recommended.

In conclusion, the plugin appears to be well-developed from a security perspective, with a limited attack surface and good implementation of core security features. The primary concern lies with the non-prepared SQL queries, which, while not evidenced as exploited, represent a latent risk. The file operations should also be closely scrutinized. The lack of past vulnerabilities is a positive sign but should not lead to complacency.

Key Concerns

  • SQL queries without prepared statements
  • File operations present
Vulnerabilities
None known

Shipping Rate By Zipcodes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Shipping Rate By Zipcodes Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
6 prepared
Unescaped Output
6
46 escaped
Nonce Checks
3
Capability Checks
4
File Operations
2
External Requests
0
Bundled Libraries
0

SQL Query Safety

55% prepared11 total queries

Output Escaping

88% escaped52 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
handle_import (shipping_rate_by_zipcodes.php:156)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Shipping Rate By Zipcodes Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_noticesshipping_rate_by_zipcodes.php:68
actionadmin_enqueue_scriptsshipping_rate_by_zipcodes.php:78
actionwp_enqueue_scriptsshipping_rate_by_zipcodes.php:79
actionwoocommerce_shipping_initshipping_rate_by_zipcodes.php:90
filterwoocommerce_shipping_methodsshipping_rate_by_zipcodes.php:91
actionwp_footershipping_rate_by_zipcodes.php:95
actionadmin_menushipping_rate_by_zipcodes.php:100
actionadmin_post_zipcoderate_exportshipping_rate_by_zipcodes.php:102
actionadmin_post_zipcoderate_importshipping_rate_by_zipcodes.php:103
actionwoocommerce_update_options_shipping_methodszipcoderate-method-class.php:26
Maintenance & Trust

Shipping Rate By Zipcodes Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 31, 2026
PHP min version7.2
Downloads3K

Community Trust

Rating74/100
Number of ratings3
Active installs90
Developer Profile

Shipping Rate By Zipcodes Developer Profile

Trident Technolabs

5 plugins · 3K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
226 days
View full developer profile
Detection Fingerprints

How We Detect Shipping Rate By Zipcodes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shipping-rate-by-zipcodes/assets/css/shipping_rate_by_zipcodes.css/wp-content/plugins/shipping-rate-by-zipcodes/assets/js/shipping_rate_by_zipcodes.js
Script Paths
/wp-content/plugins/shipping-rate-by-zipcodes/assets/js/shipping_rate_by_zipcodes.js
Version Parameters
shipping-rate-by-zipcodes/assets/css/shipping_rate_by_zipcodes.css?ver=shipping-rate-by-zipcodes/assets/js/shipping_rate_by_zipcodes.js?ver=

HTML / DOM Fingerprints

CSS Classes
shiprate-wrap
HTML Comments
<!-- Shipping Rate By Zipcodes Pro --><!-- Heading --><!-- Feature Grid -->
Data Attributes
data-shipping-method-id
JS Globals
shipping_rate_by_zipcodes_admin_params
FAQ

Frequently Asked Questions about Shipping Rate By Zipcodes