
Shipping Simulator for WooCommerce Security & Risk Analysis
wordpress.org/plugins/shipping-simulator-for-woocommerceAllows customers to calculate the shipping rates on the product page in your WooCommerce store.
Is Shipping Simulator for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Shipping Simulator for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'shipping-simulator-for-woocommerce' v2.4.4 demonstrates a generally strong security posture based on the provided static analysis. It adheres to good practices by utilizing prepared statements for all SQL queries and employing capability checks for access control. The absence of any recorded vulnerabilities, critical or otherwise, further contributes to a positive security impression. This suggests active maintenance and a proactive approach to security by the developers.
However, the analysis does reveal some areas for concern. The presence of one flow with an unsanitized path, identified as high severity in the taint analysis, represents a potential attack vector that warrants attention. Although the attack surface appears minimal with no direct entry points like AJAX handlers or REST API routes without authentication, and no shortcodes or cron events, this single unsanitized flow could still be exploited under specific conditions. The lack of nonce checks is also a notable weakness, especially if any of the functionality, though not explicitly listed as AJAX, could be triggered programmatically or through user interaction that might not be inherently secured.
In conclusion, while the plugin has a clean vulnerability history and follows several security best practices, the identified high-severity taint flow and the absence of nonce checks introduce risks that cannot be ignored. The low attack surface is a significant mitigating factor, but the specific code-level concerns require remediation to ensure a robust security profile. Addressing the unsanitized flow and implementing nonce checks would significantly enhance the plugin's overall security.
Key Concerns
- High severity taint flow with unsanitized path
- Lack of nonce checks
- Moderate output escaping (73% proper)
Shipping Simulator for WooCommerce Security Vulnerabilities
Shipping Simulator for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Shipping Simulator for WooCommerce Attack Surface
WordPress Hooks 39
Maintenance & Trust
Shipping Simulator for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Shipping Simulator for WooCommerce Alternatives
Products Per Page for WooCommerce
woocommerce-products-per-page
Products Per Page for WooCommerce is a easy-to-setup plugin that integrates a 'products per page' dropdown on your WooCommerce pages.
Ibtana – Ecommerce Product Addons
ibtana-ecommerce-product-addons
Ibtana - Ecommerce Product Addons, you get to explore so many options for editing the product page by simple drag and drop functionality.
Magical Shop Builder – WooCommerce Template Builder for Elementor | Shop, Cart, Checkout & Product Page Builder
magical-products-display
The complete WooCommerce Shop Builder for Elementor. Build custom single product pages, cart, checkout, my account & shop archives with 60+ widgets.
Video Gallery for WooCommerce
video-wc-gallery
Video Gallery for WooCommerce: Add WordPress library videos to product pages with customization. Requires WooCommerce activation.
Calculadora de Frete e Campos Checkout para o Brasil
woo-better-shipping-calculator-for-brazil
Shipping calculator for Brazilian WooCommerce stores with automatic Postal Code address pre-filling and Brazilian Market on WooCommerce.
Shipping Simulator for WooCommerce Developer Profile
4 plugins · 13K total installs
How We Detect Shipping Simulator for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shipping-simulator-for-woocommerce/assets/js/form.js/wp-content/plugins/shipping-simulator-for-woocommerce/assets/css/form.css/wp-content/plugins/shipping-simulator-for-woocommerce/assets/js/form.min.js/wp-content/plugins/shipping-simulator-for-woocommerce/assets/css/form.min.css/wp-content/plugins/shipping-simulator-for-woocommerce/assets/js/form.js/wp-content/plugins/shipping-simulator-for-woocommerce/assets/js/form.min.jsshipping-simulator-for-woocommerce/assets/js/form.js?ver=shipping-simulator-for-woocommerce/assets/css/form.css?ver=HTML / DOM Fingerprints
wc-shipping-simulator-wrappershipping-simulator-form-wrappershipping-simulator-results-wrapperdata-cfasync="false"window.wc_shipping_simulator[wc_shipping_simulator]