ShippinGo Ecommerce Delivery – ShippinGo Security & Risk Analysis

wordpress.org/plugins/shippingo

ShippinGo Ecommerce Delivery enables seamless syncing of your WooCommerce orders with a variety of delivery companies, automating the entire shipping …

0 active installs v1.0.16 PHP 7.4+ WP 5.7.0+ Updated Oct 30, 2024
chitahfdtapuzydm
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ShippinGo Ecommerce Delivery – ShippinGo Safe to Use in 2026?

Generally Safe

Score 92/100

ShippinGo Ecommerce Delivery – ShippinGo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "shippingo" v1.0.16 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of critical or high-severity taint flows, 100% use of prepared statements for SQL queries, and proper output escaping for all outputs are significant strengths. Furthermore, the presence of nonce checks on all identified AJAX entry points is a positive indicator of secure handling of these critical interaction points. The plugin also demonstrates no known historical vulnerabilities, which is an excellent sign of ongoing security diligence.

However, a notable concern arises from the lack of capability checks on any of the AJAX handlers. While nonce checks prevent basic Cross-Site Request Forgery (CSRF) attacks, they do not prevent authenticated users from performing actions they shouldn't be authorized to do. This absence of authorization checks on all entry points represents a potential privilege escalation or unauthorized action vector. Additionally, the presence of three external HTTP requests, while not inherently a vulnerability, warrants careful inspection to ensure these requests do not expose sensitive data or introduce supply chain risks.

In conclusion, "shippingo" v1.0.16 is built on a foundation of good security practices, particularly regarding data sanitization and SQL injection prevention. The primary weakness lies in the missing authorization checks on its AJAX endpoints. Addressing this, along with scrutinizing the external HTTP requests, would significantly enhance the plugin's security.

Key Concerns

  • Missing capability checks on AJAX handlers
Vulnerabilities
None known

ShippinGo Ecommerce Delivery – ShippinGo Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

ShippinGo Ecommerce Delivery – ShippinGo Release Timeline

v1.0.16Current
v1.0.15
v1.0.14
v1.0.13
v1.0.12
Code Analysis
Analyzed Mar 17, 2026

ShippinGo Ecommerce Delivery – ShippinGo Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
100 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

100% escaped100 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
<orders> (orders.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ShippinGo Ecommerce Delivery – ShippinGo Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_shippingo_registeractions.php:4
authwp_ajax_shippingo_validate_keyactions.php:72
authwp_ajax_shippingo_add_orderactions.php:148
WordPress Hooks 12
actionwoocommerce_order_status_changedactions.php:279
actionrest_api_initapi.php:16
filterplugin_action_linksdata.php:16
actionadmin_menudata.php:18
actioninitdata.php:45
actionadmin_enqueue_scriptsorders.php:48
filteradmin_footerorders.php:112
actionadd_meta_boxesorders.php:156
filtermanage_edit-shop_order_columnsorders.php:371
filtermanage_woocommerce_page_wc-orders_columnsorders.php:372
actionmanage_shop_order_posts_custom_columnorders.php:472
actionmanage_woocommerce_page_wc-orders_custom_columnorders.php:473
Maintenance & Trust

ShippinGo Ecommerce Delivery – ShippinGo Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedOct 30, 2024
PHP min version7.4
Downloads992

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

ShippinGo Ecommerce Delivery – ShippinGo Developer Profile

ShippinGo

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ShippinGo Ecommerce Delivery – ShippinGo

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shippingo/css/style_admin.css/wp-content/plugins/shippingo/js/scripts.js
Script Paths
/wp-content/plugins/shippingo/js/scripts.js
Version Parameters
shippingo/style.css?ver=shippingo/scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
shippingo-dso-modalshippingo-iframeshippingo-dso-bgshippingo-dso-conshippingo-dso-con-boxshippingo-dso-con-box-closeshippingo-shipping-boxshippingo_loader+1 more
Data Attributes
data-order-id
JS Globals
shippingo_data
REST Endpoints
/wp-json/shippingo/v1/shippingo/wp-json/shippingo/v1/settings
Shortcode Output
<div class="shippingo-dso-modal shippingo-iframe"><div class="shippingo-dso-bg"></div><div class="shippingo-dso-con"><div class="shippingo-dso-con-box">
FAQ

Frequently Asked Questions about ShippinGo Ecommerce Delivery – ShippinGo