
ShippinGo Ecommerce Delivery – ShippinGo Security & Risk Analysis
wordpress.org/plugins/shippingoShippinGo Ecommerce Delivery enables seamless syncing of your WooCommerce orders with a variety of delivery companies, automating the entire shipping …
Is ShippinGo Ecommerce Delivery – ShippinGo Safe to Use in 2026?
Generally Safe
Score 92/100ShippinGo Ecommerce Delivery – ShippinGo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "shippingo" v1.0.16 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of critical or high-severity taint flows, 100% use of prepared statements for SQL queries, and proper output escaping for all outputs are significant strengths. Furthermore, the presence of nonce checks on all identified AJAX entry points is a positive indicator of secure handling of these critical interaction points. The plugin also demonstrates no known historical vulnerabilities, which is an excellent sign of ongoing security diligence.
However, a notable concern arises from the lack of capability checks on any of the AJAX handlers. While nonce checks prevent basic Cross-Site Request Forgery (CSRF) attacks, they do not prevent authenticated users from performing actions they shouldn't be authorized to do. This absence of authorization checks on all entry points represents a potential privilege escalation or unauthorized action vector. Additionally, the presence of three external HTTP requests, while not inherently a vulnerability, warrants careful inspection to ensure these requests do not expose sensitive data or introduce supply chain risks.
In conclusion, "shippingo" v1.0.16 is built on a foundation of good security practices, particularly regarding data sanitization and SQL injection prevention. The primary weakness lies in the missing authorization checks on its AJAX endpoints. Addressing this, along with scrutinizing the external HTTP requests, would significantly enhance the plugin's security.
Key Concerns
- Missing capability checks on AJAX handlers
ShippinGo Ecommerce Delivery – ShippinGo Security Vulnerabilities
ShippinGo Ecommerce Delivery – ShippinGo Release Timeline
ShippinGo Ecommerce Delivery – ShippinGo Code Analysis
Output Escaping
Data Flow Analysis
ShippinGo Ecommerce Delivery – ShippinGo Attack Surface
AJAX Handlers 3
WordPress Hooks 12
Maintenance & Trust
ShippinGo Ecommerce Delivery – ShippinGo Maintenance & Trust
Maintenance Signals
Community Trust
ShippinGo Ecommerce Delivery – ShippinGo Alternatives
Deliver via Shipos for WooCommerce
wc-shipos-delivery
ShipOS - Auto Sync your WooCommerce store orders to all delivery companies and Automate your shipping
HFD ePost Integration
hfd-epost-integration
התוסף מאפשר סנכרון בין אתר וורדפרס למערכת המשלוחים HFD. התממשקות חד צדדית עם HFD הכוללת שליחת הזמנות, ביטול הזמנות ומעקב אחרי ההזמנות בווקומרס.
Datalogics Ecommerce Delivery – Datalogics
datalogics
Datalogics Ecommerce Delivery enables seamless syncing of your WooCommerce orders with a variety of delivery companies, automating the entire shipping …
ShippinGo Ecommerce Delivery – ShippinGo Developer Profile
1 plugin · 0 total installs
How We Detect ShippinGo Ecommerce Delivery – ShippinGo
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shippingo/css/style_admin.css/wp-content/plugins/shippingo/js/scripts.js/wp-content/plugins/shippingo/js/scripts.jsshippingo/style.css?ver=shippingo/scripts.js?ver=HTML / DOM Fingerprints
shippingo-dso-modalshippingo-iframeshippingo-dso-bgshippingo-dso-conshippingo-dso-con-boxshippingo-dso-con-box-closeshippingo-shipping-boxshippingo_loader+1 moredata-order-idshippingo_data/wp-json/shippingo/v1/shippingo/wp-json/shippingo/v1/settings<div class="shippingo-dso-modal shippingo-iframe"><div class="shippingo-dso-bg"></div><div class="shippingo-dso-con"><div class="shippingo-dso-con-box">