Shippit for WooCommerce Security & Risk Analysis

wordpress.org/plugins/shippit-simplified-australia-shipping

Multi-carrier shipping technology.

1K active installs v2.0.4 PHP 7.0+ WP 4.0.0+ Updated Oct 1, 2025
aramexaustralia-postcouriers-pleaseshipping
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Shippit for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Shippit for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The 'shippit-simplified-australia-shipping' plugin v2.0.4 exhibits a generally good security posture, with a commendable lack of identified vulnerabilities in its history and no critical findings in the static analysis. The absence of dangerous functions, raw SQL queries, and taint flows is a strong positive indicator. However, there are areas for improvement that present potential risks.

The static analysis reveals a concern with output escaping, where only 40% of outputs are properly escaped. This means that if user-supplied data is handled in the unescaped outputs, there is a risk of cross-site scripting (XSS) vulnerabilities. Additionally, the complete absence of nonce checks and capability checks on its entry points, coupled with the presence of file operations and external HTTP requests, suggests a potential for privilege escalation or unauthorized actions if these entry points are manipulated without proper authorization mechanisms.

The plugin's vulnerability history is currently clean, which is excellent. This suggests a diligent development team or a lack of past exploitable issues. However, the static analysis findings, particularly the unescaped output and lack of authorization checks on entry points, indicate that future vulnerabilities could arise if not addressed. The strengths lie in its clean history and secure handling of SQL and dangerous functions, but weaknesses lie in output sanitization and authorization checks for its functionalities.

Key Concerns

  • Unescaped output
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Shippit for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Shippit for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

40% escaped5 total outputs
Attack Surface

Shippit for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 29
actionsyncOrdersincludes\class-shippit-core.php:87
actionwoocommerce_order_status_processingincludes\class-shippit-core.php:96
actionwoocommerce_order_status_on-holdincludes\class-shippit-core.php:99
actionwoocommerce_after_order_notesincludes\class-shippit-core.php:106
actionwoocommerce_checkout_update_order_metaincludes\class-shippit-core.php:109
actionwoocommerce_admin_order_data_after_shipping_addressincludes\class-shippit-core.php:112
actionwoocommerce_settings_tabs_shippit_settings_tabincludes\class-shippit-core.php:126
actionwoocommerce_update_options_shippit_settings_tabincludes\class-shippit-core.php:127
filterquery_varsincludes\class-shippit-core.php:135
actionparse_requestincludes\class-shippit-core.php:138
actioninitincludes\class-shippit-core.php:141
actionwoocommerce_order_actionsincludes\class-shippit-core.php:144
actionwoocommerce_order_action_shippit_order_actionincludes\class-shippit-core.php:147
actionbulk_actions-edit-shop_orderincludes\class-shippit-core.php:150
actionhandle_bulk_actions-edit-shop_orderincludes\class-shippit-core.php:153
actionadmin_noticesincludes\class-shippit-core.php:155
filterwoocommerce_shipping_calculator_enable_cityincludes\class-shippit-core.php:158
actionadd_meta_boxes_shop_orderincludes\class-shippit-core.php:161
actionadd_meta_boxes_woocommerce_page_wc-ordersincludes\class-shippit-core.php:162
actionadmin_noticesincludes\class-shippit-settings.php:62
actionadmin_noticesincludes\class-shippit-settings.php:550
actionadmin_noticesincludes\class-shippit-settings.php:590
actionwoocommerce_order_status_completed_notificationincludes\class-shippit-shipment.php:320
filterwoocommerce_settings_tabs_arraywoocommerce-shippit.php:39
actionbefore_woocommerce_initwoocommerce-shippit.php:50
actionwoocommerce_initwoocommerce-shippit.php:64
actionadmin_enqueue_scriptswoocommerce-shippit.php:67
filterwoocommerce_shipping_methodswoocommerce-shippit.php:88
actionwoocommerce_shipping_initwoocommerce-shippit.php:92

Scheduled Events 2

syncOrders
syncOrders
Maintenance & Trust

Shippit for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 1, 2025
PHP min version7.0
Downloads31K

Community Trust

Rating50/100
Number of ratings4
Active installs1K
Developer Profile

Shippit for WooCommerce Developer Profile

matthewmuscat

1 plugin · 1K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Shippit for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shippit-simplified-australia-shipping/assets/js/shippit.js
Script Paths
/wp-content/plugins/shippit-simplified-australia-shipping/assets/js/shippit.js
Version Parameters
shippit-script?ver=2.0.4

HTML / DOM Fingerprints

CSS Classes
mamis-shippit
Data Attributes
data-instance_id
JS Globals
shippit_scripts
FAQ

Frequently Asked Questions about Shippit for WooCommerce