Shiprocket Security & Risk Analysis

wordpress.org/plugins/shiprocket

Auto Sync your Woocommerce store orders & ship them at lowest shipping rates. Automate your shipping, save time & money.

10K active installs v2.0.8 PHP 4.8+ WP 3.0.0+ Updated Dec 8, 2025
cash-on-deliverylogistics-integrationshipment-trackingshipping-indiawoocommerce-shipping
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEJan 29, 2026
Download
Safety Verdict

Is Shiprocket Safe to Use in 2026?

Mostly Safe

Score 78/100

Shiprocket is generally safe to use. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Jan 29, 2026Updated 5mo ago
Risk Assessment

The static analysis of Shiprocket v2.0.8 reveals a generally strong security posture regarding its code implementation. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and 100% proper output escaping are significant strengths. The limited attack surface with no unprotected entry points, shortcodes, cron events, or unauthenticated AJAX/REST API handlers is also commendable. However, the lack of any nonce checks or capability checks across its codebase, coupled with the presence of external HTTP requests without explicit mention of their security handling, represent potential areas of concern that could be exploited if not managed carefully.

The vulnerability history is the most significant factor impacting the overall risk. With one known medium-severity CVE that is currently unpatched, related to 'Authorization Bypass Through User-Controlled Key', this poses a direct and present risk. The fact that this vulnerability is recent (indicated by the future date, likely a placeholder or error in reporting) and remains unpatched is a critical red flag. This suggests a potential for ongoing security weaknesses in the plugin, and a lack of timely remediation for identified issues.

In conclusion, while Shiprocket v2.0.8 demonstrates good coding practices in areas like SQL sanitization and output escaping, the unpatched authorization bypass vulnerability severely undermines its security. Users should be highly cautious, and immediate patching of the known vulnerability is paramount. The absence of nonce and capability checks warrants further investigation by the developers to ensure all sensitive operations are properly secured.

Key Concerns

  • Unpatched medium CVE
  • No nonce checks
  • No capability checks
Vulnerabilities
1 published

Shiprocket Security Vulnerabilities

CVEs by Year

1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-68051medium · 4.3Authorization Bypass Through User-Controlled Key

Shiprocket <= 2.0.8 - Authenticated (Subscriber+) Insecure Direct Object Reference

Jan 29, 2026Unpatched
Version History

Shiprocket Release Timeline

v2.0.8Current1 CVE
v2.0.71 CVE
v2.0.61 CVE
v2.0.51 CVE
v2.0.41 CVE
v2.0.31 CVE
v2.0.21 CVE
Code Analysis
Analyzed Mar 16, 2026

Shiprocket Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
0
35 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

100% escaped35 total outputs
Attack Surface

Shiprocket Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionwoocommerce_shipping_initclass-shiprocket-woocommerce-shipping.php:113
filterwoocommerce_shipping_methodsclass-shiprocket-woocommerce-shipping.php:115
actionwoocommerce_checkout_update_order_reviewclass-shiprocket-woocommerce-shipping.php:118
filterwoocommerce_package_ratesclass-shiprocket-woocommerce-shipping.php:142
filterbulk_actions-edit-shop_orderclass-shiprocket-woocommerce-shipping.php:239
actionadmin_action_ship_with_shiprocketclass-shiprocket-woocommerce-shipping.php:253
actionwoocommerce_single_product_summaryclass-shiprocket-woocommerce-shipping.php:278
actionrest_api_initincludes\api\class-shiprocket-woocommerce-api.php:28
actionwoocommerce_cart_calculate_feesincludes\class-shiprocket-woocommerce-shipping-method.php:145
actionwoocommerce_review_order_before_paymentincludes\class-shiprocket-woocommerce-shipping-method.php:146
Maintenance & Trust

Shiprocket Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 8, 2025
PHP min version4.8
Downloads146K

Community Trust

Rating54/100
Number of ratings20
Active installs10K
Developer Profile

Shiprocket Developer Profile

Shiprocket

1 plugin · 10K total installs

79
trust score
Avg Security Score
78/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Shiprocket

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shiprocket/includes/js/shiprocket_shipping.js/wp-content/plugins/shiprocket/includes/css/shiprocket_shipping.css
Script Paths
/wp-content/plugins/shiprocket/includes/js/shiprocket_shipping.js

HTML / DOM Fingerprints

CSS Classes
shiprocket-app-configuration
Data Attributes
data-shiprocket-settings
JS Globals
shiprocket_app_settings
FAQ

Frequently Asked Questions about Shiprocket