Shipping with ShipSmart for WooCommerce Security & Risk Analysis

wordpress.org/plugins/shipsmart

Solução para logística crossborder. Cálculo de frete, impostos, gestão de pedidos e envios internacionais.

10 active installs v1.1.4 PHP 7.4+ WP 5.0+ Updated Feb 12, 2026
cartcheckoutshipshipsmartwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Shipping with ShipSmart for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Shipping with ShipSmart for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "shipsmart" plugin v1.1.4 exhibits a concerning security posture due to a significant number of unprotected entry points, specifically within its REST API routes. While the plugin demonstrates good practices by not using dangerous functions, employing prepared statements for all SQL queries, and avoiding file operations and bundled libraries, the lack of permission callbacks on 7 REST API routes creates a substantial attack surface. This means any unauthenticated user could potentially interact with these API endpoints, leading to unintended consequences depending on their functionality. The limited taint analysis, showing no unsanitized paths, is a positive sign, as is the absence of known vulnerabilities. However, the presence of 7 external HTTP requests also warrants attention, as these could be a vector for further compromise if not handled securely. Overall, the plugin has strengths in its core code security but suffers from critical weaknesses in its access control for its REST API.

Key Concerns

  • REST API routes without permission callbacks
  • External HTTP requests present
  • Inconsistent output escaping (70% proper)
Vulnerabilities
None known

Shipping with ShipSmart for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Shipping with ShipSmart for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
48
113 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
7
Bundled Libraries
0

Output Escaping

70% escaped161 total outputs
Attack Surface
7 unprotected

Shipping with ShipSmart for WooCommerce Attack Surface

Entry Points7
Unprotected7

REST API Routes 7

GET/wp-json/shipsmart/v1/api/testsrc\Providers\Config\SSFW_Api.php:22
GET/wp-json/shipsmart/v1/sycroOrdersrc\Providers\Config\SSFW_Api.php:33
GET/wp-json/shipsmart/v1/pdfsrc\Providers\Config\SSFW_Api.php:44
GET/wp-json/shipsmart/v1/updateOrderssrc\Providers\Config\SSFW_Api.php:70
GET/wp-json/shipsmart/v1/saveBoxessrc\Providers\Config\SSFW_Api.php:82
GET/wp-json/shipsmart/v1/boxessrc\Providers\Config\SSFW_Api.php:94
GET/wp-json/shipsmart/v1/order/itemssrc\Providers\Config\SSFW_Api.php:106
WordPress Hooks 46
actionbefore_woocommerce_initshipsmart.php:36
actionwoocommerce_initshipsmart.php:42
actionadmin_initshipsmart.php:55
actionadmin_noticesshipsmart.php:186
actionwoocommerce_before_calculate_totalsshipsmart.php:241
actionwoocommerce_cart_totals_before_shippingshipsmart.php:242
actionwoocommerce_review_order_before_shippingshipsmart.php:243
actionwoocommerce_checkout_order_processedshipsmart.php:344
actionwoocommerce_store_api_checkout_order_processedshipsmart.php:345
actionwoocommerce_checkout_order_createdshipsmart.php:346
actionwoocommerce_after_shipping_rateshipsmart.php:379
actionwoocommerce_review_order_after_shippingshipsmart.php:497
actionadmin_initshipsmart.php:514
actionadmin_enqueue_scriptssrc\Providers\Assets\Admin.php:16
actionenqueue_block_editor_assetssrc\Providers\Assets\Editor.php:16
actionlogin_enqueue_scriptssrc\Providers\Assets\Login.php:16
actionwp_enqueue_scriptssrc\Providers\Assets\Theme.php:16
actionrest_api_initsrc\Providers\Config\SSFW_Api.php:17
actionadmin_menusrc\Providers\Config\SSFW_Menu.php:17
actionadmin_post_save_shipping_settingssrc\Providers\Config\SSFW_Menu.php:18
actionadmin_post_save_general_settingssrc\Providers\Config\SSFW_Menu.php:19
actionadmin_post_save_orders_settingssrc\Providers\Config\SSFW_Menu.php:20
actionwoocommerce_process_shop_order_metasrc\Providers\Config\SSFW_Order.php:14
actionwoocommerce_thankyousrc\Providers\Config\SSFW_Order.php:15
actionadmin_noticessrc\Providers\Config\SSFW_Order.php:16
actionadd_meta_boxessrc\Providers\Config\SSFW_Order.php:17
filtermanage_edit-shop_order_columnssrc\Providers\Config\SSFW_Order.php:18
filtermanage_woocommerce_page_wc-orders_columnssrc\Providers\Config\SSFW_Order.php:19
actionmanage_shop_order_posts_custom_columnsrc\Providers\Config\SSFW_Order.php:20
actionmanage_woocommerce_page_wc-orders_custom_columnsrc\Providers\Config\SSFW_Order.php:21
actionupdate_status_orders_cronsrc\Providers\Config\SSFW_Order.php:22
actionget_documents_orders_cronsrc\Providers\Config\SSFW_Order.php:23
filterwoocommerce_order_item_display_meta_keysrc\Providers\Config\SSFW_Order.php:24
actionwoocommerce_checkout_create_order_shipping_itemsrc\Providers\Config\SSFW_Order.php:25
actioninitsrc\Providers\Config\SSFW_Order.php:26
actioninitsrc\Providers\Config\SSFW_Order.php:27
actionwoocommerce_product_options_inventory_product_datasrc\Providers\Config\SSFW_Product.php:12
actionwoocommerce_product_options_inventory_product_datasrc\Providers\Config\SSFW_Product.php:13
actionwoocommerce_process_product_metasrc\Providers\Config\SSFW_Product.php:14
actionwoocommerce_process_product_metasrc\Providers\Config\SSFW_Product.php:15
filterwoocommerce_product_export_column_namessrc\Providers\Config\SSFW_Product.php:16
filterwoocommerce_product_export_product_default_columnssrc\Providers\Config\SSFW_Product.php:17
filterwoocommerce_product_export_product_column_hs_codesrc\Providers\Config\SSFW_Product.php:18
filterwoocommerce_product_export_product_column_cost_basesrc\Providers\Config\SSFW_Product.php:19
actionwoocommerce_shipping_initsrc\Providers\Config\SSFW_Shipping_Methods.php:10
filterwoocommerce_shipping_methodssrc\Providers\Config\SSFW_Shipping_Methods.php:37

Scheduled Events 2

update_status_orders_cron
get_documents_orders_cron
Maintenance & Trust

Shipping with ShipSmart for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedFeb 12, 2026
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Shipping with ShipSmart for WooCommerce Developer Profile

Apiki

6 plugins · 1K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Shipping with ShipSmart for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shipsmart/assets/css/styles.css/wp-content/plugins/shipsmart/assets/js/script.js
Script Paths
/wp-content/plugins/shipsmart/assets/js/script.js
Version Parameters
shipsmart/assets/css/styles.css?ver=shipsmart/assets/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
shipsmart-shipping-method
HTML Comments
<!-- Plugin Name: Shipping with ShipSmart for WooCommerce -->
FAQ

Frequently Asked Questions about Shipping with ShipSmart for WooCommerce