
Shipping with ShipSmart for WooCommerce Security & Risk Analysis
wordpress.org/plugins/shipsmartSolução para logística crossborder. Cálculo de frete, impostos, gestão de pedidos e envios internacionais.
Is Shipping with ShipSmart for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Shipping with ShipSmart for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "shipsmart" plugin v1.1.4 exhibits a concerning security posture due to a significant number of unprotected entry points, specifically within its REST API routes. While the plugin demonstrates good practices by not using dangerous functions, employing prepared statements for all SQL queries, and avoiding file operations and bundled libraries, the lack of permission callbacks on 7 REST API routes creates a substantial attack surface. This means any unauthenticated user could potentially interact with these API endpoints, leading to unintended consequences depending on their functionality. The limited taint analysis, showing no unsanitized paths, is a positive sign, as is the absence of known vulnerabilities. However, the presence of 7 external HTTP requests also warrants attention, as these could be a vector for further compromise if not handled securely. Overall, the plugin has strengths in its core code security but suffers from critical weaknesses in its access control for its REST API.
Key Concerns
- REST API routes without permission callbacks
- External HTTP requests present
- Inconsistent output escaping (70% proper)
Shipping with ShipSmart for WooCommerce Security Vulnerabilities
Shipping with ShipSmart for WooCommerce Code Analysis
Output Escaping
Shipping with ShipSmart for WooCommerce Attack Surface
REST API Routes 7
WordPress Hooks 46
Scheduled Events 2
Maintenance & Trust
Shipping with ShipSmart for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Shipping with ShipSmart for WooCommerce Alternatives
Checkout Shipping Message Add-on for WooCommerce
checkout-shipping-message-add-on-for-woocommerce
This add-on will allow you to add a custom message to WooCommerce under that shipping totals shipping section of your checkout.
Free Shipping Notice for WooCommerce
free-shipping-notice-for-woocommerce
Displays the remaining price to receive free shipping on the cart and checkout pages.
Change Shipping Label
change-shipping-label
A simple plugin for changing shipping labels in WooCommece cart and checkout.
Lite Shipping Counter & Notice
lite-shipping-counter-notice
Lightweight notice for WooCommerce that shows how much is left to unlock free shipping.
Direct Checkout for WooCommerce
woocommerce-direct-checkout
Formerly "WooCommerce Direct Checkout". This plugin simplifies the entire WooCommerce checkout process to improve your sales rate.
Shipping with ShipSmart for WooCommerce Developer Profile
6 plugins · 1K total installs
How We Detect Shipping with ShipSmart for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shipsmart/assets/css/styles.css/wp-content/plugins/shipsmart/assets/js/script.js/wp-content/plugins/shipsmart/assets/js/script.jsshipsmart/assets/css/styles.css?ver=shipsmart/assets/js/script.js?ver=HTML / DOM Fingerprints
shipsmart-shipping-method<!-- Plugin Name: Shipping with ShipSmart for WooCommerce -->