Shiptastic integration for UPS Security & Risk Analysis

wordpress.org/plugins/shiptastic-integration-for-ups

Connect Shiptastic to the UPS® API and create UPS labels to shipments and returns.

600 active installs v1.1.0 PHP 7.0+ WP 5.4+ Updated Jul 17, 2025
shippingshiptasticupswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Shiptastic integration for UPS Safe to Use in 2026?

Generally Safe

Score 100/100

Shiptastic integration for UPS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The shiptastic-integration-for-ups plugin, version 1.1.0, exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL queries without prepared statements, unescaped output, file operations, or external HTTP requests is commendable. Furthermore, the lack of any recorded vulnerabilities (CVEs) in its history, coupled with a seemingly zero attack surface, suggests a developer who is mindful of security best practices. However, the analysis indicates a complete absence of nonce and capability checks, which is a significant concern. While the current attack surface might be zero, this could be due to the plugin's limited functionality or a lack of exposure in the current version. The lack of any taint analysis results also means that complex or indirect vulnerabilities might not have been detected. Therefore, while the current state appears secure, the absence of fundamental security checks on potential entry points, even if not currently exploited, represents a latent risk that could be exploited if the plugin's functionality evolves or if specific conditions are met.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Shiptastic integration for UPS Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Shiptastic integration for UPS Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped7 total outputs
Attack Surface

Shiptastic integration for UPS Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionplugins_loadedshiptastic-integration-for-ups.php:31
filterwoocommerce_shiptastic_shipping_provider_class_namessrc\Package.php:29
actionwoocommerce_shiptastic_initsrc\Package.php:32
actioninitsrc\Package.php:40
filtershiptastic_default_template_pathsrc\Package.php:129
filtershiptastic_register_api_instance_upssrc\Package.php:130
Maintenance & Trust

Shiptastic integration for UPS Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 17, 2025
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs600
Developer Profile

Shiptastic integration for UPS Developer Profile

vendidero

6 plugins · 104K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
602 days
View full developer profile
Detection Fingerprints

How We Detect Shiptastic integration for UPS

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shiptastic-integration-for-ups/assets/css/backend.css/wp-content/plugins/shiptastic-integration-for-ups/assets/js/backend.js
Script Paths
/wp-content/plugins/shiptastic-integration-for-ups/assets/js/backend.js
Version Parameters
/wp-content/plugins/shiptastic-integration-for-ups/assets/css/backend.css?ver=/wp-content/plugins/shiptastic-integration-for-ups/assets/js/backend.js?ver=

HTML / DOM Fingerprints

CSS Classes
shiptastic-ups-settings
Data Attributes
data-shipping-provider="ups"
JS Globals
VendideroShiptasticUPS
FAQ

Frequently Asked Questions about Shiptastic integration for UPS