
ShipWorks Connector for Woocommerce Security & Risk Analysis
wordpress.org/plugins/shipworks-e-commerce-bridgeOur plugin ShipWorks Connector allows Woocommerce to synchronize with Shipworks.
Is ShipWorks Connector for Woocommerce Safe to Use in 2026?
Generally Safe
Score 99/100ShipWorks Connector for Woocommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "shipworks-e-commerce-bridge" v5.3.2 plugin exhibits a mixed security posture. While it boasts a clean attack surface with zero identified AJAX handlers, REST API routes, shortcodes, or cron events without authentication or permission checks, and no known unpatched CVEs, significant concerns arise from its code quality. The presence of 20 dangerous "unserialize" functions, coupled with a very low rate of prepared SQL statements (1%) and only 16% of outputs being properly escaped, indicates a high potential for vulnerabilities. The taint analysis, although limited in scope with only 3 flows analyzed, revealed 2 flows with unsanitized paths, hinting at potential injection or path traversal issues that could be exploited if they interact with other weak points.
The plugin's vulnerability history, with one medium-severity CVE in the past related to Cross-Site Request Forgery (CSRF), suggests a pattern of past security oversights. While the absence of unpatched critical or high vulnerabilities is positive, the recurring nature of past security issues and the current code quality concerns necessitate caution. The plugin's strengths lie in its limited direct attack surface and lack of unpatched vulnerabilities, but these are overshadowed by significant code-level risks related to insecure function usage, poor SQL sanitization, and insufficient output escaping, which collectively present a considerable security risk.
Key Concerns
- Numerous dangerous unserialize functions detected
- Very low rate of prepared SQL statements
- Low percentage of properly escaped output
- Two unsanitized paths found in taint analysis
- One medium severity CVE in vulnerability history
- Only one nonce check found
- Zero capability checks found
ShipWorks Connector for Woocommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
ShipWorks Connector for Woocommerce <= 5.2.5 - Cross-Site Request Forgery to Service Password/Username Update
ShipWorks Connector for Woocommerce Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
ShipWorks Connector for Woocommerce Attack Surface
WordPress Hooks 7
Maintenance & Trust
ShipWorks Connector for Woocommerce Maintenance & Trust
Maintenance Signals
Community Trust
ShipWorks Connector for Woocommerce Alternatives
Shipping Manager – Table Rate, Weight Based & Woocommerce advanced shipping
shipping-manager
Powerful WooCommerce shipping plugin with table rate, weight-based rates, shipping class support, and advanced shipping rules.
Weight Based Shipping Table Rate for WooCommerce – Flexible Shipping
flexible-shipping
Weight based shipping methods for WooCommerce. Flexible shipping with table rate rules by cart weight and order value. Accurate rates at checkout.
Weight Based Shipping for WooCommerce
weight-based-shipping-for-woocommerce
Weight Based Shipping is a flexible and widely-used solution to calculate shipping costs based on the total cart weight and value.
Advanced Free Shipping for WooCommerce
woocommerce-advanced-free-shipping
Advanced Free Shipping for WooCommerce is an plugin which allows you to set up advanced free shipping conditions.
Conditional Shipping for WooCommerce
conditional-shipping-for-woocommerce
Restrict WooCommerce shipping methods based on conditions. Works with your existing shipping methods and zones.
ShipWorks Connector for Woocommerce Developer Profile
1 plugin · 300 total installs
How We Detect ShipWorks Connector for Woocommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shipworks-e-commerce-bridge/css/admin.css/wp-content/plugins/shipworks-e-commerce-bridge/css/bootstrap.min.css/wp-content/plugins/shipworks-e-commerce-bridge/css/bootstrap.min.js/wp-content/plugins/shipworks-e-commerce-bridge/css/bootstrap.min.jsshipworks-e-commerce-bridge/css/admin.css?ver=shipworks-e-commerce-bridge/css/bootstrap.min.css?ver=shipworks-e-commerce-bridge/css/bootstrap.min.js?ver=HTML / DOM Fingerprints
shipworks-connectorShipWorks ConnectorAdvancedCreationshipworks-wordpress