Showcase Shipping Options (icons) Security & Risk Analysis

wordpress.org/plugins/showcase-shipping-options-icons

The Showcase Shipping Options (icons) plugin enables you to easily display shipping method icons anywhere on your WordPress website via a shortcode.

0 active installs v1.0.0 PHP 7.2+ WP 5.0+ Updated Jul 3, 2024
e-commerceiconsshipping
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Showcase Shipping Options (icons) Safe to Use in 2026?

Generally Safe

Score 92/100

Showcase Shipping Options (icons) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "showcase-shipping-options-icons" plugin, version 1.0.0, exhibits a seemingly strong security posture based on the provided static analysis and vulnerability history. There are no identified CVEs, suggesting a history of responsible development or limited historical scrutiny. The absence of direct entry points like AJAX handlers, REST API routes, shortcodes, and cron events, as well as the lack of file operations and external HTTP requests, significantly reduces the plugin's attack surface. Furthermore, the use of prepared statements for all SQL queries is a positive indicator of secure database interaction.

However, a notable concern arises from the output escaping. With 45% of outputs not properly escaped, there is a moderate risk of Cross-Site Scripting (XSS) vulnerabilities. If user-supplied data is directly reflected in the output without adequate sanitization, an attacker could potentially inject malicious scripts. The lack of any identified capability checks or nonce checks, combined with zero total entry points and zero unprotected entry points, is somewhat contradictory. If there were indeed no entry points, then these checks would logically be absent. However, if there are hidden or implicit entry points, their absence would pose a significant risk.

Overall, the plugin demonstrates good practices in areas like SQL query handling and attack surface minimization. The primary weakness lies in the insufficient output escaping, which, while not flagged as critical in taint analysis, presents a tangible risk. The plugin's clean vulnerability history is positive, but it's crucial to address the identified output escaping issues to maintain this strong record.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

Showcase Shipping Options (icons) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Showcase Shipping Options (icons) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

45% escaped22 total outputs
Attack Surface

Showcase Shipping Options (icons) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menushipping-icons-plugin.php:26
actionadmin_initshipping-icons-plugin.php:244
actionadmin_headshipping-icons-plugin.php:307
Maintenance & Trust

Showcase Shipping Options (icons) Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedJul 3, 2024
PHP min version7.2
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Showcase Shipping Options (icons) Developer Profile

KNEET

6 plugins · 1K total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Showcase Shipping Options (icons)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/showcase-shipping-options-icons/shipping-icons-plugin.js
Version Parameters
showcase-shipping-options-icons/shipping-icons-plugin.js?ver=

HTML / DOM Fingerprints

CSS Classes
ssoi-shipping-icons-container
Data Attributes
data-icon-sizedata-icon-spacing
JS Globals
ssoi_shipping_options_icons_settings
Shortcode Output
<div class="ssoi-shipping-icons-container">
FAQ

Frequently Asked Questions about Showcase Shipping Options (icons)