
Small Package Quotes – Purolator Edition Security & Risk Analysis
wordpress.org/plugins/small-package-quotes-purolator-editionReal-time small package (parcel) shipping rates from Purolator. Fifteen day free trial.
Is Small Package Quotes – Purolator Edition Safe to Use in 2026?
Generally Safe
Score 98/100Small Package Quotes – Purolator Edition has a strong security track record. Known vulnerabilities have been patched promptly.
The overall security posture of 'small-package-quotes-purolator-edition' v3.6.7 shows a mix of good practices and notable concerns. The plugin demonstrates strong adherence to secure coding by utilizing prepared statements for a high percentage of its SQL queries and properly escaping a good portion of its output. The absence of dangerous functions and file operations is also positive. However, the presence of an unprotected REST API route is a significant concern, as it represents a direct entry point that could be exploited without proper authorization checks. The taint analysis revealing a high-severity flow with unsanitized paths is also a critical red flag, indicating potential for vulnerabilities like cross-site scripting or command injection if not handled carefully by the developer. The vulnerability history shows a past high-severity SQL injection vulnerability, which, despite being patched, highlights a potential area of weakness within the plugin's codebase that warrants vigilance. While the plugin has good internal security practices, the identified unprotected entry point and high-severity taint flow, coupled with past SQL injection issues, elevate the risk profile.
Key Concerns
- Unprotected REST API route
- High severity unsanitized taint flow
- Past high severity SQL Injection vulnerability
- Unprotected AJAX handlers (1 of 20)
Small Package Quotes – Purolator Edition Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Small Package Quotes – Purolator Edition <= 3.6.4 - Unauthenticated SQL Injection
Small Package Quotes – Purolator Edition Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Small Package Quotes – Purolator Edition Attack Surface
AJAX Handlers 20
REST API Routes 1
WordPress Hooks 66
Scheduled Events 1
Maintenance & Trust
Small Package Quotes – Purolator Edition Maintenance & Trust
Maintenance Signals
Community Trust
Small Package Quotes – Purolator Edition Alternatives
Small Package Quotes – Worldwide Express Edition
small-package-quotes-wwe-edition
Real-time small package (parcel) shipping rates from Worldwide Express. Fifteen day free trial.
Small Package Quotes – Unishippers Edition
small-package-quotes-unishippers-edition
Real-time small package (parcel) shipping rates from Unishippers. Fifteen day free trial.
Small Package Quotes – For Customers of FedEx
small-package-quotes-fedex-edition
Real-time small package (parcel) shipping rates from Fedex. Fifteen day free trial.
Small Package Quotes – USPS Edition
small-package-quotes-usps-edition
Real-time small package (parcel) shipping rates from Usps. Fifteen day free trial.
Real Time Shipping Quotes for WooCommerce
real-time-shipping-quotes-for-woocommerce
The Real Time Shipping Quotes for WooCommerce retrieves your negotiated shipping rates
Small Package Quotes – Purolator Edition Developer Profile
29 plugins · 1K total installs
How We Detect Small Package Quotes – Purolator Edition
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/small-package-quotes-purolator-edition/logs/en-json-tree-view/en-jtv-style.css/wp-content/plugins/small-package-quotes-purolator-edition/logs/en-json-tree-view/en-jtv-script.js/wp-content/plugins/small-package-quotes-purolator-edition/js/en-purolator-small.jssmall-package-quotes-purolator-edition/logs/en-json-tree-view/en-jtv-script.js?ver=1.0.0small-package-quotes-purolator-edition/js/en-purolator-small.js?ver=1.0.4HTML / DOM Fingerprints
data-en-tree-view-urldata-en-purolator-small-scripten_purolator_small_admin_script