Small Package Quotes – Unishippers Edition Security & Risk Analysis

wordpress.org/plugins/small-package-quotes-unishippers-edition

Real-time small package (parcel) shipping rates from Unishippers. Fifteen day free trial.

60 active installs v2.4.18 PHP + WP 6.4+ Updated Mar 11, 2026
enitureparcel-quotesparcel-ratesshipping-estimatesunishippers
97
A · Safe
CVEs total3
Unpatched0
Last CVEFeb 23, 2025
Safety Verdict

Is Small Package Quotes – Unishippers Edition Safe to Use in 2026?

Generally Safe

Score 97/100

Small Package Quotes – Unishippers Edition has a strong security track record. Known vulnerabilities have been patched promptly.

3 known CVEsLast CVE: Feb 23, 2025Updated 24d ago
Risk Assessment

The "small-package-quotes-unishippers-edition" plugin exhibits a mixed security posture. While it demonstrates strengths in areas like using prepared statements for SQL queries and proper output escaping, significant concerns arise from its attack surface and taint analysis. The plugin has a substantial number of entry points, with a concerning 20 of these lacking proper authorization checks, presenting a clear pathway for unauthorized actions. The taint analysis reveals 6 high-severity flows with unsanitized paths, indicating potential vulnerabilities that could be exploited for malicious purposes, such as cross-site scripting or unauthorized data access. Although there are currently no unpatched CVEs, the plugin's history of vulnerabilities, including high and medium severity issues like XSS and SQL injection, suggests a pattern of security weaknesses that require ongoing vigilance. The presence of unpatched vulnerabilities in the past, combined with the identified high-severity taint flows and numerous unprotected entry points, indicates that this plugin, despite some good practices, carries a notable risk that needs to be addressed.

Key Concerns

  • Unprotected AJAX handlers
  • Unprotected REST API routes
  • High severity taint flows
  • Historical high severity CVEs
  • Historical medium severity CVEs
Vulnerabilities
3

Small Package Quotes – Unishippers Edition Security Vulnerabilities

CVEs by Year

3 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1
Medium
2

3 total CVEs

CVE-2025-26918medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Small Package Quotes – Unishippers Edition <= 2.4.9 - Reflected Cross-Site Scripting

Feb 23, 2025 Patched in 2.4.10 (9d)
CVE-2025-26960medium · 5.3Missing Authorization

Small Package Quotes – Unishippers Edition <= 2.4.9 - Missing Authorization

Feb 23, 2025 Patched in 2.4.10 (9d)
CVE-2025-24665high · 7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Small Package Quotes – Unishippers Edition <= 2.4.8 - Unauthenticated SQL Injection

Jan 18, 2025 Patched in 2.4.9 (11d)
Code Analysis
Analyzed Mar 16, 2026

Small Package Quotes – Unishippers Edition Code Analysis

Dangerous Functions
0
Raw SQL Queries
22
45 prepared
Unescaped Output
63
401 escaped
Nonce Checks
13
Capability Checks
16
File Operations
0
External Requests
8
Bundled Libraries
0

SQL Query Safety

67% prepared67 total queries

Output Escaping

86% escaped464 total outputs
Data Flows
10 unsanitized

Data Flow Analysis

23 flows10 with unsanitized paths
<en-coupon-api> (fdo\en-coupon-api.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
20 unprotected

Small Package Quotes – Unishippers Edition Attack Surface

Entry Points50
Unprotected20

AJAX Handlers 49

authwp_ajax_en_unishippers_small_fdo_connection_status_refreshfdo\en-coupon-api.php:9
noprivwp_ajax_en_unishippers_small_fdo_connection_status_refreshfdo\en-coupon-api.php:10
authwp_ajax_en_unishippers_small_va_connection_status_refreshfdo\en-coupon-api.php:12
noprivwp_ajax_en_unishippers_small_va_connection_status_refreshfdo\en-coupon-api.php:13
noprivwp_ajax_unishippers_s_fdfdo\en-coupon-api.php:15
authwp_ajax_unishippers_s_fdfdo\en-coupon-api.php:16
authwp_ajax_eniture_calculate_shipping_rates_adminorder-details\rates\order-rates.php:13
noprivwp_ajax_en_unishippers_small_save_shipping_ruleshipping-rules\shipping-rules-save.php:24
authwp_ajax_en_unishippers_small_save_shipping_ruleshipping-rules\shipping-rules-save.php:25
noprivwp_ajax_en_unishippers_small_edit_shipping_ruleshipping-rules\shipping-rules-save.php:27
authwp_ajax_en_unishippers_small_edit_shipping_ruleshipping-rules\shipping-rules-save.php:28
noprivwp_ajax_en_unishippers_small_delete_shipping_ruleshipping-rules\shipping-rules-save.php:30
authwp_ajax_en_unishippers_small_delete_shipping_ruleshipping-rules\shipping-rules-save.php:31
noprivwp_ajax_en_unishippers_small_update_shipping_rule_statusshipping-rules\shipping-rules-save.php:33
authwp_ajax_en_unishippers_small_update_shipping_rule_statusshipping-rules\shipping-rules-save.php:34
noprivwp_ajax_unishipper_small_test_connectionunishipper_small_test_connection.php:16
authwp_ajax_unishipper_small_test_connectionunishipper_small_test_connection.php:17
authwp_ajax_unishippers_small_activate_hit_to_update_planupdate-plan.php:11
noprivwp_ajax_unishippers_small_activate_hit_to_update_planupdate-plan.php:12
authwp_ajax_sm_get_addresswarehouse-dropship\save_warehouse.php:13
noprivwp_ajax_sm_get_addresswarehouse-dropship\save_warehouse.php:14
authwp_ajax_sm_save_warehousewarehouse-dropship\save_warehouse.php:115
noprivwp_ajax_sm_save_warehousewarehouse-dropship\save_warehouse.php:116
authwp_ajax_sm_edit_warehousewarehouse-dropship\save_warehouse.php:171
noprivwp_ajax_sm_edit_warehousewarehouse-dropship\save_warehouse.php:172
authwp_ajax_sm_delete_warehousewarehouse-dropship\save_warehouse.php:192
noprivwp_ajax_sm_delete_warehousewarehouse-dropship\save_warehouse.php:193
authwp_ajax_sm_save_dropshipwarehouse-dropship\save_warehouse.php:208
noprivwp_ajax_sm_save_dropshipwarehouse-dropship\save_warehouse.php:209
authwp_ajax_sm_edit_dropshipwarehouse-dropship\save_warehouse.php:266
noprivwp_ajax_sm_edit_dropshipwarehouse-dropship\save_warehouse.php:267
authwp_ajax_sm_delete_dropshipwarehouse-dropship\save_warehouse.php:287
noprivwp_ajax_sm_delete_dropshipwarehouse-dropship\save_warehouse.php:288
noprivwp_ajax_en_wd_get_addresswarehouse-dropship\wild\includes\wild-delivery-save.php:24
authwp_ajax_en_wd_get_addresswarehouse-dropship\wild\includes\wild-delivery-save.php:25
noprivwp_ajax_en_uni_small_wd_save_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:28
authwp_ajax_en_uni_small_wd_save_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:29
noprivwp_ajax_en_uni_small_wd_edit_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:31
authwp_ajax_en_uni_small_wd_edit_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:32
noprivwp_ajax_en_uni_small_wd_delete_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:34
authwp_ajax_en_uni_small_wd_delete_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:35
noprivwp_ajax_en_uni_small_wd_save_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:38
authwp_ajax_en_uni_small_wd_save_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:39
noprivwp_ajax_en_uni_small_wd_edit_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:41
authwp_ajax_en_uni_small_wd_edit_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:42
noprivwp_ajax_en_uni_small_wd_delete_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:44
authwp_ajax_en_uni_small_wd_delete_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:45
noprivwp_ajax_en_uni_small_wd_bulk_delete_locationswarehouse-dropship\wild\includes\wild-delivery-save.php:47
authwp_ajax_en_uni_small_wd_bulk_delete_locationswarehouse-dropship\wild\includes\wild-delivery-save.php:48

REST API Routes 1

POST/wp-json/fdo-company-id/update-statusfdo\en-coupon-api.php:108
WordPress Hooks 96
actionrest_api_initfdo\en-coupon-api.php:17
filteren_fdo_packagefdo\en-sbs.php:8
actionadmin_footerjs\unishipper_small_js.php:19
actionwoocommerce_thankyouorder-details\en-order-export.php:14
actioninitorder-details\en-order-export.php:15
actionen_async_orders_exporting_processorder-details\en-order-export.php:16
filtercron_schedulesorder-details\en-order-export.php:17
actionwoocommerce_order_actionsorder-details\en-order-widget.php:16
actionwoocommerce_order_actionsorder-details\en-unishipper-small-order-widget-details.php:107
filteren_order_accessoriesorder-details\rates\order-rates.php:14
actionbefore_woocommerce_initsmall-package-quotes-unishipper-edition.php:32
filteren_pluginssmall-package-quotes-unishipper-edition.php:45
filteren_woo_plans_notification_actionsmall-package-quotes-unishipper-edition.php:73
filteren_woo_plans_notification_message_actionsmall-package-quotes-unishipper-edition.php:88
actionadmin_initsmall-package-quotes-unishipper-edition.php:116
actionadmin_noticessmall-package-quotes-unishipper-edition.php:127
actionadmin_initsmall-package-quotes-unishipper-edition.php:142
actionadmin_noticessmall-package-quotes-unishipper-edition.php:152
actionadmin_enqueue_scriptssmall-package-quotes-unishipper-edition.php:192
filterplugin_action_linkssmall-package-quotes-unishipper-edition.php:219
actionadmin_enqueue_scriptssmall-package-quotes-unishipper-edition.php:279
actionupgrader_process_completesmall-package-quotes-unishipper-edition.php:375
actioninitsmall-package-quotes-unishipper-edition.php:402
filterwoocommerce_shipping_methodssmall-package-quotes-unishipper-edition.php:407
filterwoocommerce_get_settings_pagessmall-package-quotes-unishipper-edition.php:408
actionwoocommerce_shipping_initsmall-package-quotes-unishipper-edition.php:409
filterwoocommerce_package_ratessmall-package-quotes-unishipper-edition.php:410
filterwoocommerce_shipping_calculator_enable_citysmall-package-quotes-unishipper-edition.php:411
actioninitsmall-package-quotes-unishipper-edition.php:412
actionadmin_initsmall-package-quotes-unishipper-edition.php:414
actionadmin_initsmall-package-quotes-unishipper-edition.php:415
actionadmin_initsmall-package-quotes-unishipper-edition.php:416
actionwp_enqueue_scriptssmall-package-quotes-unishipper-edition.php:421
filterunishippers_small_quotes_plans_suscription_and_featuressmall-package-quotes-unishipper-edition.php:438
filterunishippers_small_plans_notification_linksmall-package-quotes-unishipper-edition.php:464
filteren_check_ground_transit_restrict_statussmall-package-quotes-unishipper-edition.php:500
filteren_wd_update_query_stringstandard-package-addon\instore-pickup-local-delivery\instore-local-delivery.php:17
filteren_wd_origin_array_setstandard-package-addon\instore-pickup-local-delivery\instore-local-delivery.php:18
filteren_wd_standard_plansstandard-package-addon\instore-pickup-local-delivery\instore-local-delivery.php:19
filtersuppress_local_deliverystandard-package-addon\instore-pickup-local-delivery\instore-local-delivery.php:20
filterwoocommerce_product_export_product_column_en_nicknametemplate\csv-export.php:9
filterwoocommerce_product_export_product_column_en_citytemplate\csv-export.php:10
filterwoocommerce_product_export_product_column_en_statetemplate\csv-export.php:11
filterwoocommerce_product_export_product_column_en_ziptemplate\csv-export.php:12
filterwoocommerce_product_export_product_column_en_countrytemplate\csv-export.php:13
filterwoocommerce_product_export_product_column_en_product_freight_classtemplate\csv-export.php:16
filterwoocommerce_product_export_product_column_en_product_freight_class_variationtemplate\csv-export.php:17
filterwoocommerce_product_export_column_namestemplate\csv-export.php:20
filterwoocommerce_product_export_product_default_columnstemplate\csv-export.php:21
filteren_app_common_plan_statustemplate\en-product-detail.php:27
actionwoocommerce_product_options_shippingtemplate\en-product-detail.php:33
actionwoocommerce_process_product_metatemplate\en-product-detail.php:34
actionwoocommerce_product_after_variable_attributestemplate\en-product-detail.php:37
actionwoocommerce_save_product_variationtemplate\en-product-detail.php:38
filterEn_Plugins_dropship_filtertemplate\en-product-detail.php:41
filterEn_Plugins_variable_freight_classification_filtertemplate\en-product-detail.php:42
filtersignature_required_includedtemplate\en-product-detail.php:44
filteren_insurance_filtertemplate\en-product-detail.php:50
actionwoocommerce_product_options_shippingtemplate\en-product-detail.php:55
actionwoocommerce_process_product_metatemplate\en-product-detail.php:56
actionwoocommerce_product_after_variable_attributestemplate\en-product-detail.php:59
actionwoocommerce_save_product_variationtemplate\en-product-detail.php:60
filtersignature_required_includedtemplate\en-product-detail.php:62
actionwoocommerce_product_options_shippingtemplate\en-product-detail.php:377
actionwoocommerce_process_product_metatemplate\en-product-detail.php:378
actionwoocommerce_product_after_variable_attributestemplate\en-product-detail.php:381
actionwoocommerce_save_product_variationtemplate\en-product-detail.php:382
filteren_small_package_quotes_fieldstemplate\en-product-detail.php:385
actionwoocommerce_product_options_shippingtemplate\products-insurance-option.php:30
actionwoocommerce_process_product_metatemplate\products-insurance-option.php:33
actionwoocommerce_product_after_variable_attributestemplate\products-insurance-option.php:43
actionwoocommerce_save_product_variationtemplate\products-insurance-option.php:46
actionwoocommerce_product_options_shippingtemplate\products-nested-options.php:32
actionwoocommerce_process_product_metatemplate\products-nested-options.php:35
actionwoocommerce_product_after_variable_attributestemplate\products-nested-options.php:46
actionwoocommerce_save_product_variationtemplate\products-nested-options.php:50
actionwoocommerce_product_options_shippingtemplate\products-options.php:30
actionwoocommerce_process_product_metatemplate\products-options.php:33
actionwoocommerce_product_after_variable_attributestemplate\products-options.php:43
actionwoocommerce_save_product_variationtemplate\products-options.php:46
actionwoocommerce_product_options_shippingtemplate\product_detail.php:79
actionwoocommerce_product_after_variable_attributestemplate\product_detail.php:80
filterEn_Plugins_dropship_filtertemplate\product_detail.php:81
actionwoocommerce_save_product_variationtemplate\product_detail.php:201
actionwoocommerce_process_product_metatemplate\product_detail.php:227
filterunishepper_small_domestic_servicesunishipper-small-carriers.php:21
filterunishepper_small_international_servicesunishipper-small-carriers.php:22
filterwoocommerce_product_importer_parsed_dataunishipper_small_admin_filter.php:206
filteren_fdo_image_urls_mergeunishipper_small_group_package.php:380
filterwoocommerce_package_ratesunishipper_small_shipping_class.php:400
filterwoocommerce_package_ratesunishipper_small_shipping_class.php:585
filterwoocommerce_package_ratesunishipper_small_shipping_class.php:608
filterwoocommerce_settings_tabs_arrayunishipper_small_tab_class.php:23
actionadmin_noticesupdate-plan.php:265
filteren_wd_get_addresswarehouse-dropship\get-distance-request.php:21
actionadmin_enqueue_scriptswarehouse-dropship\wild-delivery.php:34

Scheduled Events 1

en_async_orders_exporting_process
Maintenance & Trust

Small Package Quotes – Unishippers Edition Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 11, 2026
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

Small Package Quotes – Unishippers Edition Developer Profile

enituretechnology

29 plugins · 1K total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
11 days
View full developer profile
Detection Fingerprints

How We Detect Small Package Quotes – Unishippers Edition

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/small-package-quotes-unishippers-edition/logs/en-json-tree-view/en-jtv-style.css/wp-content/plugins/small-package-quotes-unishippers-edition/logs/en-json-tree-view/en-jtv-script.js/wp-content/plugins/small-package-quotes-unishippers-edition/shipping-rules/assets/js/shipping_rules.js/wp-content/plugins/small-package-quotes-unishippers-edition/shipping-rules/assets/css/shipping_rules.css/wp-content/plugins/small-package-quotes-unishippers-edition/css/unishipper_small_style.css/wp-content/plugins/small-package-quotes-unishippers-edition/js/wickedpicker.js
Script Paths
wp-content/plugins/small-package-quotes-unishippers-edition/logs/en-json-tree-view/en-jtv-script.jswp-content/plugins/small-package-quotes-unishippers-edition/shipping-rules/assets/js/shipping_rules.jswp-content/plugins/small-package-quotes-unishippers-edition/js/wickedpicker.js
Version Parameters
small-package-quotes-unishippers-edition/logs/en-json-tree-view/en-jtv-style.css?ver=small-package-quotes-unishippers-edition/logs/en-json-tree-view/en-jtv-script.js?ver=small-package-quotes-unishippers-edition/shipping-rules/assets/js/shipping_rules.js?ver=small-package-quotes-unishippers-edition/shipping-rules/assets/css/shipping_rules.css?ver=small-package-quotes-unishippers-edition/css/unishipper_small_style.css?ver=small-package-quotes-unishippers-edition/js/wickedpicker.js?ver=

HTML / DOM Fingerprints

CSS Classes
eniture_plugin_
HTML Comments
<!-- Unishipper Small Plugin -->/** * Array For common Plans Notification On Product Detail Page *//** * Show plan notification on product detail page *//** * Load scripts for Unishippers Small json tree view */+8 more
Data Attributes
en_tree_view_urlen_unishippers_small_sr_scripten_unishippers_small_sr_nonce
JS Globals
unishippers_en_small_jtv_scriptunishippers_en_woo_plans_notification_PDunishippers_en_woo_plans_notification_messageunishippers_small_wc_avaibility_errunishippers_small_check_woo_versionunishippers_small_wc_version_failure+2 more
FAQ

Frequently Asked Questions about Small Package Quotes – Unishippers Edition