
Small Package Quotes – Unishippers Edition Security & Risk Analysis
wordpress.org/plugins/small-package-quotes-unishippers-editionReal-time small package (parcel) shipping rates from Unishippers. Fifteen day free trial.
Is Small Package Quotes – Unishippers Edition Safe to Use in 2026?
Generally Safe
Score 97/100Small Package Quotes – Unishippers Edition has a strong security track record. Known vulnerabilities have been patched promptly.
The "small-package-quotes-unishippers-edition" plugin exhibits a mixed security posture. While it demonstrates strengths in areas like using prepared statements for SQL queries and proper output escaping, significant concerns arise from its attack surface and taint analysis. The plugin has a substantial number of entry points, with a concerning 20 of these lacking proper authorization checks, presenting a clear pathway for unauthorized actions. The taint analysis reveals 6 high-severity flows with unsanitized paths, indicating potential vulnerabilities that could be exploited for malicious purposes, such as cross-site scripting or unauthorized data access. Although there are currently no unpatched CVEs, the plugin's history of vulnerabilities, including high and medium severity issues like XSS and SQL injection, suggests a pattern of security weaknesses that require ongoing vigilance. The presence of unpatched vulnerabilities in the past, combined with the identified high-severity taint flows and numerous unprotected entry points, indicates that this plugin, despite some good practices, carries a notable risk that needs to be addressed.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- High severity taint flows
- Historical high severity CVEs
- Historical medium severity CVEs
Small Package Quotes – Unishippers Edition Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Small Package Quotes – Unishippers Edition <= 2.4.9 - Reflected Cross-Site Scripting
Small Package Quotes – Unishippers Edition <= 2.4.9 - Missing Authorization
Small Package Quotes – Unishippers Edition <= 2.4.8 - Unauthenticated SQL Injection
Small Package Quotes – Unishippers Edition Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Small Package Quotes – Unishippers Edition Attack Surface
AJAX Handlers 49
REST API Routes 1
WordPress Hooks 96
Scheduled Events 1
Maintenance & Trust
Small Package Quotes – Unishippers Edition Maintenance & Trust
Maintenance Signals
Community Trust
Small Package Quotes – Unishippers Edition Alternatives
Small Package Quotes – Worldwide Express Edition
small-package-quotes-wwe-edition
Real-time small package (parcel) shipping rates from Worldwide Express. Fifteen day free trial.
Small Package Quotes – For Customers of FedEx
small-package-quotes-fedex-edition
Real-time small package (parcel) shipping rates from Fedex. Fifteen day free trial.
Small Package Quotes – Purolator Edition
small-package-quotes-purolator-edition
Real-time small package (parcel) shipping rates from Purolator. Fifteen day free trial.
Small Package Quotes – USPS Edition
small-package-quotes-usps-edition
Real-time small package (parcel) shipping rates from Usps. Fifteen day free trial.
Real Time Shipping Quotes for WooCommerce
real-time-shipping-quotes-for-woocommerce
The Real Time Shipping Quotes for WooCommerce retrieves your negotiated shipping rates
Small Package Quotes – Unishippers Edition Developer Profile
29 plugins · 1K total installs
How We Detect Small Package Quotes – Unishippers Edition
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/small-package-quotes-unishippers-edition/logs/en-json-tree-view/en-jtv-style.css/wp-content/plugins/small-package-quotes-unishippers-edition/logs/en-json-tree-view/en-jtv-script.js/wp-content/plugins/small-package-quotes-unishippers-edition/shipping-rules/assets/js/shipping_rules.js/wp-content/plugins/small-package-quotes-unishippers-edition/shipping-rules/assets/css/shipping_rules.css/wp-content/plugins/small-package-quotes-unishippers-edition/css/unishipper_small_style.css/wp-content/plugins/small-package-quotes-unishippers-edition/js/wickedpicker.jswp-content/plugins/small-package-quotes-unishippers-edition/logs/en-json-tree-view/en-jtv-script.jswp-content/plugins/small-package-quotes-unishippers-edition/shipping-rules/assets/js/shipping_rules.jswp-content/plugins/small-package-quotes-unishippers-edition/js/wickedpicker.jssmall-package-quotes-unishippers-edition/logs/en-json-tree-view/en-jtv-style.css?ver=small-package-quotes-unishippers-edition/logs/en-json-tree-view/en-jtv-script.js?ver=small-package-quotes-unishippers-edition/shipping-rules/assets/js/shipping_rules.js?ver=small-package-quotes-unishippers-edition/shipping-rules/assets/css/shipping_rules.css?ver=small-package-quotes-unishippers-edition/css/unishipper_small_style.css?ver=small-package-quotes-unishippers-edition/js/wickedpicker.js?ver=HTML / DOM Fingerprints
eniture_plugin_<!-- Unishipper Small Plugin -->/**
* Array For common Plans Notification On Product Detail Page
*//**
* Show plan notification on product detail page
*//**
* Load scripts for Unishippers Small json tree view
*/+8 moreen_tree_view_urlen_unishippers_small_sr_scripten_unishippers_small_sr_nonceunishippers_en_small_jtv_scriptunishippers_en_woo_plans_notification_PDunishippers_en_woo_plans_notification_messageunishippers_small_wc_avaibility_errunishippers_small_check_woo_versionunishippers_small_wc_version_failure+2 more