Small Package Quotes – UPS Edition Security & Risk Analysis

wordpress.org/plugins/small-package-quotes-ups-edition

Real-time UPS quotes from UPS. Fifteen day free trial.

50 active installs v4.5.29 PHP + WP 6.6+ Updated Feb 26, 2026
enitureparcel-quotesparcel-ratesshipping-estimatesups
98
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 11, 2025
Safety Verdict

Is Small Package Quotes – UPS Edition Safe to Use in 2026?

Generally Safe

Score 98/100

Small Package Quotes – UPS Edition has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Feb 11, 2025Updated 2mo ago
Risk Assessment

The "small-package-quotes-ups-edition" v4.5.29 plugin exhibits a mixed security posture. While it demonstrates good practices such as a high percentage of prepared SQL statements and properly escaped output, several critical areas of concern exist. The static analysis reveals a significant attack surface with 31 entry points, of which 3 are unprotected, specifically 2 AJAX handlers and 1 REST API route lacking authentication or permission checks. Furthermore, the taint analysis identified 5 flows with unsanitized paths, including one of high severity, indicating a potential for vulnerabilities if these flows are exposed to untrusted input. The plugin's vulnerability history shows a single high-severity CVE for SQL Injection, which is currently patched. However, the past occurrence of such a vulnerability, coupled with the identified unsanitized paths, suggests a recurring risk profile.

Key Concerns

  • Unprotected AJAX handlers found
  • Unprotected REST API route found
  • High severity taint flow identified
  • Unsanitized paths in taint flows
  • Past high severity SQL Injection CVE
Vulnerabilities
1 published

Small Package Quotes – UPS Edition Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2024-13475high · 7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Small Package Quotes – UPS Edition <= 4.5.16 - Unauthenticated SQL Injection

Feb 11, 2025 Patched in 4.5.17 (1d)
Version History

Small Package Quotes – UPS Edition Release Timeline

v4.5.29Current
v4.5.28
v4.5.27
v4.5.26
v4.5.25
v4.5.24
v4.5.23
Code Analysis
Analyzed Apr 16, 2026

Small Package Quotes – UPS Edition Code Analysis

Dangerous Functions
0
Raw SQL Queries
7
54 prepared
Unescaped Output
63
345 escaped
Nonce Checks
13
Capability Checks
21
File Operations
0
External Requests
4
Bundled Libraries
0

SQL Query Safety

89% prepared61 total queries

Output Escaping

85% escaped408 total outputs
Data Flows · Security
5 unsanitized

Data Flow Analysis

14 flows5 with unsanitized paths
save_shipping_rule_ajax (shipping-rules/shipping-rules-save.php:37)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

Small Package Quotes – UPS Edition Attack Surface

Entry Points31
Unprotected3

AJAX Handlers 30

noprivwp_ajax_en_save_shipping_ruleshipping-rules/shipping-rules-save.php:19
authwp_ajax_en_save_shipping_ruleshipping-rules/shipping-rules-save.php:20
noprivwp_ajax_en_edit_shipping_ruleshipping-rules/shipping-rules-save.php:22
authwp_ajax_en_edit_shipping_ruleshipping-rules/shipping-rules-save.php:23
noprivwp_ajax_en_delete_shipping_ruleshipping-rules/shipping-rules-save.php:25
authwp_ajax_en_delete_shipping_ruleshipping-rules/shipping-rules-save.php:26
noprivwp_ajax_en_update_shipping_rule_statusshipping-rules/shipping-rules-save.php:28
authwp_ajax_en_update_shipping_rule_statusshipping-rules/shipping-rules-save.php:29
noprivwp_ajax_ups_s_fdsmall-package-quotes-ups-edition.php:491
authwp_ajax_ups_s_fdsmall-package-quotes-ups-edition.php:492
authwp_ajax_eniture_ups_small_activate_hit_to_update_planupdate-plan.php:10
noprivwp_ajax_eniture_ups_small_activate_hit_to_update_planupdate-plan.php:11
noprivwp_ajax_eniture_ups_small_test_connectionups-small-test-connection.php:13
authwp_ajax_eniture_ups_small_test_connectionups-small-test-connection.php:14
noprivwp_ajax_eniture_wd_get_addresswarehouse-dropship/wild/includes/wild-delivery-save.php:24
authwp_ajax_eniture_wd_get_addresswarehouse-dropship/wild/includes/wild-delivery-save.php:25
noprivwp_ajax_en_ups_small_wd_save_warehousewarehouse-dropship/wild/includes/wild-delivery-save.php:28
authwp_ajax_en_ups_small_wd_save_warehousewarehouse-dropship/wild/includes/wild-delivery-save.php:29
noprivwp_ajax_en_ups_small_wd_edit_warehousewarehouse-dropship/wild/includes/wild-delivery-save.php:31
authwp_ajax_en_ups_small_wd_edit_warehousewarehouse-dropship/wild/includes/wild-delivery-save.php:32
noprivwp_ajax_en_ups_small_wd_delete_warehousewarehouse-dropship/wild/includes/wild-delivery-save.php:34
authwp_ajax_en_ups_small_wd_delete_warehousewarehouse-dropship/wild/includes/wild-delivery-save.php:35
noprivwp_ajax_en_ups_small_wd_save_dropshipwarehouse-dropship/wild/includes/wild-delivery-save.php:38
authwp_ajax_en_ups_small_wd_save_dropshipwarehouse-dropship/wild/includes/wild-delivery-save.php:39
noprivwp_ajax_en_ups_small_wd_edit_dropshipwarehouse-dropship/wild/includes/wild-delivery-save.php:41
authwp_ajax_en_ups_small_wd_edit_dropshipwarehouse-dropship/wild/includes/wild-delivery-save.php:42
noprivwp_ajax_en_ups_small_wd_delete_dropshipwarehouse-dropship/wild/includes/wild-delivery-save.php:44
authwp_ajax_en_ups_small_wd_delete_dropshipwarehouse-dropship/wild/includes/wild-delivery-save.php:45
noprivwp_ajax_en_ups_small_wd_bulk_delete_locationswarehouse-dropship/wild/includes/wild-delivery-save.php:47
authwp_ajax_en_ups_small_wd_bulk_delete_locationswarehouse-dropship/wild/includes/wild-delivery-save.php:48

REST API Routes 1

POST/wp-json/fdo-company-id/update-statussmall-package-quotes-ups-edition.php:539
WordPress Hooks 80
filteren_fdo_packagefdo/en-sbs.php:8
actionwoocommerce_thankyouorder-details/en-order-export.php:18
actioninitorder-details/en-order-export.php:19
actionen_async_orders_exporting_processorder-details/en-order-export.php:20
filtercron_schedulesorder-details/en-order-export.php:21
actionwoocommerce_order_actionsorder-details/en-order-widget.php:22
actionwoocommerce_order_before_calculate_totalsorder-details/rates/order-rates.php:18
filteren_order_accessoriesorder-details/rates/order-rates.php:19
filteren_app_common_plan_statusproduct/en-common-product-detail.php:30
actionwoocommerce_product_options_shippingproduct/en-common-product-detail.php:34
actionwoocommerce_process_product_metaproduct/en-common-product-detail.php:35
actionwoocommerce_product_after_variable_attributesproduct/en-common-product-detail.php:38
actionwoocommerce_save_product_variationproduct/en-common-product-detail.php:39
filteren_insurance_filterproduct/en-common-product-detail.php:42
filteren_app_common_plan_statusproduct/en-product-detail.php:30
actionwoocommerce_product_options_shippingproduct/en-product-detail.php:36
actionwoocommerce_process_product_metaproduct/en-product-detail.php:37
actionwoocommerce_product_after_variable_attributesproduct/en-product-detail.php:40
actionwoocommerce_save_product_variationproduct/en-product-detail.php:41
filterEn_Plugins_dropship_filterproduct/en-product-detail.php:44
filterEn_Plugins_variable_freight_classification_filterproduct/en-product-detail.php:45
actionwoocommerce_product_options_shippingproduct/en-product-detail.php:355
actionwoocommerce_process_product_metaproduct/en-product-detail.php:356
actionwoocommerce_product_after_variable_attributesproduct/en-product-detail.php:359
actionwoocommerce_save_product_variationproduct/en-product-detail.php:360
filteren_small_package_quotes_fieldsproduct/en-product-detail.php:363
actionbefore_woocommerce_initsmall-package-quotes-ups-edition.php:21
filteren_pluginssmall-package-quotes-ups-edition.php:35
filteren_woo_plans_notification_actionsmall-package-quotes-ups-edition.php:60
filteren_woo_plans_notification_message_actionsmall-package-quotes-ups-edition.php:72
filteren_woo_plans_nested_notification_message_actionsmall-package-quotes-ups-edition.php:85
actionadmin_initsmall-package-quotes-ups-edition.php:112
actionadmin_noticessmall-package-quotes-ups-edition.php:120
actionadmin_initsmall-package-quotes-ups-edition.php:132
actionadmin_noticessmall-package-quotes-ups-edition.php:142
actionadmin_enqueue_scriptssmall-package-quotes-ups-edition.php:180
filterplugin_action_linkssmall-package-quotes-ups-edition.php:192
actionadmin_enqueue_scriptssmall-package-quotes-ups-edition.php:217
actionadmin_initsmall-package-quotes-ups-edition.php:265
actionadmin_initsmall-package-quotes-ups-edition.php:266
filterwoocommerce_shipping_methodssmall-package-quotes-ups-edition.php:292
filterwoocommerce_get_settings_pagessmall-package-quotes-ups-edition.php:293
actionwoocommerce_shipping_initsmall-package-quotes-ups-edition.php:294
filterwoocommerce_package_ratessmall-package-quotes-ups-edition.php:295
filterwoocommerce_shipping_calculator_enable_citysmall-package-quotes-ups-edition.php:296
actioninitsmall-package-quotes-ups-edition.php:297
actioninitsmall-package-quotes-ups-edition.php:298
actioninitsmall-package-quotes-ups-edition.php:299
actionupgrader_process_completesmall-package-quotes-ups-edition.php:349
actionadmin_enqueue_scriptssmall-package-quotes-ups-edition.php:354
filtereniture_ups_small_quotes_plans_suscription_and_featuressmall-package-quotes-ups-edition.php:404
filtereniture_ups_small_plans_notification_linksmall-package-quotes-ups-edition.php:436
actionrest_api_initsmall-package-quotes-ups-edition.php:536
filtereniture_check_ground_transit_restrict_statussmall-package-quotes-ups-edition.php:618
filteren_ups_small_wd_update_query_stringstandard-package-addon/instore-pickup-local-delivery/instore-local-delivery.php:17
filteren_ups_small_wd_origin_array_setstandard-package-addon/instore-pickup-local-delivery/instore-local-delivery.php:18
filteren_ups_small_wd_standard_plansstandard-package-addon/instore-pickup-local-delivery/instore-local-delivery.php:19
filtersuppress_local_deliverystandard-package-addon/instore-pickup-local-delivery/instore-local-delivery.php:20
filterwoocommerce_product_export_product_column_en_nicknametemplate/csv-export.php:13
filterwoocommerce_product_export_product_column_en_citytemplate/csv-export.php:14
filterwoocommerce_product_export_product_column_en_statetemplate/csv-export.php:15
filterwoocommerce_product_export_product_column_en_ziptemplate/csv-export.php:16
filterwoocommerce_product_export_product_column_en_countrytemplate/csv-export.php:17
filterwoocommerce_product_export_product_column_en_product_freight_classtemplate/csv-export.php:20
filterwoocommerce_product_export_product_column_en_product_freight_class_variationtemplate/csv-export.php:21
filterwoocommerce_product_export_column_namestemplate/csv-export.php:24
filterwoocommerce_product_export_product_default_columnstemplate/csv-export.php:25
actionwoocommerce_product_options_shippingtemplate/products-nested-options.php:33
actionwoocommerce_process_product_metatemplate/products-nested-options.php:36
actionwoocommerce_product_after_variable_attributestemplate/products-nested-options.php:47
actionwoocommerce_save_product_variationtemplate/products-nested-options.php:51
actionadmin_noticesupdate-plan.php:273
filterwoocommerce_product_importer_parsed_dataups-small-admin-filter.php:207
filteren_fdo_image_urls_mergeups-small-group-package.php:483
filterwoocommerce_package_ratesups-small-shipping-class.php:343
filterwoocommerce_package_ratesups-small-shipping-class.php:522
filterwoocommerce_package_ratesups-small-shipping-class.php:546
filterwoocommerce_settings_tabs_arrayups-small-tab-class.php:25
filtereniture_wd_get_addresswarehouse-dropship/get-distance-request.php:21
actionadmin_enqueue_scriptswarehouse-dropship/wild-delivery.php:32

Scheduled Events 1

en_async_orders_exporting_process
Maintenance & Trust

Small Package Quotes – UPS Edition Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 26, 2026
PHP min version
Downloads8K

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

Small Package Quotes – UPS Edition Developer Profile

enituretechnology

32 plugins · 1K total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
19 days
View full developer profile
Detection Fingerprints

How We Detect Small Package Quotes – UPS Edition

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/small-package-quotes-ups-edition/css/ups-small-style.css/wp-content/plugins/small-package-quotes-ups-edition/shipping-rules/assets/js/shipping_rules.js/wp-content/plugins/small-package-quotes-ups-edition/shipping-rules/assets/css/shipping_rules.css/wp-content/plugins/small-package-quotes-ups-edition/logs/en-json-tree-view/en-jtv-style.css/wp-content/plugins/small-package-quotes-ups-edition/logs/en-json-tree-view/en-jtv-script.js
Script Paths
/wp-content/plugins/small-package-quotes-ups-edition/shipping-rules/assets/js/shipping_rules.js/wp-content/plugins/small-package-quotes-ups-edition/logs/en-json-tree-view/en-jtv-script.js
Version Parameters
small-package-quotes-ups-edition/css/ups-small-style.css?ver=small-package-quotes-ups-edition/shipping-rules/assets/js/shipping_rules.js?ver=small-package-quotes-ups-edition/shipping-rules/assets/css/shipping_rules.css?ver=small-package-quotes-ups-edition/logs/en-json-tree-view/en-jtv-style.css?ver=small-package-quotes-ups-edition/logs/en-json-tree-view/en-jtv-script.js?ver=

HTML / DOM Fingerprints

JS Globals
sr_script
FAQ

Frequently Asked Questions about Small Package Quotes – UPS Edition