
Small Package Quotes – UPS Edition Security & Risk Analysis
wordpress.org/plugins/small-package-quotes-ups-editionReal-time UPS quotes from UPS. Fifteen day free trial.
Is Small Package Quotes – UPS Edition Safe to Use in 2026?
Generally Safe
Score 98/100Small Package Quotes – UPS Edition has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "small-package-quotes-ups-edition" v4.5.29 plugin exhibits a mixed security posture. While it demonstrates good practices such as a high percentage of prepared SQL statements and properly escaped output, several critical areas of concern exist. The static analysis reveals a significant attack surface with 31 entry points, of which 3 are unprotected, specifically 2 AJAX handlers and 1 REST API route lacking authentication or permission checks. Furthermore, the taint analysis identified 5 flows with unsanitized paths, including one of high severity, indicating a potential for vulnerabilities if these flows are exposed to untrusted input. The plugin's vulnerability history shows a single high-severity CVE for SQL Injection, which is currently patched. However, the past occurrence of such a vulnerability, coupled with the identified unsanitized paths, suggests a recurring risk profile.
Key Concerns
- Unprotected AJAX handlers found
- Unprotected REST API route found
- High severity taint flow identified
- Unsanitized paths in taint flows
- Past high severity SQL Injection CVE
Small Package Quotes – UPS Edition Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Small Package Quotes – UPS Edition <= 4.5.16 - Unauthenticated SQL Injection
Small Package Quotes – UPS Edition Release Timeline
Small Package Quotes – UPS Edition Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Small Package Quotes – UPS Edition Attack Surface
AJAX Handlers 30
REST API Routes 1
WordPress Hooks 80
Scheduled Events 1
Maintenance & Trust
Small Package Quotes – UPS Edition Maintenance & Trust
Maintenance Signals
Community Trust
Small Package Quotes – UPS Edition Alternatives
Small Package Quotes – Worldwide Express Edition
small-package-quotes-wwe-edition
Real-time small package (parcel) shipping rates from Worldwide Express. Fifteen day free trial.
Small Package Quotes – Unishippers Edition
small-package-quotes-unishippers-edition
Real-time small package (parcel) shipping rates from Unishippers. Fifteen day free trial.
Small Package Quotes – For Customers of FedEx
small-package-quotes-fedex-edition
Real-time small package (parcel) shipping rates from Fedex. Fifteen day free trial.
Small Package Quotes – Purolator Edition
small-package-quotes-purolator-edition
Real-time small package (parcel) shipping rates from Purolator. Fifteen day free trial.
Small Package Quotes – USPS Edition
small-package-quotes-usps-edition
Real-time small package (parcel) shipping rates from Usps. Fifteen day free trial.
Small Package Quotes – UPS Edition Developer Profile
32 plugins · 1K total installs
How We Detect Small Package Quotes – UPS Edition
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/small-package-quotes-ups-edition/css/ups-small-style.css/wp-content/plugins/small-package-quotes-ups-edition/shipping-rules/assets/js/shipping_rules.js/wp-content/plugins/small-package-quotes-ups-edition/shipping-rules/assets/css/shipping_rules.css/wp-content/plugins/small-package-quotes-ups-edition/logs/en-json-tree-view/en-jtv-style.css/wp-content/plugins/small-package-quotes-ups-edition/logs/en-json-tree-view/en-jtv-script.js/wp-content/plugins/small-package-quotes-ups-edition/shipping-rules/assets/js/shipping_rules.js/wp-content/plugins/small-package-quotes-ups-edition/logs/en-json-tree-view/en-jtv-script.jssmall-package-quotes-ups-edition/css/ups-small-style.css?ver=small-package-quotes-ups-edition/shipping-rules/assets/js/shipping_rules.js?ver=small-package-quotes-ups-edition/shipping-rules/assets/css/shipping_rules.css?ver=small-package-quotes-ups-edition/logs/en-json-tree-view/en-jtv-style.css?ver=small-package-quotes-ups-edition/logs/en-json-tree-view/en-jtv-script.js?ver=HTML / DOM Fingerprints
sr_script