
Small Package Quotes – Worldwide Express Edition Security & Risk Analysis
wordpress.org/plugins/small-package-quotes-wwe-editionReal-time small package (parcel) shipping rates from Worldwide Express. Fifteen day free trial.
Is Small Package Quotes – Worldwide Express Edition Safe to Use in 2026?
Generally Safe
Score 95/100Small Package Quotes – Worldwide Express Edition has a strong security track record. Known vulnerabilities have been patched promptly.
The "small-package-quotes-wwe-edition" v5.3.8 plugin exhibits a mixed security posture. While it demonstrates good practices in areas like output escaping (86%) and prepared statement usage in SQL queries (70%), significant concerns arise from its attack surface. A notable portion of its AJAX handlers (7 out of 37) and a REST API route (1 out of 1) lack proper authentication or permission checks. The taint analysis revealed one high-severity flow, indicating a potential for exploitable vulnerabilities even with the presence of some security checks.
The plugin's historical vulnerability data, with 4 known CVEs including high and medium severity issues like Missing Authorization, Cross-site Scripting, and SQL Injection, is a major red flag. The commonality of these vulnerability types suggests recurring weaknesses in input validation and authorization logic. Although there are currently no unpatched CVEs, the past patterns and the identified high-severity taint flow indicate a need for heightened vigilance. The plugin has shown a history of security flaws that require attention, and the current analysis points to areas that could be exploited if not addressed.
In conclusion, while the plugin implements some solid security measures, the combination of a substantial unprotected attack surface, a high-severity taint flow, and a history of critical vulnerability types presents a notable risk. Users should be cautious, and the developers should prioritize a thorough review and remediation of the identified unprotected entry points and the high-severity taint flow.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API route
- High severity taint flow
- Historically vulnerable to SQL Injection
- Historically vulnerable to XSS
- Historically vulnerable to Missing Authorization
- High number of unprotected entry points
Small Package Quotes – Worldwide Express Edition Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Small Package Quotes – Worldwide Express Edition <= 5.2.19 - Missing Authorization
Small Package Quotes – Worldwide Express Edition <= 5.2.18 - Reflected Cross-Site Scripting
Small Package Quotes – Worldwide Express Edition <= 5.2.18 - Unauthenticated SQL Injection
Small Package Quotes – Worldwide Express Edition <= 5.2.17 - Unauthenticated SQL Injection
Small Package Quotes – Worldwide Express Edition Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Small Package Quotes – Worldwide Express Edition Attack Surface
AJAX Handlers 37
REST API Routes 1
WordPress Hooks 79
Scheduled Events 1
Maintenance & Trust
Small Package Quotes – Worldwide Express Edition Maintenance & Trust
Maintenance Signals
Community Trust
Small Package Quotes – Worldwide Express Edition Alternatives
Small Package Quotes – Unishippers Edition
small-package-quotes-unishippers-edition
Real-time small package (parcel) shipping rates from Unishippers. Fifteen day free trial.
Small Package Quotes – For Customers of FedEx
small-package-quotes-fedex-edition
Real-time small package (parcel) shipping rates from Fedex. Fifteen day free trial.
Small Package Quotes – Purolator Edition
small-package-quotes-purolator-edition
Real-time small package (parcel) shipping rates from Purolator. Fifteen day free trial.
Small Package Quotes – USPS Edition
small-package-quotes-usps-edition
Real-time small package (parcel) shipping rates from Usps. Fifteen day free trial.
Real Time Shipping Quotes for WooCommerce
real-time-shipping-quotes-for-woocommerce
The Real Time Shipping Quotes for WooCommerce retrieves your negotiated shipping rates
Small Package Quotes – Worldwide Express Edition Developer Profile
29 plugins · 1K total installs
How We Detect Small Package Quotes – Worldwide Express Edition
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/small-package-quotes-wwe-edition/js/en-speedship.js/wp-content/plugins/small-package-quotes-wwe-edition/logs/en-json-tree-view/en-jtv-style.css/wp-content/plugins/small-package-quotes-wwe-edition/logs/en-json-tree-view/en-jtv-script.js/wp-content/plugins/small-package-quotes-wwe-edition/js/en-speedship.jssmall-package-quotes-wwe-edition/js/en-speedship.js?ver=small-package-quotes-wwe-edition/logs/en-json-tree-view/en-jtv-style.css?ver=small-package-quotes-wwe-edition/logs/en-json-tree-view/en-jtv-script.js?ver=HTML / DOM Fingerprints
eniture-admin-settings<!-- Small Package Quotes for WooCommerce - Worldwide Express Edition --><!-- Copyright (C) 2016 Eniture LLC d/b/a Eniture Technology --><!-- This program is free software; you can redistribute it and/or --><!-- modify it under the terms of the GNU General Public License version 2 -->+9 moreen_tree_view_urlen_speedship_admin_script