
SMSA Shipping (official) Security & Risk Analysis
wordpress.org/plugins/smsa-shipping-officialThis plugin integrates SMSA Express Shipping for easy shipment tracking and management.
Is SMSA Shipping (official) Safe to Use in 2026?
Generally Safe
Score 98/100SMSA Shipping (official) has a strong security track record. Known vulnerabilities have been patched promptly.
The smsa-shipping-official plugin v2.4 exhibits a mixed security posture. While it demonstrates good practices in areas like using prepared statements for all SQL queries and a high percentage of properly escaped output, significant concerns arise from its attack surface and historical vulnerability. The presence of three AJAX handlers, two of which lack proper authentication checks, presents a direct avenue for potential exploitation. This, combined with two identified flows with unsanitized paths in the taint analysis, suggests a risk of unauthorized actions or data manipulation if these entry points are not secured. The plugin also has a history of a high-severity vulnerability related to External Control of File Name or Path, even though it is currently patched. This historical pattern, alongside the current lack of robust authorization on two AJAX endpoints, indicates a recurring weakness that requires vigilant monitoring and remediation.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Historical high-severity vulnerability
- Bundled library: DataTables
- Bundled library: TCPDF
SMSA Shipping (official) Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
SMSA Shipping(official) <= 2.3 - Authenticated (Subscriber+) Arbitrary File Deletion
SMSA Shipping (official) Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
SMSA Shipping (official) Attack Surface
AJAX Handlers 3
WordPress Hooks 15
Maintenance & Trust
SMSA Shipping (official) Maintenance & Trust
Maintenance Signals
Community Trust
SMSA Shipping (official) Developer Profile
1 plugin · 400 total installs
How We Detect SMSA Shipping (official)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smsa-shipping-official/css/smsa-style.css/wp-content/plugins/smsa-shipping-official/css/dataTables.bootstrap5.min.css/wp-content/plugins/smsa-shipping-official/js/jquery.dataTables.min.js/wp-content/plugins/smsa-shipping-official/js/dataTables.bootstrap5.min.js/wp-content/plugins/smsa-shipping-official/js/smsa-script.jsjquery.dataTables.min.jsdataTables.bootstrap5.min.jssmsa-script.jssmsa-shipping-official/css/smsa-style.css?ver=smsa-shipping-official/css/dataTables.bootstrap5.min.css?ver=smsa-shipping-official/js/jquery.dataTables.min.js?ver=smsa-shipping-official/js/dataTables.bootstrap5.min.js?ver=smsa-shipping-official/js/smsa-script.js?ver=HTML / DOM Fingerprints
data-noncesmsa_vars/wp-json/smsa-shipping-official/v1/get_tracking_info