TURBO – Shipping Rules for WooCommerce Security & Risk Analysis

wordpress.org/plugins/turbo-shipping-rules-for-woocommerce

Manage WooCommerce shipping with custom states and weight-based methods filtered by product categories. Fast and flexible.

0 active installs v1.0.2 PHP 7.2+ WP 5.4+ Updated Mar 16, 2026
custom-shippingshipping-rulesshipping-zonesweight-based-shippingwoocommerce-shipping
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TURBO – Shipping Rules for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

TURBO – Shipping Rules for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "turbo-shipping-rules-for-woocommerce" plugin v1.0.2 exhibits a strong security posture based on the provided static analysis and vulnerability history. All identified entry points (AJAX handlers) are protected with nonce and capability checks, indicating a good understanding of WordPress security best practices. The absence of dangerous functions, file operations, and external HTTP requests further bolsters its security. SQL queries are exclusively handled using prepared statements, and all output is properly escaped, mitigating common web vulnerabilities like SQL injection and Cross-Site Scripting.

The vulnerability history is also exceptionally clean, with no recorded CVEs of any severity. This lack of past vulnerabilities, combined with the robust static analysis findings, suggests the plugin has been well-developed and maintained with security in mind. The plugin's limited attack surface, with only three AJAX handlers and no REST API routes, shortcodes, or cron events, also contributes to its overall safety.

In conclusion, this plugin appears to be very secure. The developers have implemented critical security controls effectively. The only minor point of consideration is the presence of one external HTTP request, which, while not inherently a vulnerability, warrants careful monitoring for potential future risks if the external service were compromised or if the request itself lacked proper security measures. However, based on the provided data, the plugin represents a low-risk addition to a WordPress site.

Vulnerabilities
None known

TURBO – Shipping Rules for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

TURBO – Shipping Rules for WooCommerce Release Timeline

v1.0.2Current
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

TURBO – Shipping Rules for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
113 escaped
Nonce Checks
12
Capability Checks
11
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped113 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

4 flows
<state-add-form> (includes/state-add-form.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

TURBO – Shipping Rules for WooCommerce Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_tsrfw_get_zone_regionsincludes/admin-shipping-zones.php:11
authwp_ajax_wppulse_reason_submitwppulse/wppulse-plugin-analytics-engine-sdk.php:44
authwp_ajax_wppulse_reason_skipwppulse/wppulse-plugin-analytics-engine-sdk.php:45
WordPress Hooks 16
actionadmin_menuincludes/admin-menu.php:3
filterwoocommerce_get_sections_shippingincludes/admin-shipping-zones.php:7
actionwoocommerce_settings_shippingincludes/admin-shipping-zones.php:8
actionwoocommerce_update_options_shippingincludes/admin-shipping-zones.php:9
actionadmin_enqueue_scriptsincludes/admin-shipping-zones.php:10
actioninitincludes/register-post-type.php:3
filterwoocommerce_shipping_methodsincludes/weight-based-shipping.php:7
actionwoocommerce_shipping_initincludes/weight-based-shipping.php:12
actionadmin_enqueue_scriptsincludes/weight-based-shipping.php:145
actionbefore_woocommerce_initturbo-shipping-rules-for-woocommerce.php:23
actionplugins_loadedturbo-shipping-rules-for-woocommerce.php:69
actionadmin_noticesturbo-shipping-rules-for-woocommerce.php:74
filterwoocommerce_statesturbo-shipping-rules-for-woocommerce.php:86
actionupgrader_process_completewppulse/wppulse-plugin-analytics-engine-sdk.php:38
actiondeleted_pluginwppulse/wppulse-plugin-analytics-engine-sdk.php:39
actionadmin_footerwppulse/wppulse-plugin-analytics-engine-sdk.php:43
Maintenance & Trust

TURBO – Shipping Rules for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 16, 2026
PHP min version7.2
Downloads278

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

TURBO – Shipping Rules for WooCommerce Developer Profile

Turbo Addons

5 plugins · 12K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
104 days
View full developer profile
Detection Fingerprints

How We Detect TURBO – Shipping Rules for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/turbo-shipping-rules-for-woocommerce/assets/css/admin.css/wp-content/plugins/turbo-shipping-rules-for-woocommerce/assets/js/admin.js
Script Paths
/wp-content/plugins/turbo-shipping-rules-for-woocommerce/assets/js/admin.js
Version Parameters
turbo-shipping-rules-for-woocommerce/assets/css/admin.css?ver=turbo-shipping-rules-for-woocommerce/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
tsrfw-admin-shipping-zones
HTML Comments
<!-- New file for custom shipping zones --><!-- New: include Weight Based Shipping --><!-- phpcs:ignore WordPress.Security.NonceVerification.Recommended --><!-- Select a Shipping Zone. -->
Data Attributes
id="tsrfw_shipping_zone_name"id="tsrfw_shipping_zone_regions"
JS Globals
tsrfw_admin_params
REST Endpoints
/wp-json/tsrfw/v1/get_zone_regions
FAQ

Frequently Asked Questions about TURBO – Shipping Rules for WooCommerce