
Advanced FedEx Shipping – Live Rates & Address Validation for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wc-fedex-shippingFedEx Shipping plugin for WooCommerce displays live shipping rates at cart / checkout pages and validates shipping address before allowing to place an …
Is Advanced FedEx Shipping – Live Rates & Address Validation for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Advanced FedEx Shipping – Live Rates & Address Validation for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'wc-fedex-shipping' v1.2.8 presents a generally good security posture based on the provided static analysis. The absence of any CVEs in its history is a positive indicator, suggesting a history of secure development or diligent patching of past issues. The analysis shows a limited attack surface with no registered AJAX handlers, REST API routes, shortcodes, or cron events. Importantly, all SQL queries utilize prepared statements, and there are no file operations or bundled libraries to worry about. The code also demonstrates some level of security awareness with capability checks in place and a decent percentage of output escaping.
However, the presence of the `unserialize` function without explicit checks for its source is a significant concern. If data processed by `unserialize` originates from user input or an untrusted source, it could lead to Remote Code Execution (RCE) vulnerabilities. While taint analysis shows no immediate flows, the potential for misuse remains. Furthermore, the lack of nonce checks on any entry points (although there are none listed) is a weakness if new handlers are ever added. The 59% proper output escaping also means a portion of the output is not being secured, potentially leading to Cross-Site Scripting (XSS) vulnerabilities if the unescaped data is user-controlled.
Overall, the plugin has strengths in its minimal attack surface and secure SQL handling. The primary risks stem from the insecure use of `unserialize` and the partial output escaping. The clean vulnerability history is encouraging, but the identified code signals warrant attention. A balanced conclusion is that while the plugin avoids common pitfalls, the specific findings regarding `unserialize` and output escaping introduce moderate risks that should be addressed.
Key Concerns
- Unsanitized unserialize function
- Partial output escaping (41% not properly escaped)
- Missing nonce checks on potential entry points
Advanced FedEx Shipping – Live Rates & Address Validation for WooCommerce Security Vulnerabilities
Advanced FedEx Shipping – Live Rates & Address Validation for WooCommerce Code Analysis
Dangerous Functions Found
Output Escaping
Advanced FedEx Shipping – Live Rates & Address Validation for WooCommerce Attack Surface
WordPress Hooks 10
Maintenance & Trust
Advanced FedEx Shipping – Live Rates & Address Validation for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Advanced FedEx Shipping – Live Rates & Address Validation for WooCommerce Alternatives
Multi-Carrier Shippo Shipping Rates & Address Validation for WooCommerce
wc-shippo-shipping
Multi-Carrier Shippo shipping plugin for WooCommerce displays live shipping rates at cart / checkout pages, validates shipping address.
Multi-Carrier EasyPost Shipping Methods & Address Validation for WooCommerce
wc-easypost-shipping
EasyPost Shipping plugin for WooCommerce displays live shipping rates at cart / checkout pages.
Multi-Carrier Shipmondo Shipping for WooCommerce
wc-shipmondo-shipping
Multi-Carrier Shipmondo shipping plugin for WooCommerce displays live shipping rates at cart / checkout pages.
WC Hide Shipping Methods
wc-hide-shipping-methods
This plugin automatically hides all other shipping methods when "Free Shipping" is available, while allowing you to retain "Local Picku …
Hide Shipping Method For WooCommerce
hide-shipping-method-for-woocommerce
Allows store owners to hide shipping methods based on specific conditions!
Advanced FedEx Shipping – Live Rates & Address Validation for WooCommerce Developer Profile
14 plugins · 6K total installs
How We Detect Advanced FedEx Shipping – Live Rates & Address Validation for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-fedex-shipping/assets/css/admin.css/wp-content/plugins/wc-fedex-shipping/assets/js/admin.js/wp-content/plugins/wc-fedex-shipping/assets/js/admin.jswc-fedex-shipping/assets/css/admin.css?ver=wc-fedex-shipping/assets/js/admin.js?ver=HTML / DOM Fingerprints
oneteamsoftwareoneteamsoftware_custom_cssoneteamsoftware-icon/*********************************************************************/
/* PROGRAM FlexRC */
/* PROPERTY 3-7170 Ash Cres */
/* OF Vancouver BC V6P 3K7 */
/* */
/* Any usage / copying / extension or modification without */
/* prior authorization is prohibited */
/*********************************************************************//*********************************************************************/
/* PROGRAM (C) 2021 FlexRC */
/* PROPERTY 3-7170 Ash Cres */
/* OF Vancouver, BC V6P3K7 */
/* CANADA */
/* Voice (604) 800-7879 */
/*********************************************************************/data-toggledata-targetoneTeamSoftware