Free Shipping Per Package For WooCommerce Security & Risk Analysis

wordpress.org/plugins/wc-free-shipping-per-package

The most Advanced Free Shipping Per Package for WooCommerce plugin that allows you to define flexible Free Shipping scenarios for individual Cart ship …

50 active installs v1.0.14 PHP 7.3+ WP 5.6+ Updated Mar 4, 2026
advanced-free-shippigfree-shippingfree-shipping-per-packagewoocommerce-multi-vendor-shippingwoocommerce-shipping-packages
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Free Shipping Per Package For WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Free Shipping Per Package For WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin "wc-free-shipping-per-package" v1.0.14 exhibits a generally positive security posture with a clean vulnerability history. The static analysis shows no critical or high severity taint flows, no raw SQL queries, and a reasonable percentage of output escaping. The absence of known CVEs and recorded vulnerabilities further strengthens this impression. However, the presence of one instance of the `unserialize` function is a notable concern. While there are no immediate indications of malicious exploitation due to the lack of taint flows, `unserialize` can be a vector for remote code execution if it processes untrusted user input. The plugin also lacks nonce checks and capability checks on its entry points, which, combined with the `unserialize` function, could pose a risk if an attacker can inject serialized data into the environment where the plugin operates.

Despite these concerns, the plugin's strengths lie in its minimal attack surface, the absence of critical vulnerabilities in its history, and the use of prepared statements for SQL. The limited number of external HTTP requests and file operations also reduce potential exposure. The overall security is good, but the identified `unserialize` risk, coupled with the absence of robust input validation and authorization checks on potentially sensitive functions, warrants careful consideration and potential remediation.

Key Concerns

  • Use of unserialize function
  • No nonce checks on entry points
  • Only one capability check
  • Output escaping not fully comprehensive
Vulnerabilities
None known

Free Shipping Per Package For WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Free Shipping Per Package For WooCommerce Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
7
13 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

Dangerous Functions Found

unserialize$data = unserialize($response['body']);includes\Admin\OneTeamSoftware.php:178

Output Escaping

65% escaped20 total outputs
Attack Surface

Free Shipping Per Package For WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_menuincludes\Admin\OneTeamSoftware.php:54
actionadmin_initincludes\Admin\OneTeamSoftware.php:55
actionwoocommerce_settings_savedincludes\FreeShippingPerPackage\Plugin.php:61
actionadmin_menuincludes\FreeShippingPerPackage\Plugin.php:66
filterwoocommerce_shipping_methodsincludes\FreeShippingPerPackage\Plugin.php:71
actioninitincludes\FreeShippingPerPackage\Plugin.php:73
actionadmin_noticesincludes\Utils\PluginDependency.php:33
Maintenance & Trust

Free Shipping Per Package For WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 4, 2026
PHP min version7.3
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

Free Shipping Per Package For WooCommerce Developer Profile

oneteamsoftware

14 plugins · 6K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
97 days
View full developer profile
Detection Fingerprints

How We Detect Free Shipping Per Package For WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-free-shipping-per-package/assets/css/style.css
Script Paths
/wp-content/plugins/wc-free-shipping-per-package/assets/js/script.js
Version Parameters
wc-free-shipping-per-package/assets/css/style.css?ver=wc-free-shipping-per-package/assets/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
oneteamsoftware
HTML Comments
PROGRAM (C) 2022 FlexRC PROPERTY 604-1097 View St OF Victoria, BC, V8V 0G9 CANADA +1 more
Data Attributes
data-i18ndata-numdata-titledata-descriptiondata-extra
FAQ

Frequently Asked Questions about Free Shipping Per Package For WooCommerce