
Multi-Carrier ShipEngine Shipping Rates & Address Validation for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wc-shipengine-shippingShipEngine Shipping will help your business to access deeply discounted rates across multiple carriers and display them in the cart and checkout pages …
Is Multi-Carrier ShipEngine Shipping Rates & Address Validation for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Multi-Carrier ShipEngine Shipping Rates & Address Validation for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wc-shipengine-shipping" plugin, version 1.3.18, exhibits a generally positive security posture with no recorded vulnerabilities or CVEs. The static analysis reveals a minimal attack surface, with no unprotected AJAX handlers, REST API routes, shortcodes, or cron events identified. Code signals indicate a responsible approach to data handling, with all SQL queries using prepared statements and a majority of outputs being properly escaped. The plugin also performs necessary capability checks for its operations.
However, there are a few areas for concern. The presence of the `unserialize` function is a potential risk, as it can lead to remote code execution if used with unsanitized user-supplied data. Although no taint flows were detected in this analysis, the inherent risk of `unserialize` should not be overlooked. Additionally, the lack of nonce checks on any entry points, while the entry point count is zero, signifies a potential oversight that could be exploited if new entry points are introduced or if the current analysis missed any subtle ones.
Overall, the plugin has a strong foundation with no known historical vulnerabilities. The minimal attack surface and adherence to prepared statements are commendable. Nevertheless, the use of `unserialize` without further context on its usage and the absence of nonce checks are potential weaknesses that warrant attention to maintain a robust security profile.
Key Concerns
- Dangerous function `unserialize` found
- No nonce checks on entry points
Multi-Carrier ShipEngine Shipping Rates & Address Validation for WooCommerce Security Vulnerabilities
Multi-Carrier ShipEngine Shipping Rates & Address Validation for WooCommerce Code Analysis
Dangerous Functions Found
Output Escaping
Multi-Carrier ShipEngine Shipping Rates & Address Validation for WooCommerce Attack Surface
WordPress Hooks 12
Maintenance & Trust
Multi-Carrier ShipEngine Shipping Rates & Address Validation for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Multi-Carrier ShipEngine Shipping Rates & Address Validation for WooCommerce Alternatives
ChitChats Shipping for WooCommerce
wc-chitchats-shipping
Estimates ChitChats shipping rates in the cart, lets customers to choose shipping method.
Modern Cart – WooCommerce Side Cart & Popup Cart
modern-cart
Modern Cart gives your store a side cart and free shipping bar so shoppers stay on the page, spend more to unlock rewards, and check out in seconds.
Multi-Carrier ShipStation Shipping Rates for WooCommerce
wc-shipstation-shipping
Take your integration with ShipStation shipping service to the next level by displaying live shipping rates in the cart and checkout pages.
API2Cart Live Shipping 4 Woocommerce
api2cart-live-shipping-4-woocommerce
This plugin allows to use of real-time shipping rates provided by third-party shipping services.
Checkout Shipping Message Add-on for WooCommerce
checkout-shipping-message-add-on-for-woocommerce
This add-on will allow you to add a custom message to WooCommerce under that shipping totals shipping section of your checkout.
Multi-Carrier ShipEngine Shipping Rates & Address Validation for WooCommerce Developer Profile
14 plugins · 6K total installs
How We Detect Multi-Carrier ShipEngine Shipping Rates & Address Validation for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-shipengine-shipping/assets/css/shipengine-shipping.css/wp-content/plugins/wc-shipengine-shipping/assets/js/shipengine-shipping.js/wp-content/plugins/wc-shipengine-shipping/assets/js/shipengine-shipping.jswc-shipengine-shipping/assets/css/shipengine-shipping.css?ver=wc-shipengine-shipping/assets/js/shipengine-shipping.js?ver=HTML / DOM Fingerprints
oneteamsoftwareoneteamsoftware-admin-cssPROGRAM (C) 2022 FlexRC PROPERTY 604-1097 View St OF Victoria, BC, V8V 0G9 CANADA +1 moredata-admin-menu-pagedata-main-menu-id