Multi-Carrier ShipEngine Shipping Rates & Address Validation for WooCommerce Security & Risk Analysis

wordpress.org/plugins/wc-shipengine-shipping

ShipEngine Shipping will help your business to access deeply discounted rates across multiple carriers and display them in the cart and checkout pages …

10 active installs v1.3.18 PHP 7.3+ WP 5.6+ Updated Mar 4, 2026
cartebayshippingshipstationwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Multi-Carrier ShipEngine Shipping Rates & Address Validation for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Multi-Carrier ShipEngine Shipping Rates & Address Validation for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "wc-shipengine-shipping" plugin, version 1.3.18, exhibits a generally positive security posture with no recorded vulnerabilities or CVEs. The static analysis reveals a minimal attack surface, with no unprotected AJAX handlers, REST API routes, shortcodes, or cron events identified. Code signals indicate a responsible approach to data handling, with all SQL queries using prepared statements and a majority of outputs being properly escaped. The plugin also performs necessary capability checks for its operations.

However, there are a few areas for concern. The presence of the `unserialize` function is a potential risk, as it can lead to remote code execution if used with unsanitized user-supplied data. Although no taint flows were detected in this analysis, the inherent risk of `unserialize` should not be overlooked. Additionally, the lack of nonce checks on any entry points, while the entry point count is zero, signifies a potential oversight that could be exploited if new entry points are introduced or if the current analysis missed any subtle ones.

Overall, the plugin has a strong foundation with no known historical vulnerabilities. The minimal attack surface and adherence to prepared statements are commendable. Nevertheless, the use of `unserialize` without further context on its usage and the absence of nonce checks are potential weaknesses that warrant attention to maintain a robust security profile.

Key Concerns

  • Dangerous function `unserialize` found
  • No nonce checks on entry points
Vulnerabilities
None known

Multi-Carrier ShipEngine Shipping Rates & Address Validation for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Multi-Carrier ShipEngine Shipping Rates & Address Validation for WooCommerce Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
10
18 escaped
Nonce Checks
0
Capability Checks
1
File Operations
2
External Requests
3
Bundled Libraries
0

Dangerous Functions Found

unserialize$data = unserialize($response['body']);includes\Admin\OneTeamSoftware.php:179

Output Escaping

64% escaped28 total outputs
Attack Surface

Multi-Carrier ShipEngine Shipping Rates & Address Validation for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionadmin_menuincludes\Admin\OneTeamSoftware.php:55
actionadmin_initincludes\Admin\OneTeamSoftware.php:56
actionadmin_initincludes\Shipping\AbstractShippingMethod.php:24
filterhttp_request_timeoutincludes\Shipping\Adapter\AbstractAdapter.php:82
actionadmin_menuincludes\Shipping\Plugin.php:96
filterwoocommerce_shipping_methodsincludes\Shipping\Plugin.php:100
actionplugins_loadedincludes\Shipping\Plugin.php:107
actionplugins_loadedincludes\Shipping\Plugin.php:109
actionwp_loadedincludes\Shipping\Plugin.php:110
actionwoocommerce_after_checkout_validationincludes\Shipping\Plugin.php:111
filterwoocommerce_billing_fieldsincludes\Shipping\Plugin.php:112
filterwoocommerce_shipping_fieldsincludes\Shipping\Plugin.php:113
Maintenance & Trust

Multi-Carrier ShipEngine Shipping Rates & Address Validation for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 4, 2026
PHP min version7.3
Downloads2K

Community Trust

Rating20/100
Number of ratings1
Active installs10
Developer Profile

Multi-Carrier ShipEngine Shipping Rates & Address Validation for WooCommerce Developer Profile

oneteamsoftware

14 plugins · 6K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
97 days
View full developer profile
Detection Fingerprints

How We Detect Multi-Carrier ShipEngine Shipping Rates & Address Validation for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-shipengine-shipping/assets/css/shipengine-shipping.css/wp-content/plugins/wc-shipengine-shipping/assets/js/shipengine-shipping.js
Script Paths
/wp-content/plugins/wc-shipengine-shipping/assets/js/shipengine-shipping.js
Version Parameters
wc-shipengine-shipping/assets/css/shipengine-shipping.css?ver=wc-shipengine-shipping/assets/js/shipengine-shipping.js?ver=

HTML / DOM Fingerprints

CSS Classes
oneteamsoftwareoneteamsoftware-admin-css
HTML Comments
PROGRAM (C) 2022 FlexRC PROPERTY 604-1097 View St OF Victoria, BC, V8V 0G9 CANADA +1 more
Data Attributes
data-admin-menu-pagedata-main-menu-id
FAQ

Frequently Asked Questions about Multi-Carrier ShipEngine Shipping Rates & Address Validation for WooCommerce