
WooReer Security & Risk Analysis
wordpress.org/plugins/wcsdmWooReer calculates shipping rates based on distance via Google Maps, Mapbox, DistanceMatrix.ai, Geoapify, or HERE.
Is WooReer Safe to Use in 2026?
Generally Safe
Score 100/100WooReer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "wcsdm" v3.1.4 demonstrates a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength, indicating a minimal attack surface. Furthermore, the code signals show good practices with 100% of SQL queries using prepared statements and a very high percentage of output being properly escaped. The lack of dangerous functions and file operations also contributes positively to its security. The vulnerability history being completely clear of any CVEs further solidifies its current security standing.
However, there are a few areas that warrant attention. The presence of external HTTP requests, while not inherently a vulnerability, introduces potential risks if the target endpoints are compromised or if the data sent is not handled securely. The limited number of nonce and capability checks, especially given the absence of observed taint flows, might suggest an assumption that no sensitive operations are being performed, or that these checks are implemented elsewhere in a way not captured by this analysis. The lack of identified taint flows is positive, but it's important to remember that static analysis might not uncover all dynamic vulnerabilities.
In conclusion, "wcsdm" v3.1.4 appears to be a well-secured plugin with a robust foundation. Its minimal attack surface and adherence to secure coding practices for SQL and output escaping are commendable. The absence of past vulnerabilities is a significant positive. The primary areas for consideration are the management of external HTTP requests and a potential lack of comprehensive authorization checks that could be a concern if the plugin's functionality evolves to include more sensitive operations.
Key Concerns
- External HTTP requests present potential risks
- Limited capability checks found
- Limited nonce checks found
WooReer Security Vulnerabilities
WooReer Release Timeline
WooReer Code Analysis
Output Escaping
WooReer Attack Surface
WordPress Hooks 20
Maintenance & Trust
WooReer Maintenance & Trust
Maintenance Signals
Community Trust
WooReer Alternatives
Calculate Prices based on Distance For WooCommerce
calculate-prices-based-on-distance-for-woocommerce
The best WooCommerce Distance Rate Shipping alternative. Secure delivery fee calculation by KM/Mile via Google Maps. Supports Block Checkout & Del …
Gellum Delivery Calculator for WooCommerce
gellum-delivery-calculator
Calculates shipping costs for WooCommerce based on GPS distance with GeoJSON limited areas. Shortcode [gellumdcw_map]
Easyship WooCommerce Shipping Rates
easyship-woocommerce-shipping-rates
Easyship for WooCommerce saves you time and money with live courier rates, seamless checkout, automated taxes & duties, and shipping label creation.
Product page shipping calculator for WooCommerce
product-page-shipping-calculator-for-woocommerce
This plugin allows you to show the shipping methods available on the product page for WooCommerce, so customers can see if shipping is available to th …
Shipday Local Delivery for WooCommerce
shipday-for-woocommerce
Shipday adds local delivery and pickup workflows, dispatch sync, and checkout date/time selection to WooCommerce.
WooReer Developer Profile
6 plugins · 1K total installs
How We Detect WooReer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wcsdm/assets/css/backend.css/wp-content/plugins/wcsdm/assets/js/backend.js/wp-content/plugins/wcsdm/assets/js/backend.jsHTML / DOM Fingerprints
wcsdm-shipping-method-settings<!-- WooReer shipping method settings --><!-- Initialized by WooReer plugin -->data-plugin-path="wcsdm"data-wcsdm-version="3.1.4"window.wcsdm_backend_params/wp-json/wcsdm/v1/shipping