Webshipper – Automated Shipping Security & Risk Analysis

wordpress.org/plugins/webshipper-automated-shipping

Automated shipping for WooCommerce.

400 active installs v1.5.14 PHP + WP 3.7+ Updated Dec 18, 2025
automated-shippingbluewaterpostnordshippingvalgfrit-afhentningssted
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Webshipper – Automated Shipping Safe to Use in 2026?

Generally Safe

Score 100/100

Webshipper – Automated Shipping has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The plugin "webshipper-automated-shipping" v1.5.14 exhibits a generally good security posture with some notable exceptions. The static analysis reveals excellent practices regarding SQL query sanitization and output escaping, with 100% of SQL queries using prepared statements and 97% of outputs properly escaped. The absence of known CVEs in its vulnerability history is also a strong positive indicator. However, the plugin's attack surface is a significant concern, featuring two unprotected AJAX handlers. This lack of authentication on entry points presents a clear risk, as any unauthenticated user could potentially trigger these handlers, leading to unintended actions or information disclosure.

The taint analysis shows no critical or high-severity unsanitized paths, which is reassuring. The plugin does use external HTTP requests, which can be a vector for vulnerabilities if not handled carefully, but no specific issues were flagged in the static analysis. The presence of the Guzzle library is noted, and while not inherently a vulnerability, it's important to ensure it's kept up-to-date to avoid potential risks associated with bundled libraries. The overall conclusion is that while the core code quality in terms of data handling and sanitization is strong, the critical oversight of lacking authentication on AJAX handlers significantly elevates the risk profile. Addressing these unprotected entry points should be the highest priority.

Key Concerns

  • AJAX handlers without authentication
  • No nonce checks on AJAX handlers
  • Bundled Guzzle library
Vulnerabilities
None known

Webshipper – Automated Shipping Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Webshipper – Automated Shipping Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
65 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

97% escaped67 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
show_on_order (webshipper-automated-shipping.php:235)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Webshipper – Automated Shipping Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_get_shopswebshipper-automated-shipping.php:505
noprivwp_ajax_get_shopswebshipper-automated-shipping.php:506
WordPress Hooks 11
actionwoocommerce_shipping_initwebshipper-automated-shipping.php:33
filterwoocommerce_shipping_methodswebshipper-automated-shipping.php:45
actionwoocommerce_review_order_before_order_totalwebshipper-automated-shipping.php:56
actionwoocommerce_checkout_processwebshipper-automated-shipping.php:76
actionwoocommerce_checkout_update_order_metawebshipper-automated-shipping.php:141
actionwoocommerce_order_status_changedwebshipper-automated-shipping.php:177
filterhandle_bulk_actions-edit-shop_orderwebshipper-automated-shipping.php:201
actionwoocommerce_admin_order_data_after_order_detailswebshipper-automated-shipping.php:233
filterwoocommerce_get_settings_shippingwebshipper-automated-shipping.php:352
actionwp_enqueue_scriptswebshipper-automated-shipping.php:440
actionadmin_enqueue_scriptswebshipper-automated-shipping.php:443
Maintenance & Trust

Webshipper – Automated Shipping Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 18, 2025
PHP min version
Downloads14K

Community Trust

Rating100/100
Number of ratings1
Active installs400
Developer Profile

Webshipper – Automated Shipping Developer Profile

nShift

1 plugin · 400 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Webshipper – Automated Shipping

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/webshipper-automated-shipping/webshipper.css/wp-content/plugins/webshipper-automated-shipping/webshipper.js
Script Paths
/wp-content/plugins/webshipper-automated-shipping/webshipper.js
Version Parameters
webshipper-automated-shipping/webshipper.css?ver=webshipper-automated-shipping/webshipper.js?ver=

HTML / DOM Fingerprints

CSS Classes
webshipper-drop-point-selector
HTML Comments
<!-- Webshipper Drop Point Selector --><!-- Webshipper API Error: --><!-- Webshipper plugin activated but not configured. Configure it now under WooCommerce > Settings > Shipping > Shipping options -->
Data Attributes
data-ws-drop-point-iddata-ws-drop-point-namedata-ws-drop-point-address-1data-ws-drop-point-citydata-ws-drop-point-zipdata-ws-drop-point-country-code+1 more
JS Globals
WebshipperAPI
FAQ

Frequently Asked Questions about Webshipper – Automated Shipping