
Webshipper – Automated Shipping Security & Risk Analysis
wordpress.org/plugins/webshipper-automated-shippingAutomated shipping for WooCommerce.
Is Webshipper – Automated Shipping Safe to Use in 2026?
Generally Safe
Score 100/100Webshipper – Automated Shipping has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "webshipper-automated-shipping" v1.5.14 exhibits a generally good security posture with some notable exceptions. The static analysis reveals excellent practices regarding SQL query sanitization and output escaping, with 100% of SQL queries using prepared statements and 97% of outputs properly escaped. The absence of known CVEs in its vulnerability history is also a strong positive indicator. However, the plugin's attack surface is a significant concern, featuring two unprotected AJAX handlers. This lack of authentication on entry points presents a clear risk, as any unauthenticated user could potentially trigger these handlers, leading to unintended actions or information disclosure.
The taint analysis shows no critical or high-severity unsanitized paths, which is reassuring. The plugin does use external HTTP requests, which can be a vector for vulnerabilities if not handled carefully, but no specific issues were flagged in the static analysis. The presence of the Guzzle library is noted, and while not inherently a vulnerability, it's important to ensure it's kept up-to-date to avoid potential risks associated with bundled libraries. The overall conclusion is that while the core code quality in terms of data handling and sanitization is strong, the critical oversight of lacking authentication on AJAX handlers significantly elevates the risk profile. Addressing these unprotected entry points should be the highest priority.
Key Concerns
- AJAX handlers without authentication
- No nonce checks on AJAX handlers
- Bundled Guzzle library
Webshipper – Automated Shipping Security Vulnerabilities
Webshipper – Automated Shipping Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Webshipper – Automated Shipping Attack Surface
AJAX Handlers 2
WordPress Hooks 11
Maintenance & Trust
Webshipper – Automated Shipping Maintenance & Trust
Maintenance Signals
Community Trust
Webshipper – Automated Shipping Alternatives
DEPRECATED – Shipmondo – A complete shipping solution for WooCommerce
pakkelabels-for-woocommerce
Shipmondo for WooCommerce – Provide pick-up points in checkout and manage shipping easily
Smart Send Logistics
smart-send-logistics
Complete WooCommerce shipping solution for PostNord, GLS, DAO, Burd, Budbee and Bring.
BuckyDrop – Branded Dropshipping for WooCommerce
buckydrop-dropshipping-for-woocommerce
Find dropshipping products from Alibaba/1688/Taobao/Weidian/Yupoo/Poizon, import them to your WooCommerce store, and automate your order processes.
Wetail Shipping Integration
wetail-shipping
A quick and effective integration to print shipping labels from WooCommerce order admin. Support for Postnord, DHL, Schenker, Budbee, and Best Transpo …
Automated PostNord label and pickup – HPOS Supported
automated-postnord-shipping
Automated PostNord Shipping plugin for WooCommerce. Generate shipping labels, track orders, and manage pickups automatically.
Webshipper – Automated Shipping Developer Profile
1 plugin · 400 total installs
How We Detect Webshipper – Automated Shipping
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/webshipper-automated-shipping/webshipper.css/wp-content/plugins/webshipper-automated-shipping/webshipper.js/wp-content/plugins/webshipper-automated-shipping/webshipper.jswebshipper-automated-shipping/webshipper.css?ver=webshipper-automated-shipping/webshipper.js?ver=HTML / DOM Fingerprints
webshipper-drop-point-selector<!-- Webshipper Drop Point Selector --><!-- Webshipper API Error: --><!-- Webshipper plugin activated but not configured. Configure it now under WooCommerce > Settings > Shipping > Shipping options -->data-ws-drop-point-iddata-ws-drop-point-namedata-ws-drop-point-address-1data-ws-drop-point-citydata-ws-drop-point-zipdata-ws-drop-point-country-code+1 moreWebshipperAPI