Free Shipping Bar for WooCommerce Security & Risk Analysis

wordpress.org/plugins/woo-free-shipping-bar

Motivate customers to reach the free shipping threshold with a visual free shipping bar, dynamic messages and progress tracker.

2K active installs v1.2.12 PHP 7.0+ WP 5.0+ Updated Feb 27, 2026
promotion-barshipping-barwidgetwoocommerce-free-shipping-bar
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Free Shipping Bar for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Free Shipping Bar for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "woo-free-shipping-bar" plugin version 1.2.12 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The plugin effectively utilizes prepared statements for all SQL queries, has a high rate of proper output escaping, and incorporates a significant number of nonce and capability checks. The absence of known CVEs and a clean vulnerability history further bolster this positive assessment, suggesting a mature and well-maintained codebase.

While the attack surface is small with no unprotected entry points, the presence of two AJAX handlers, even with security checks, warrants a minor note. The two external HTTP requests, though not analyzed for potential vulnerabilities, are a common feature of plugins and do not immediately indicate a high risk without further context. The lack of critical or high severity findings in taint analysis is particularly encouraging, indicating that data flows are generally handled securely within the plugin.

In conclusion, "woo-free-shipping-bar" v1.2.12 appears to be a secure plugin. Its robust use of WordPress security best practices, such as prepared statements and output escaping, combined with a clean vulnerability record, suggests minimal risk to a WordPress site. The minimal concerns identified are primarily related to the inherent nature of external requests and the presence of AJAX endpoints, which are standard in many plugins.

Key Concerns

  • AJAX handlers present
  • External HTTP requests exist
Vulnerabilities
None known

Free Shipping Bar for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Free Shipping Bar for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
459 escaped
Nonce Checks
9
Capability Checks
3
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

98% escaped469 total outputs
Data Flows
All sanitized

Data Flow Analysis

4 flows
hide_notices (includes\support.php:434)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Free Shipping Bar for WooCommerce Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_wfspb_added_to_cartwoo-free-shipping-bar.php:241
noprivwp_ajax_wfspb_added_to_cartwoo-free-shipping-bar.php:242
WordPress Hooks 26
actionadmin_enqueue_scriptsadmin\settings.php:11
actionadmin_menuadmin\settings.php:12
actionadmin_initadmin\settings.php:13
actionwp_enqueue_scriptsfrontend\frontend.php:15
filterwoocommerce_add_to_cart_fragmentsfrontend\frontend.php:16
filterwoocommerce_update_order_review_fragmentsfrontend\frontend.php:17
filterwoocommerce_after_calculate_totalsfrontend\frontend.php:19
actionadmin_enqueue_scriptsincludes\support.php:32
actionadmin_noticesincludes\support.php:33
actionadmin_initincludes\support.php:34
actionadmin_menuincludes\support.php:35
filterplugin_row_metaincludes\support.php:37
actionadmin_initincludes\support.php:39
actionadmin_bar_menuincludes\support.php:41
actionadmin_noticesincludes\support.php:55
actionadmin_footerincludes\support.php:672
actionadmin_bar_menuincludes\support.php:810
actionadmin_noticesincludes\support.php:956
actionplugins_loadedwoo-free-shipping-bar.php:45
actionbefore_woocommerce_initwoo-free-shipping-bar.php:47
actioninitwoo-free-shipping-bar.php:80
actionplugins_loadedwoo-free-shipping-bar.php:188
filterplugin_action_links_woo-free-shipping-bar/woo-free-shipping-bar.phpwoo-free-shipping-bar.php:218
actionadmin_menuwoo-free-shipping-bar.php:236
actionadmin_enqueue_scriptswoo-free-shipping-bar.php:237
actionadmin_initwoo-free-shipping-bar.php:238
Maintenance & Trust

Free Shipping Bar for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 27, 2026
PHP min version7.0
Downloads95K

Community Trust

Rating94/100
Number of ratings40
Active installs2K
Developer Profile

Free Shipping Bar for WooCommerce Developer Profile

VillaTheme

58 plugins · 167K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
217 days
View full developer profile
Detection Fingerprints

How We Detect Free Shipping Bar for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-free-shipping-bar/assets/css/wfspb_frontend.css/wp-content/plugins/woo-free-shipping-bar/assets/css/wfspb_frontend_responsive.css/wp-content/plugins/woo-free-shipping-bar/assets/js/wfspb_frontend.js
Script Paths
/wp-content/plugins/woo-free-shipping-bar/assets/js/wfspb_frontend.js
Version Parameters
woo-free-shipping-bar/assets/css/wfspb_frontend.css?ver=woo-free-shipping-bar/assets/css/wfspb_frontend_responsive.css?ver=woo-free-shipping-bar/assets/js/wfspb_frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
wfspb-shipping-barwfspb-bar-messagewfspb-bar-progresswfspb-bar-progress-bar
Data Attributes
data-wfspb-bar-id
JS Globals
wfspb_frontend_params
FAQ

Frequently Asked Questions about Free Shipping Bar for WooCommerce