
Free Shipping Per Product for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woo-free-shipping-per-productA simple way to set free shipping for certain products.
Is Free Shipping Per Product for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Free Shipping Per Product for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "woo-free-shipping-per-product" plugin version 1.3.4 exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points suggests a minimal attack surface. Furthermore, the code signals indicate a lack of dangerous functions, file operations, and external HTTP requests. The use of prepared statements for all SQL queries is a significant positive, as is the absence of any recorded vulnerabilities in its history, suggesting a well-maintained and secure codebase.
However, the analysis does highlight a couple of areas for improvement. The fact that only 50% of the identified output points are properly escaped could potentially lead to cross-site scripting (XSS) vulnerabilities if the unescaped outputs are rendered in a sensitive context. Additionally, the complete absence of nonce checks and capability checks across all entry points, while seemingly benign due to the lack of identified entry points, indicates a potential lack of foundational security practices that would be crucial if new entry points were introduced in future updates. The lack of taint analysis results is also noteworthy, as it means we cannot definitively rule out potential data manipulation issues that might not be caught by static function checks alone.
Overall, this plugin appears to be quite secure due to its limited attack surface and good practices in areas like SQL handling. The main areas of concern are the potential for XSS due to partial output escaping and the absence of robust authentication/authorization checks, which, while not exploited in the current version, represent a risk if the plugin evolves. The lack of historical vulnerabilities is a strong indicator of responsible development.
Key Concerns
- Unescaped output found
- No nonce checks implemented
- No capability checks implemented
Free Shipping Per Product for WooCommerce Security Vulnerabilities
Free Shipping Per Product for WooCommerce Code Analysis
Output Escaping
Free Shipping Per Product for WooCommerce Attack Surface
WordPress Hooks 5
Maintenance & Trust
Free Shipping Per Product for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Free Shipping Per Product for WooCommerce Alternatives
WC Hide Shipping Methods
wc-hide-shipping-methods
This plugin automatically hides all other shipping methods when "Free Shipping" is available, while allowing you to retain "Local Picku …
Hide Shipping Method For WooCommerce
hide-shipping-method-for-woocommerce
Allows store owners to hide shipping methods based on specific conditions!
Australia Post WooCommerce Extension
australian-post-woocommerce-extension
Australia Post WooCommerce Extension integrates Australia Post with WooCommerce, calculating shipping costs and delivery times for customers.
ELEX Hide WooCommerce Shipping Methods
elex-hide-woocommerce-shipping-methods-basic
The ELEX Hide WooCommerce Shipping Methods is a free plugin allows you to hide certain shipping methods based on shipping class, order weight, other e …
bpost shipping
bpost-shipping
This plugin allows customers to choose their preferred Belgian bpost delivery method when ordering in your Woocommerce webshop.
Free Shipping Per Product for WooCommerce Developer Profile
10 plugins · 27K total installs
How We Detect Free Shipping Per Product for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-free-shipping-per-product/assets/css/admin.css/wp-content/plugins/woo-free-shipping-per-product/assets/js/admin.jswoo-free-shipping-per-product/assets/css/admin.css?ver=woo-free-shipping-per-product/assets/js/admin.js?ver=HTML / DOM Fingerprints
wc-free-shipping-per-product<!-- WooCommerce Free Shipping Per Product Options --><!-- End WooCommerce Free Shipping Per Product Options -->data-hide_other_methodsdata-remove_from_shipping_methods_calculationsdata-free_shipping_overridewc_shipping_per_product_params