
PrangoShip [Quantity Based] for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woo-quantity-based-shipping-rateLets you assign shipping rates based on the quantity of items in the cart for your WooCommerce Store.
Is PrangoShip [Quantity Based] for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100PrangoShip [Quantity Based] for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "woo-quantity-based-shipping-rate" v1.0.0 plugin exhibits a mixed security posture. While the static analysis reveals no direct attack surface like AJAX handlers, REST API routes, or shortcodes, and importantly, no known historical vulnerabilities or CVEs, there are significant concerns. The complete lack of output escaping on all 15 identified output points is a critical weakness, potentially exposing the plugin and users to cross-site scripting (XSS) vulnerabilities. Furthermore, the taint analysis indicates that all three analyzed flows have unsanitized paths, though they are not classified as critical or high severity. This suggests potential injection risks that require further investigation beyond the scope of this static analysis.
Despite the absence of known vulnerabilities and a seemingly clean historical record, the lack of output escaping and the presence of unsanitized taint flows are serious issues. The plugin developers have not implemented basic security measures for handling output, which is a fundamental aspect of web application security. The implication is that any data processed and displayed by this plugin could be manipulated by an attacker. While there are no immediate indications of critical flaws based on the provided data, these unaddressed issues represent a tangible risk that could be exploited if combined with other vulnerabilities or user interaction.
In conclusion, the plugin's strength lies in its minimal attack surface and lack of historical exploits, which is positive. However, the critical deficiency in output escaping and the presence of unsanitized data flows in the taint analysis are substantial weaknesses. These issues indicate a lack of mature security development practices. Until these output and taint path issues are addressed, the plugin should be considered to have a moderate to high risk profile despite its clean CVE history, as the potential for client-side attacks like XSS is significant.
Key Concerns
- Unescaped output on all identified points
- Taint flows with unsanitized paths
PrangoShip [Quantity Based] for WooCommerce Security Vulnerabilities
PrangoShip [Quantity Based] for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
PrangoShip [Quantity Based] for WooCommerce Attack Surface
WordPress Hooks 2
Maintenance & Trust
PrangoShip [Quantity Based] for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
PrangoShip [Quantity Based] for WooCommerce Alternatives
PiWeb Flat rate / Conditional shipping for WooCommerce
advanced-free-flat-shipping-woocommerce
WooCommerce conditional shipping & WooCommerce Advanced Flat rate shipping rates plugin to Create Advanced Flat rate shipping or Free shipping met …
Table rate shipping for WooCommerce
advanced-table-rate-shipping-for-woocommerce
Table rate shipping a addon plugin for WooCommerce shipping.
Advanced WooCommerce Shipping – Flexible Shipping Cost by Weight, Volume & Quantity – Codiepress
advanced-shipping-cost
Flexible and complex shipping cost solution for WooCommerce. Calculate rates by weight, volume, or quantity with easy-to-define rules.
Calcurates for WooCommerce
calcurates-for-woocommerce
An ultimate multi-carrier shipping plugin for e-commerce that helps manage and display the right shipping methods and rates at checkout
Sherpa Delivery for WooCommerce
sherpa-on-demand
Connects your WooCommerce store to your Sherpa Delivery account. Automated same day (and future day) local delivery for Australian businesses.
PrangoShip [Quantity Based] for WooCommerce Developer Profile
1 plugin · 100 total installs
How We Detect PrangoShip [Quantity Based] for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-quantity-based-shipping-rate/css/admin.css/wp-content/plugins/woo-quantity-based-shipping-rate/js/admin.jsHTML / DOM Fingerprints
shippingrowsdebug-col<!-- Set --><!-- ID --><!-- Name --><!-- Minimum Quantity -->+4 moredata-tip