
OPSI Israel Domestic Shipments Security & Risk Analysis
wordpress.org/plugins/woo-ups-pickupUPS Israel PickUP Access Points (Stores and Lockers) for WooCommerce. Displays Live Shipping Rates based on the Shipping Address and Cart Content.
Is OPSI Israel Domestic Shipments Safe to Use in 2026?
Mostly Safe
Score 78/100OPSI Israel Domestic Shipments is generally safe to use. 2 past CVEs were resolved. Keep it updated.
The "woo-ups-pickup" plugin v2.8.2 presents a significant security risk due to a large attack surface and a history of vulnerabilities. All 11 identified AJAX handlers lack proper authorization checks, making them prime targets for unauthorized actions. This, combined with the presence of dangerous functions like `create_function` and `system`, and a complete absence of prepared statements for SQL queries, indicates a poor security posture. The taint analysis, while not revealing critical or high-severity flows, shows 7 instances of unsanitized paths, which could lead to directory traversal or other file-related attacks if exploited in conjunction with other weaknesses. The plugin's vulnerability history, with two medium-severity CVEs and one currently unpatched, highlights a recurring pattern of security oversights, specifically around missing authorization and cross-site scripting. While the plugin has some strengths such as proper nonce checks on a portion of its entry points and a reasonable number of capability checks, these are heavily overshadowed by the critical lack of authorization on its entire AJAX interface and the historical security issues. Organizations using this plugin should exercise extreme caution and consider updating or replacing it.
Key Concerns
- Unpatched CVE
- 11 AJAX handlers without auth checks
- SQL queries not using prepared statements
- Dangerous functions (create_function, system)
- 7 flows with unsanitized paths
- 54% output escaping (below ideal)
OPSI Israel Domestic Shipments Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
OPSI Israel Domestic Shipments <= 2.6.8 - Missing Authorization
OPSI Israel Domestic Shipments <= 2.6.5 - Reflected Cross-Site Scripting
OPSI Israel Domestic Shipments Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
OPSI Israel Domestic Shipments Attack Surface
AJAX Handlers 11
WordPress Hooks 91
Maintenance & Trust
OPSI Israel Domestic Shipments Maintenance & Trust
Maintenance Signals
Community Trust
OPSI Israel Domestic Shipments Alternatives
Automated UPS Shipping for WooCommerce – HPOS supported
a2z-ups-shipping
UPS plugin: Real-time rates, label printing, auto tracking emails, previews on product pages, and more. Seamless integration.
WC Hide Shipping Methods
wc-hide-shipping-methods
This plugin automatically hides all other shipping methods when "Free Shipping" is available, while allowing you to retain "Local Picku …
Shipping Live Rates and Access Points for UPS for WooCommerce
flexible-shipping-ups
Provide auto-calculated UPS rates and Access Point options. Easy 5-minute setup. Show real prices and nearest pickup points at WooCommerce checkout.
Live Shipping Rates Australia for woocommerce – Get real-time shipping rates for your store
live-shipping-rates-australia
Live Shipping Rates Australia integrates real-time shipping rates into WooCommerce, offering reliable shipping options for Australian businesses.
Flat Shipping Rates by Eniture Technology
flat-shipping-rates-by-eniture-technology
The Flat Rate Shipping for WooCommerce plugin is a free add-on plugin that requires the installation and
OPSI Israel Domestic Shipments Developer Profile
1 plugin · 300 total installs
How We Detect OPSI Israel Domestic Shipments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-ups-pickup/includes/ups-pickups.css/wp-content/plugins/woo-ups-pickup/js/admin-ups-pickups.js/wp-content/plugins/woo-ups-pickup/js/ups-pickups.js/wp-content/plugins/woo-ups-pickup/js/admin-ups-pickups.js/wp-content/plugins/woo-ups-pickup/js/ups-pickups.jswoo-ups-pickup/includes/ups-pickups.css?ver=woo-ups-pickup/js/admin-ups-pickups.js?ver=woo-ups-pickup/js/ups-pickups.js?ver=HTML / DOM Fingerprints
woocommerce_ups_pickupsdata-method_id="woo-ups-pickups"data-method_title="UPS PickUP"data-ups-shipping-method-id="woo-ups-pickups"window.ups_pickups_params