
OPSI Israel Domestic Shipments Security & Risk Analysis
wordpress.org/plugins/woo-ups-pickupUPS Israel PickUP Access Points (Stores and Lockers) for WooCommerce. Displays Live Shipping Rates based on the Shipping Address and Cart Content.
Is OPSI Israel Domestic Shipments Safe to Use in 2026?
Mostly Safe
Score 78/100OPSI Israel Domestic Shipments is generally safe to use. 2 past CVEs were resolved.
The "woo-ups-pickup" plugin v2.8.2 presents a significant security risk due to a large attack surface and a history of vulnerabilities. All 11 identified AJAX handlers lack proper authorization checks, making them prime targets for unauthorized actions. This, combined with the presence of dangerous functions like `create_function` and `system`, and a complete absence of prepared statements for SQL queries, indicates a poor security posture. The taint analysis, while not revealing critical or high-severity flows, shows 7 instances of unsanitized paths, which could lead to directory traversal or other file-related attacks if exploited in conjunction with other weaknesses. The plugin's vulnerability history, with two medium-severity CVEs and one currently unpatched, highlights a recurring pattern of security oversights, specifically around missing authorization and cross-site scripting. While the plugin has some strengths such as proper nonce checks on a portion of its entry points and a reasonable number of capability checks, these are heavily overshadowed by the critical lack of authorization on its entire AJAX interface and the historical security issues. Organizations using this plugin should exercise extreme caution and consider updating or replacing it.
Key Concerns
- Unpatched CVE
- 11 AJAX handlers without auth checks
- SQL queries not using prepared statements
- Dangerous functions (create_function, system)
- 7 flows with unsanitized paths
- 54% output escaping (below ideal)
OPSI Israel Domestic Shipments Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
OPSI Israel Domestic Shipments <= 2.6.8 - Missing Authorization
OPSI Israel Domestic Shipments <= 2.6.5 - Reflected Cross-Site Scripting
OPSI Israel Domestic Shipments Release Timeline
OPSI Israel Domestic Shipments Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
OPSI Israel Domestic Shipments Attack Surface
AJAX Handlers 11
WordPress Hooks 91
Maintenance & Trust
OPSI Israel Domestic Shipments Maintenance & Trust
Maintenance Signals
Community Trust
OPSI Israel Domestic Shipments Alternatives
Automated UPS Shipping for WooCommerce – HPOS supported
a2z-ups-shipping
UPS plugin: Real-time rates, label printing, auto tracking emails, previews on product pages, and more. Seamless integration.
UPS Shipping
woo-ups-shipping
UPS Shipping method for WooCommerce site. Easy installation and very light for WooCommerce sites.
Shipping Method for UPS and WooCommerce
shipping-method-for-ups-and-wc
The Shipping Method for WooCommerce UPS is a Wordpress Plugin that integrate the UPS service, it will calculate the shipping cost and the delivery tim …
Shipping Methods for UPS on WooCommerce
woo-ups-shipping-method
UPS shipping methods for WooCommerce. Provide live shipping rates by UPS.
WC Hide Shipping Methods
wc-hide-shipping-methods
This plugin automatically hides all other shipping methods when "Free Shipping" is available, while allowing you to retain "Local Picku …
OPSI Israel Domestic Shipments Developer Profile
1 plugin · 300 total installs
How We Detect OPSI Israel Domestic Shipments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-ups-pickup/includes/ups-pickups.css/wp-content/plugins/woo-ups-pickup/js/admin-ups-pickups.js/wp-content/plugins/woo-ups-pickup/js/ups-pickups.js/wp-content/plugins/woo-ups-pickup/js/admin-ups-pickups.js/wp-content/plugins/woo-ups-pickup/js/ups-pickups.jswoo-ups-pickup/includes/ups-pickups.css?ver=woo-ups-pickup/js/admin-ups-pickups.js?ver=woo-ups-pickup/js/ups-pickups.js?ver=HTML / DOM Fingerprints
woocommerce_ups_pickupsdata-method_id="woo-ups-pickups"data-method_title="UPS PickUP"data-ups-shipping-method-id="woo-ups-pickups"window.ups_pickups_params