USPS Simple Shipping for Woocommerce Security & Risk Analysis

wordpress.org/plugins/woo-usps-simple-shipping

USPS Simple provides real-time USPS domestic rates.

8K active installs v1.18.0 PHP 7.2+ WP 4.6+ Updated Mar 14, 2026
uspsusps-live-ratesusps-shippingusps-woocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is USPS Simple Shipping for Woocommerce Safe to Use in 2026?

Generally Safe

Score 100/100

USPS Simple Shipping for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 20d ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "woo-usps-simple-shipping" plugin version 1.18.0 exhibits a generally strong security posture with some areas for improvement. The complete absence of identified CVEs and a clean vulnerability history is a significant positive, suggesting a history of secure development or diligent patching by users. The plugin also demonstrates good practices in its handling of SQL queries by exclusively using prepared statements and the absence of dangerous functions or file operations further bolsters its security. However, the static analysis does highlight potential weaknesses. The low percentage of properly escaped output (33%) is a concern, as it could lead to Cross-Site Scripting (XSS) vulnerabilities if sensitive data is displayed to users without proper sanitization. While the attack surface appears minimal with zero identified entry points, this could be misleading if the analysis did not uncover all potential interaction vectors. The presence of an external HTTP request, while not inherently a vulnerability, warrants scrutiny to ensure it's being made securely and to a trusted endpoint. The lack of nonce and capability checks on its entry points, though the entry points are reported as zero, is a gap in typical WordPress security best practices for any interaction that modifies data or performs sensitive actions. Overall, the plugin is likely secure given its history, but the unescaped output and lack of explicit permission checks on any potential, even if currently undiscovered, interaction points present the primary risks.

Key Concerns

  • Low percentage of properly escaped output
  • External HTTP requests without explicit context
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

USPS Simple Shipping for Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

USPS Simple Shipping for Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

33% escaped6 total outputs
Attack Surface

USPS Simple Shipping for Woocommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionwoocommerce_before_checkout_formsrc\Debug.php:25
actionwoocommerce_before_cartsrc\Debug.php:26
filterwoocommerce_shipping_methodssrc\Plugin.php:82
actionbefore_woocommerce_initsrc\Plugin.php:89
actionwoocommerce_settings_save_generalsrc\ShippingMethod.php:45
actionwoocommerce_update_options_generalsrc\ShippingMethod.php:55
Maintenance & Trust

USPS Simple Shipping for Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 14, 2026
PHP min version7.2
Downloads361K

Community Trust

Rating88/100
Number of ratings28
Active installs8K
Developer Profile

USPS Simple Shipping for Woocommerce Developer Profile

Dan

4 plugins · 72K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
316 days
View full developer profile
Detection Fingerprints

How We Detect USPS Simple Shipping for Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-usps-simple-shipping/public/debug/style.css/wp-content/plugins/woo-usps-simple-shipping/public/debug/clipboard.min.js/wp-content/plugins/woo-usps-simple-shipping/public/debug/main.js
Script Paths
/wp-content/plugins/woo-usps-simple-shipping/public/debug/clipboard.min.js/wp-content/plugins/woo-usps-simple-shipping/public/debug/main.js

HTML / DOM Fingerprints

CSS Classes
uspss-debug-detailsuspss-debug-copyuspss-debug-inneruspss-debug
FAQ

Frequently Asked Questions about USPS Simple Shipping for Woocommerce