
WC – APG Free Shipping Security & Risk Analysis
wordpress.org/plugins/woocommerce-apg-free-postcodestatecountry-shippingAdd to WooCommerce a free shipping based on postcode, state (province), country and a minimum and/or a valid coupon.
Is WC – APG Free Shipping Safe to Use in 2026?
Generally Safe
Score 100/100WC – APG Free Shipping has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "woocommerce-apg-free-postcodestatecountry-shipping" plugin, version 3.5.3, exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, having a high percentage of SQL queries using prepared statements, and a strong rate of output escaping. The absence of known CVEs and past vulnerabilities is also a significant strength, suggesting a generally well-maintained codebase.
However, significant concerns arise from the attack surface analysis. Two of the three AJAX handlers lack authentication checks, creating potential entry points for unauthorized actions. Furthermore, the taint analysis revealed three flows with unsanitized paths, all categorized as high severity. This indicates that user-supplied data might be processed in a way that could lead to security issues if not handled carefully by downstream functions or if combined with other vulnerabilities. The presence of an external HTTP request, while not inherently a vulnerability, warrants attention for potential risks like SSRF if not properly validated.
In conclusion, while the plugin's history of security is commendable and many secure coding practices are in place, the identified unauthenticated AJAX handlers and high-severity unsanitized taint flows represent critical areas that require immediate attention. These findings overshadow the positive aspects and suggest that the plugin, in its current state, is not entirely secure, particularly concerning unauthorized access and potential data manipulation.
Key Concerns
- Unauthenticated AJAX handlers
- High severity unsanitized taint flows
WC – APG Free Shipping Security Vulnerabilities
WC – APG Free Shipping Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WC – APG Free Shipping Attack Surface
AJAX Handlers 3
WordPress Hooks 28
Maintenance & Trust
WC – APG Free Shipping Maintenance & Trust
Maintenance Signals
Community Trust
WC – APG Free Shipping Alternatives
Weight Based Shipping for WooCommerce
weight-based-shipping-for-woocommerce
Weight Based Shipping is a flexible and widely-used solution to calculate shipping costs based on the total cart weight and value.
Advanced Free Shipping for WooCommerce
woocommerce-advanced-free-shipping
Advanced Free Shipping for WooCommerce is an plugin which allows you to set up advanced free shipping conditions.
Modern Cart – WooCommerce Side Cart & Popup Cart
modern-cart
Modern Cart gives your store a side cart and free shipping bar so shoppers stay on the page, spend more to unlock rewards, and check out in seconds.
WC Hide Shipping Methods
wc-hide-shipping-methods
This plugin automatically hides all other shipping methods when "Free Shipping" is available, while allowing you to retain "Local Picku …
Hide Shipping Method For WooCommerce
hide-shipping-method-for-woocommerce
Allows store owners to hide shipping methods based on specific conditions!
WC – APG Free Shipping Developer Profile
9 plugins · 19K total installs
How We Detect WC – APG Free Shipping
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woocommerce-apg-free-postcodestatecountry-shipping/includes/admin/js/apg-free-shipping-admin.js/wp-content/plugins/woocommerce-apg-free-postcodestatecountry-shipping/includes/admin/css/apg-free-shipping-admin.css/wp-content/plugins/woocommerce-apg-free-postcodestatecountry-shipping/includes/admin/js/apg-free-shipping-admin.jswoocommerce-apg-free-postcodestatecountry-shipping/includes/admin/js/apg-free-shipping-admin.js?ver=woocommerce-apg-free-postcodestatecountry-shipping/includes/admin/css/apg-free-shipping-admin.css?ver=HTML / DOM Fingerprints
apg-weight-marker<!-- Igual no deberías poder abrirme. -->data-plugin-slug="woocommerce-apg-free-postcodestatecountry-shipping"apg_free_shipping_loading_shipping_methods