
Shipping Gateway Per Product for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woocommerce-shipping-gateway-per-productTake full control of your WooCommerce shipping by assigning gateways per product, category, tag, or mixed cart.
Is Shipping Gateway Per Product for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Shipping Gateway Per Product for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin exhibits a concerning security posture due to its unprotected AJAX endpoints, which represent its entire attack surface. While the plugin does not appear to have a history of known vulnerabilities, this is overshadowed by the immediate risks identified in the static analysis. The presence of two AJAX handlers without any authentication checks is a significant oversight, potentially allowing unauthenticated users to trigger plugin functionality. Furthermore, the extremely low percentage of properly escaped output (3%) indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data might be directly rendered without adequate sanitization. Although there are no raw SQL queries and taint analysis shows no critical or high severity flows, the lack of output escaping and unprotected AJAX handlers are critical weaknesses. The bundled Freemius library, while common, should also be monitored for potential vulnerabilities. Overall, while the absence of known historical vulnerabilities is positive, the current code analysis reveals significant and immediate security risks that require urgent attention.
Key Concerns
- AJAX handlers without authentication
- Low percentage of properly escaped output
- Bundled Freemius v1.0 library
Shipping Gateway Per Product for WooCommerce Security Vulnerabilities
Shipping Gateway Per Product for WooCommerce Release Timeline
Shipping Gateway Per Product for WooCommerce Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Shipping Gateway Per Product for WooCommerce Attack Surface
AJAX Handlers 2
WordPress Hooks 28
Maintenance & Trust
Shipping Gateway Per Product for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Shipping Gateway Per Product for WooCommerce Alternatives
WC Hide Shipping Methods
wc-hide-shipping-methods
This plugin automatically hides all other shipping methods when "Free Shipping" is available, while allowing you to retain "Local Picku …
Hide Shipping Method For WooCommerce
hide-shipping-method-for-woocommerce
Allows store owners to hide shipping methods based on specific conditions!
ELEX Hide WooCommerce Shipping Methods
elex-hide-woocommerce-shipping-methods-basic
The ELEX Hide WooCommerce Shipping Methods is a free plugin allows you to hide certain shipping methods based on shipping class, order weight, other e …
bpost shipping
bpost-shipping
This plugin allows customers to choose their preferred Belgian bpost delivery method when ordering in your Woocommerce webshop.
WC Hide Shipping Methods Except Pont
wc-hide-shipping-methods-except-pont
This plugin automatically hides all other shipping methods when “free shipping” is available.
Shipping Gateway Per Product for WooCommerce Developer Profile
6 plugins · 410 total installs
How We Detect Shipping Gateway Per Product for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woocommerce-shipping-gateway-per-product/freemius/start.php/wp-content/plugins/woocommerce-shipping-gateway-per-product/inc/quick_bulk_edit_patch.php/wp-content/plugins/woocommerce-shipping-gateway-per-product/inc/settings.phpHTML / DOM Fingerprints
wps-shipping-formdata-zone-iddata-method-iddfm_sgppfw_fs