
Shipping Gateway Per Product for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woocommerce-shipping-gateway-per-productAssign specific shipping gateways for individual WooCommerce products to provide a customized shipping experience for your customers.
Is Shipping Gateway Per Product for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Shipping Gateway Per Product for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin exhibits a concerning security posture due to its unprotected AJAX endpoints, which represent its entire attack surface. While the plugin does not appear to have a history of known vulnerabilities, this is overshadowed by the immediate risks identified in the static analysis. The presence of two AJAX handlers without any authentication checks is a significant oversight, potentially allowing unauthenticated users to trigger plugin functionality. Furthermore, the extremely low percentage of properly escaped output (3%) indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data might be directly rendered without adequate sanitization. Although there are no raw SQL queries and taint analysis shows no critical or high severity flows, the lack of output escaping and unprotected AJAX handlers are critical weaknesses. The bundled Freemius library, while common, should also be monitored for potential vulnerabilities. Overall, while the absence of known historical vulnerabilities is positive, the current code analysis reveals significant and immediate security risks that require urgent attention.
Key Concerns
- AJAX handlers without authentication
- Low percentage of properly escaped output
- Bundled Freemius v1.0 library
Shipping Gateway Per Product for WooCommerce Security Vulnerabilities
Shipping Gateway Per Product for WooCommerce Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Shipping Gateway Per Product for WooCommerce Attack Surface
AJAX Handlers 2
WordPress Hooks 28
Maintenance & Trust
Shipping Gateway Per Product for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Shipping Gateway Per Product for WooCommerce Alternatives
WC Hide Shipping Methods
wc-hide-shipping-methods
This plugin automatically hides all other shipping methods when "Free Shipping" is available, while allowing you to retain "Local Picku …
Hide Shipping Method For WooCommerce
hide-shipping-method-for-woocommerce
Allows store owners to hide shipping methods based on specific conditions!
Bulgarisation for WooCommerce
bulgarisation-for-woocommerce
Всичко необходимо за вашият онлайн магазин за България. Включва облекчен режим за Наредба - H-18 и методи за доставка с Еконт, CVC и Спиди.
The Courier Guy Shipping for WooCommerce
the-courier-guy
This is the official WooCommerce extension to ship products using The Courier Guy.
ELEX Hide WooCommerce Shipping Methods
elex-hide-woocommerce-shipping-methods-basic
The ELEX Hide WooCommerce Shipping Methods is a free plugin allows you to hide certain shipping methods based on shipping class, order weight, other e …
Shipping Gateway Per Product for WooCommerce Developer Profile
5 plugins · 410 total installs
How We Detect Shipping Gateway Per Product for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woocommerce-shipping-gateway-per-product/freemius/start.php/wp-content/plugins/woocommerce-shipping-gateway-per-product/inc/quick_bulk_edit_patch.php/wp-content/plugins/woocommerce-shipping-gateway-per-product/inc/settings.phpHTML / DOM Fingerprints
wps-shipping-formdata-zone-iddata-method-iddfm_sgppfw_fs