Smart Send Shipping for WooCommerce Security & Risk Analysis

wordpress.org/plugins/woocommerce-smart-send-australian-shipping

Australian merchants can get real-time shipping quotes, order fulfillment and shipping package packing for their WooCommerce website.

10 active installs v4.1.2 PHP 7.4+ WP 4.7+ Updated Mar 3, 2025
australiacalculatorcarrierscarte-commerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Smart Send Shipping for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Smart Send Shipping for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin "woocommerce-smart-send-australian-shipping" version 4.1.2 appears to have a generally good security posture with several positive indicators. Notably, there are no known historical vulnerabilities (CVEs) and the attack surface is relatively small, with all identified entry points (AJAX handlers) having authentication checks. The absence of dangerous functions, file operations, and external HTTP requests that are not explicitly handled further strengthens this impression. The plugin also implements some security measures like nonce checks and capability checks, which are good practices.

However, there are areas of concern highlighted by the static analysis. A significant portion of SQL queries (50%) are not using prepared statements, which can be a vector for SQL injection if not handled with extreme care. More critically, 100% of the analyzed taint flows involve unsanitized paths, indicating a potential risk of cross-site scripting (XSS) or other path-related vulnerabilities, despite no critical or high severity flows being explicitly identified in the report. The low percentage of properly escaped output (18%) also raises a red flag, as it suggests a higher likelihood of XSS vulnerabilities if user-supplied data is directly outputted without adequate sanitization. The two external HTTP requests, while not flagged as inherently dangerous, warrant careful review to ensure they are not susceptible to manipulation.

In conclusion, while the plugin benefits from a clean vulnerability history and a controlled attack surface, the presence of unsanitized taint flows and a low rate of output escaping are significant weaknesses that require attention. Addressing these issues through proper input sanitization and output escaping would greatly improve the plugin's overall security. The 50% of SQL queries not using prepared statements also represents a potential risk that should be mitigated.

Key Concerns

  • Unsanitized taint flows present
  • Low percentage of properly escaped output
  • Half of SQL queries not using prepared statements
Vulnerabilities
None known

Smart Send Shipping for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Smart Send Shipping for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
2 prepared
Unescaped Output
18
4 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

50% prepared4 total queries

Output Escaping

18% escaped22 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
renderDashboard (includes\admin\class-admin.php:32)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Smart Send Shipping for WooCommerce Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_smart_send_shipping_optionsincludes\class-hooks.php:35
noprivwp_ajax_smart_send_shipping_optionsincludes\class-hooks.php:36
WordPress Hooks 15
actioninitincludes\class-hooks.php:21
filterwoocommerce_shipping_methodsincludes\class-hooks.php:23
filterwoocommerce_webhook_payloadincludes\class-hooks.php:24
filterwoocommerce_webhook_http_argsincludes\class-hooks.php:25
filterwoocommerce_rest_prepare_shop_order_objectincludes\class-hooks.php:26
filterpre_http_requestincludes\class-hooks.php:27
actionadmin_menuincludes\class-hooks.php:28
actionadmin_noticesincludes\class-hooks.php:29
filterwoocommerce_admin_process_product_objectincludes\class-hooks.php:31
filterwoocommerce_cart_totals_after_shippingincludes\class-hooks.php:32
filterwoocommerce_review_order_after_shippingincludes\class-hooks.php:33
actionwoocommerce_checkout_update_order_metaincludes\class-hooks.php:34
actionwp_enqueue_scriptsincludes\class-hooks.php:38
actionadmin_enqueue_scriptsincludes\class-hooks.php:39
actioninitsmart-send.php:178
Maintenance & Trust

Smart Send Shipping for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedMar 3, 2025
PHP min version7.4
Downloads8K

Community Trust

Rating74/100
Number of ratings3
Active installs10
Developer Profile

Smart Send Shipping for WooCommerce Developer Profile

Smart Send

1 plugin · 10 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Smart Send Shipping for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woocommerce-smart-send-australian-shipping/assets/css/backend.css/wp-content/plugins/woocommerce-smart-send-australian-shipping/assets/css/frontend.css/wp-content/plugins/woocommerce-smart-send-australian-shipping/assets/js/backend.js/wp-content/plugins/woocommerce-smart-send-australian-shipping/assets/js/frontend.js
Script Paths
/wp-content/plugins/woocommerce-smart-send-australian-shipping/assets/js/backend.js/wp-content/plugins/woocommerce-smart-send-australian-shipping/assets/js/frontend.js
Version Parameters
woocommerce-smart-send-australian-shipping/assets/css/backend.css?ver=woocommerce-smart-send-australian-shipping/assets/css/frontend.css?ver=woocommerce-smart-send-australian-shipping/assets/js/backend.js?ver=woocommerce-smart-send-australian-shipping/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
banner-to-settingsmessage
Data Attributes
id="iframe_dashboard"
FAQ

Frequently Asked Questions about Smart Send Shipping for WooCommerce