
WP E-Commerce Pick-up Shipping Module Security & Risk Analysis
wordpress.org/plugins/wp-e-commerce-local-pick-up-shipping-moduleAdds a local pick-up otion to your wp e-commerce cart by GetShopped.org
Is WP E-Commerce Pick-up Shipping Module Safe to Use in 2026?
Generally Safe
Score 85/100WP E-Commerce Pick-up Shipping Module has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-e-commerce-local-pick-up-shipping-module" v1.0 plugin exhibits a seemingly strong security posture at first glance, with no recorded CVEs and a clean vulnerability history. The static analysis also reports zero AJAX handlers, REST API routes, shortcodes, or cron events, suggesting a minimal attack surface. Furthermore, the code analysis indicates no dangerous functions, file operations, or external HTTP requests, and all identified outputs are properly escaped. However, the analysis reveals significant concerns regarding its handling of SQL queries. A single SQL query is present, and alarmingly, it is not utilizing prepared statements, which presents a substantial risk of SQL injection vulnerabilities. While the taint analysis found no critical or high severity flows, the presence of unsanitized paths in two flows, despite the lack of direct exploitable vulnerabilities identified in this scan, warrants caution. The complete absence of nonce and capability checks across the board is also a notable weakness, even with the limited reported entry points. The plugin's strength lies in its clean vulnerability history and seemingly secure output handling. The primary weaknesses are the unescaped SQL query and the lack of authentication/authorization checks on any potential entry points that might emerge in future versions or with different configurations.
Key Concerns
- SQL queries without prepared statements
- Unsanitized paths in taint flows
- Missing nonce checks
- Missing capability checks
WP E-Commerce Pick-up Shipping Module Security Vulnerabilities
WP E-Commerce Pick-up Shipping Module Code Analysis
SQL Query Safety
Data Flow Analysis
WP E-Commerce Pick-up Shipping Module Attack Surface
WordPress Hooks 1
Maintenance & Trust
WP E-Commerce Pick-up Shipping Module Maintenance & Trust
Maintenance Signals
Community Trust
WP E-Commerce Pick-up Shipping Module Alternatives
DHL Shipping Germany for WooCommerce
dhl-for-woocommerce
Automate e-commerce orders with Official DHL for WooCommerce. Covers DHL Paket and Deutsche Post International.
The Courier Guy Shipping for WooCommerce
the-courier-guy
This is the official WooCommerce extension to ship products using The Courier Guy.
AppScenic – Smart AI Dropshipping
appscenic
Expand your store catalogue with no upfront inventory cost. Source high-quality products from verified domestic suppliers and use AI in the process.
CDEKDelivery
cdekdelivery
Integration with CDEK delivery for your WooCommerce store.
DHL eCommerce (Benelux) for WooCommerce
dhlpwc
DHL eCommerce (Benelux) presents: The official DHL eCommerce for WooCommerce plugin to automate your e-commerce shipping process.
WP E-Commerce Pick-up Shipping Module Developer Profile
3 plugins · 20 total installs
How We Detect WP E-Commerce Pick-up Shipping Module
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-e-commerce-local-pick-up-shipping-module/style.css/wp-content/plugins/wp-e-commerce-local-pick-up-shipping-module/script.js/wp-content/plugins/wp-e-commerce-local-pick-up-shipping-module/script.jswp-e-commerce-local-pick-up-shipping-module/style.css?ver=wp-e-commerce-local-pick-up-shipping-module/script.js?ver=HTML / DOM Fingerprints
name="shipping[charge]"