WP E-Commerce Region Based Shipping Australia States Security & Risk Analysis

wordpress.org/plugins/wp-e-commerce-region-based-shipping-for-australia-states

"WP E-Commerce Region Based Shipping Australia States" module gives the clients the ability to set the various new postage options.

10 active installs v0.1.2 PHP + WP 2.0.2+ Updated Oct 2, 2012
dijitulecommercepostageshippingwp-ecommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is WP E-Commerce Region Based Shipping Australia States Safe to Use in 2026?

Generally Safe

Score 85/100

WP E-Commerce Region Based Shipping Australia States has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The plugin "wp-e-commerce-region-based-shipping-for-australia-states" v0.1.2 exhibits a mixed security posture. On the positive side, the static analysis reveals no apparent attack surface through common WordPress entry points like AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, there are no detected dangerous functions, file operations, or external HTTP requests, and all identified output is properly escaped. This suggests good development practices in these areas.

However, significant concerns arise from the handling of SQL queries and taint analysis. All four detected SQL queries are executed without prepared statements, which is a major risk for SQL injection vulnerabilities. The taint analysis also identified two flows with unsanitized paths. While these were not classified as critical or high severity, the presence of unsanitized paths is a strong indicator of potential vulnerabilities that could be exploited if user input is not handled carefully within these flows.

The vulnerability history is currently clean, with no recorded CVEs. While this is a positive sign, it doesn't negate the risks identified in the code analysis. The absence of historical vulnerabilities might be due to the plugin's limited usage, its recent development, or the fact that the identified issues haven't been discovered or exploited yet. The overall conclusion is that the plugin has a solid foundation in avoiding common attack vectors, but the unaddressed SQL query practices and the presence of unsanitized taint flows represent serious potential security weaknesses that require immediate attention.

Key Concerns

  • Raw SQL queries without prepared statements
  • Taint flows with unsanitized paths
Vulnerabilities
None known

WP E-Commerce Region Based Shipping Australia States Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WP E-Commerce Region Based Shipping Australia States Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared4 total queries
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
submit_form (crikey.php:114)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP E-Commerce Region Based Shipping Australia States Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filterwpsc_shipping_modulescrikey.php:302
Maintenance & Trust

WP E-Commerce Region Based Shipping Australia States Maintenance & Trust

Maintenance Signals

WordPress version tested3.3.2
Last updatedOct 2, 2012
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WP E-Commerce Region Based Shipping Australia States Developer Profile

DJB31st

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP E-Commerce Region Based Shipping Australia States

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
name="shipping[ACT]"name="shipping[NSW]"name="shipping[NT]"name="shipping[QLD]"name="shipping[SA]"name="shipping[TAS]"+3 more
JS Globals
crikey_SESSION['wpsc_selected_region']_SESSION['wpsc_delivery_country']_POST['shipping']_SESSION['wpsc_delivery_region']
FAQ

Frequently Asked Questions about WP E-Commerce Region Based Shipping Australia States