
WCFM and WC Marketplace – The Courier Guy Shipping for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wp-multi-vendor-marketplace-the-courier-guy-shipping-for-woocommerceThis is the official WCFM and WC Marketplace extension to ship products using The Courier Guy.
Is WCFM and WC Marketplace – The Courier Guy Shipping for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100WCFM and WC Marketplace – The Courier Guy Shipping for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis, the 'wp-multi-vendor-marketplace-the-courier-guy-shipping-for-woocommerce' plugin v1.0.2 exhibits a strong security posture. The complete absence of identified dangerous functions, raw SQL queries, file operations, external HTTP requests, and taint flows with unsanitized paths is highly positive. Furthermore, the robust output escaping rate of 94% indicates good practice in preventing cross-site scripting (XSS) vulnerabilities. The lack of any recorded vulnerabilities in its history further reinforces this impression of a well-secured plugin.
However, a notable area of concern is the complete absence of nonces and capability checks for all entry points. While the current analysis shows zero unprotected entry points, this suggests that the plugin relies heavily on WordPress's core authorization mechanisms rather than implementing its own security checks. This could potentially become a risk if future code changes introduce new entry points or if there are undiscovered vulnerabilities in how WordPress handles authorization in this specific context. The lack of identified attack vectors like AJAX handlers, REST API routes, or shortcodes in this version is a strength, but it's crucial to remember that attack surfaces can evolve with updates.
In conclusion, this version of the plugin appears to be very secure, with excellent coding practices observed in the provided metrics. The main weakness lies in the absence of explicit nonce and capability checks, which, while not an immediate critical flaw given the current zero-attack-surface findings, represents a potential future risk that should be monitored. The plugin's clean vulnerability history is a testament to its current stability.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Minor unescaped output
WCFM and WC Marketplace – The Courier Guy Shipping for WooCommerce Security Vulnerabilities
WCFM and WC Marketplace – The Courier Guy Shipping for WooCommerce Code Analysis
Output Escaping
WCFM and WC Marketplace – The Courier Guy Shipping for WooCommerce Attack Surface
WordPress Hooks 6
Maintenance & Trust
WCFM and WC Marketplace – The Courier Guy Shipping for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
WCFM and WC Marketplace – The Courier Guy Shipping for WooCommerce Alternatives
The Courier Guy Shipping for WooCommerce
the-courier-guy
This is the official WooCommerce extension to ship products using The Courier Guy.
FlagShip WooCommerce Shipping
flagship-woocommerce-shipping
FlagShip WooCommerce Shipping is an e-shipping courier solution that helps you shipping anything from Canada. Beautifully.
FlagShip WooCommerce Extension
flagship-shipping-extension-for-woocommerce
FlagShip WooCommerce Extension obtains FlagShip shipping rates for orders and exports order to FlagShip to dispatch shipment.
Spocket ‑ US & EU Dropshipping
spocket
Find fast shipping products from reliable suppliers, import them to your WooCommerce store and manage your orders automatically: all for free.
Inkedjoy-POD Dropshipping
eprolo-pod-dropshipping
Impressive Products & Price - Print On Demand Dropshipping.
WCFM and WC Marketplace – The Courier Guy Shipping for WooCommerce Developer Profile
2 plugins · 3K total installs
How We Detect WCFM and WC Marketplace – The Courier Guy Shipping for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-multi-vendor-marketplace-the-courier-guy-shipping-for-woocommerce/js/tcg-wcfm-fields.js/wp-content/plugins/wp-multi-vendor-marketplace-the-courier-guy-shipping-for-woocommerce/css/tcg-wcfm-fields.csswp-multi-vendor-marketplace-the-courier-guy-shipping-for-woocommerce/js/tcg-wcfm-fields.js?ver=wp-multi-vendor-marketplace-the-courier-guy-shipping-for-woocommerce/css/tcg-wcfm-fields.css?ver=HTML / DOM Fingerprints
tcg-suburb-field