WCFM and WC Marketplace – The Courier Guy Shipping for WooCommerce Security & Risk Analysis

wordpress.org/plugins/wp-multi-vendor-marketplace-the-courier-guy-shipping-for-woocommerce

This is the official WCFM and WC Marketplace extension to ship products using The Courier Guy.

10 active installs v1.0.2 PHP 7.2+ WP 4.9.8+ Updated Oct 12, 2020
couriere-commerceecommerceshippingwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is WCFM and WC Marketplace – The Courier Guy Shipping for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

WCFM and WC Marketplace – The Courier Guy Shipping for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

Based on the provided static analysis, the 'wp-multi-vendor-marketplace-the-courier-guy-shipping-for-woocommerce' plugin v1.0.2 exhibits a strong security posture. The complete absence of identified dangerous functions, raw SQL queries, file operations, external HTTP requests, and taint flows with unsanitized paths is highly positive. Furthermore, the robust output escaping rate of 94% indicates good practice in preventing cross-site scripting (XSS) vulnerabilities. The lack of any recorded vulnerabilities in its history further reinforces this impression of a well-secured plugin.

However, a notable area of concern is the complete absence of nonces and capability checks for all entry points. While the current analysis shows zero unprotected entry points, this suggests that the plugin relies heavily on WordPress's core authorization mechanisms rather than implementing its own security checks. This could potentially become a risk if future code changes introduce new entry points or if there are undiscovered vulnerabilities in how WordPress handles authorization in this specific context. The lack of identified attack vectors like AJAX handlers, REST API routes, or shortcodes in this version is a strength, but it's crucial to remember that attack surfaces can evolve with updates.

In conclusion, this version of the plugin appears to be very secure, with excellent coding practices observed in the provided metrics. The main weakness lies in the absence of explicit nonce and capability checks, which, while not an immediate critical flaw given the current zero-attack-surface findings, represents a potential future risk that should be monitored. The plugin's clean vulnerability history is a testament to its current stability.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Minor unescaped output
Vulnerabilities
None known

WCFM and WC Marketplace – The Courier Guy Shipping for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WCFM and WC Marketplace – The Courier Guy Shipping for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
17 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped18 total outputs
Attack Surface

WCFM and WC Marketplace – The Courier Guy Shipping for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_initwc-multivendor-marketplace-thecourierguy-extension.php:43
actionwcfm_initwc-multivendor-marketplace-thecourierguy-extension.php:44
filterwcfm_marketplace_settings_fields_addresswc-multivendor-marketplace-thecourierguy-extension.php:45
filterthecourierguy_before_request_quotewc-multivendor-marketplace-thecourierguy-extension.php:46
filterthecourierguy_before_submit_collectionwc-multivendor-marketplace-thecourierguy-extension.php:47
actionadmin_noticeswc-multivendor-marketplace-thecourierguy-extension.php:151
Maintenance & Trust

WCFM and WC Marketplace – The Courier Guy Shipping for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedOct 12, 2020
PHP min version7.2
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

WCFM and WC Marketplace – The Courier Guy Shipping for WooCommerce Developer Profile

talenttcg

2 plugins · 3K total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WCFM and WC Marketplace – The Courier Guy Shipping for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-multi-vendor-marketplace-the-courier-guy-shipping-for-woocommerce/js/tcg-wcfm-fields.js/wp-content/plugins/wp-multi-vendor-marketplace-the-courier-guy-shipping-for-woocommerce/css/tcg-wcfm-fields.css
Version Parameters
wp-multi-vendor-marketplace-the-courier-guy-shipping-for-woocommerce/js/tcg-wcfm-fields.js?ver=wp-multi-vendor-marketplace-the-courier-guy-shipping-for-woocommerce/css/tcg-wcfm-fields.css?ver=

HTML / DOM Fingerprints

CSS Classes
tcg-suburb-field
FAQ

Frequently Asked Questions about WCFM and WC Marketplace – The Courier Guy Shipping for WooCommerce