
Conditional Shipping for WooCommerce: Restrict Shipping Options by Anything Security & Risk Analysis
wordpress.org/plugins/wpfactory-conditional-shipping-for-woocommerceSet conditions for WooCommerce shipping methods to show up.
Is Conditional Shipping for WooCommerce: Restrict Shipping Options by Anything Safe to Use in 2026?
Generally Safe
Score 100/100Conditional Shipping for WooCommerce: Restrict Shipping Options by Anything has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "wpfactory-conditional-shipping-for-woocommerce" v2.1.2 reveals a generally positive security posture. The absence of any identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code analysis shows no dangerous functions, all SQL queries are prepared statements, and there are no file operations or external HTTP requests. This indicates strong adherence to secure coding practices in these areas. The high percentage of properly escaped output (80%) is also a good sign, though not perfect.
The plugin's vulnerability history is also exceptionally clean, with zero known CVEs, either historical or currently unpatched. This, combined with the lack of critical or high-severity taint flows and the absence of common vulnerability types, suggests a mature and well-maintained codebase that has likely undergone thorough security scrutiny. The lack of identified nonces and capability checks is a notable absence, and while the current analysis doesn't show these leading to vulnerabilities, it represents a potential area for future risk if the plugin were to introduce new entry points or functionality.
In conclusion, "wpfactory-conditional-shipping-for-woocommerce" v2.1.2 appears to be a highly secure plugin based on the provided data. Its minimal attack surface, strong adherence to secure coding practices regarding SQL and external requests, and a pristine vulnerability history are significant strengths. The only minor concern is the incomplete output escaping and the absence of nonce/capability checks, which, while not currently exploitable, are good practices to maintain as the plugin evolves. Overall, the plugin presents a low-risk profile.
Key Concerns
- Output escaping is not 100% complete
- No nonce checks implemented
- No capability checks implemented
Conditional Shipping for WooCommerce: Restrict Shipping Options by Anything Security Vulnerabilities
Conditional Shipping for WooCommerce: Restrict Shipping Options by Anything Code Analysis
Output Escaping
Conditional Shipping for WooCommerce: Restrict Shipping Options by Anything Attack Surface
WordPress Hooks 15
Maintenance & Trust
Conditional Shipping for WooCommerce: Restrict Shipping Options by Anything Maintenance & Trust
Maintenance Signals
Community Trust
Conditional Shipping for WooCommerce: Restrict Shipping Options by Anything Alternatives
Easy Shipping for Woocommerce
easy-shipping-rate
Easy Shipping for Woocommerce allows you to easily create new shipping methods. It is a very flexible plugin with which you can condition the pricing …
Weight Based Shipping Table Rate for WooCommerce – Flexible Shipping
flexible-shipping
Weight based shipping methods for WooCommerce. Flexible shipping with table rate rules by cart weight and order value. Accurate rates at checkout.
Conditional Shipping for WooCommerce
conditional-shipping-for-woocommerce
Restrict WooCommerce shipping methods based on conditions. Works with your existing shipping methods and zones.
Flat Rate Shipping Method for WooCommerce
woo-extra-flat-rate
Create flexible flat rate shipping methods with custom rules i.e. for specific products or countries where the products will be shipped to.
Conditional Payments and Shipping for WooCommerce
wc-restricted-shipping-and-payment
A simplistic plugin for excluding shipping methods based on multiple rules such as shipping class, package weight and cart totals.
Conditional Shipping for WooCommerce: Restrict Shipping Options by Anything Developer Profile
63 plugins · 136K total installs
How We Detect Conditional Shipping for WooCommerce: Restrict Shipping Options by Anything
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpfactory-conditional-shipping-for-woocommerce/assets/js/alg-wc-cs-checkout.jsHTML / DOM Fingerprints
alg-wc-cs-noticedata-alg-wc-cs-initalg_wc_cs_checkout_params