abrestan Accounting Security & Risk Analysis

wordpress.org/plugins/abrestan

Connect abrestan Online Accounting to WooCommerce.

10 active installs v2.2.6 PHP 7.1+ WP 5.2+ Updated Apr 25, 2023
accounting-cloud-abrestan
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is abrestan Accounting Safe to Use in 2026?

Generally Safe

Score 85/100

abrestan Accounting has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The abrestan plugin v2.2.6 presents a significant security concern due to its unprotected entry points. With 14 AJAX handlers, none of which implement authentication or capability checks, an attacker could potentially trigger any of these functions without prior authorization. This large, unprotected attack surface is a primary risk. While the plugin shows good practices in using prepared statements for SQL queries and properly escaping most outputs, the lack of security checks on its AJAX endpoints overshadows these strengths. The taint analysis indicates flows with unsanitized paths, though none reached critical or high severity levels, this still suggests potential for indirect vulnerabilities if combined with other weaknesses or future code changes.

The plugin's vulnerability history is clean, with no recorded CVEs. This is a positive indicator, suggesting that past development may have been secure or that the plugin hasn't been a target for known exploits. However, the absence of past vulnerabilities does not guarantee future security, especially given the identified structural weaknesses in the current version. The lack of nonce checks and capability checks on AJAX handlers is a critical oversight that needs immediate attention. Overall, the plugin's security posture is weak due to its exposed AJAX handlers, despite some good practices in data handling.

Key Concerns

  • 14 unprotected AJAX handlers
  • 0 nonce checks on AJAX handlers
  • 0 capability checks on AJAX handlers
  • 5 flows with unsanitized paths
Vulnerabilities
None known

abrestan Accounting Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

abrestan Accounting Release Timeline

v2.2.2
v2.2.1
v2.2.0
v2.1.3
Code Analysis
Analyzed Mar 17, 2026

abrestan Accounting Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
5 prepared
Unescaped Output
10
50 escaped
Nonce Checks
0
Capability Checks
0
File Operations
5
External Requests
1
Bundled Libraries
0

SQL Query Safety

83% prepared6 total queries

Output Escaping

83% escaped60 total outputs
Data Flows · Security
5 unsanitized

Data Flow Analysis

7 flows5 with unsanitized paths
abrestan_login_action (abrestan.php:199)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
14 unprotected

abrestan Accounting Attack Surface

Entry Points14
Unprotected14

AJAX Handlers 14

authwp_ajax_abrestan_login_actionabrestan.php:197
noprivwp_ajax_abrestan_login_actionabrestan.php:198
authwp_ajax_abrestan_logout_actionabrestan.php:207
noprivwp_ajax_abrestan_logout_actionabrestan.php:208
authwp_ajax_abrestan_company_actionabrestan.php:216
noprivwp_ajax_abrestan_company_actionabrestan.php:217
authwp_ajax_abrestan_get_orders_actionabrestan.php:225
noprivwp_ajax_abrestan_get_orders_actionabrestan.php:226
authwp_ajax_abrestan_send_orders_actionabrestan.php:235
noprivwp_ajax_abrestan_send_orders_actionabrestan.php:236
authwp_ajax_abrestan_send_again_orders_actionabrestan.php:257
noprivwp_ajax_abrestan_send_again_orders_actionabrestan.php:258
authwp_ajax_abrestan_save_setting_actionabrestan.php:298
noprivwp_ajax_abrestan_save_setting_actionabrestan.php:299
WordPress Hooks 10
actionwoocommerce_initabrestan.php:28
actionwp_trash_postabrestan.php:423
actionwoocommerce_update_orderabrestan.php:424
actionwoocommerce_order_status_completedabrestan.php:425
filtermanage_edit-shop_order_columnsinc\Api\AddColumn.php:11
actionmanage_shop_order_posts_custom_columninc\Api\AddColumn.php:12
actionadmin_print_stylesinc\Api\AddColumn.php:14
actionadmin_enqueue_scriptsinc\Base\ABR_Enqueue.php:8
actionadd_meta_boxesinc\Base\order_metabox.php:11
actionadmin_menuinc\Base\SettingApi.php:13
Maintenance & Trust

abrestan Accounting Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedApr 25, 2023
PHP min version7.1
Downloads2K

Community Trust

Rating20/100
Number of ratings1
Active installs10
Alternatives

abrestan Accounting Alternatives

No alternatives data available yet.

Developer Profile

abrestan Accounting Developer Profile

abrestan

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect abrestan Accounting

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/abrestan/css/abrestan.css/wp-content/plugins/abrestan/js/abrestan.js
Script Paths
/wp-content/plugins/abrestan/js/abrestan.js
Version Parameters
abrestan/css/abrestan.css?ver=abrestan/js/abrestan.js?ver=

HTML / DOM Fingerprints

JS Globals
abrestan_ajax_object
REST Endpoints
/wp-json/abrestan/v1/get_logs
FAQ

Frequently Asked Questions about abrestan Accounting