AtomX Services Security & Risk Analysis

wordpress.org/plugins/atomx-services

Generation of purchase codes/tokens for AtomX extension (or based on AtomX) for products and subscriptions.

0 active installs v2.0.5 PHP 7.4+ WP 5.8+ Updated Mar 8, 2026
atomxpurchase-codessubscriptionstokenswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AtomX Services Safe to Use in 2026?

Generally Safe

Score 100/100

AtomX Services has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 27d ago
Risk Assessment

The "atomx-services" v2.0.5 plugin demonstrates a strong security posture with several good practices evident in the static analysis. Notably, there are no SQL queries that are not using prepared statements, and an overwhelming majority of output is properly escaped, significantly reducing the risk of cross-site scripting (XSS) vulnerabilities. The plugin also implements nonce and capability checks on its AJAX handlers, which is crucial for preventing unauthorized actions. The absence of any known vulnerabilities or CVEs in its history further contributes to a positive security outlook. This indicates a development team that is mindful of common web security pitfalls.

Despite the positive findings, a few areas warrant attention. The presence of a single flow with an unsanitized path in the taint analysis, although not classified as critical or high, represents a potential risk. This flow could be a vector for directory traversal or other file-related attacks if not properly handled. Additionally, the plugin makes two external HTTP requests, which, while not inherently insecure, can introduce risks if the target endpoints are compromised or if the data sent is sensitive and not properly handled. The use of the Select2 library, if outdated or not from a trusted source, could also pose a risk, although this is not explicitly detailed in the provided data.

Overall, "atomx-services" v2.0.5 appears to be a relatively secure plugin, adhering to many security best practices. The limited number of identified code signals and the complete lack of historical vulnerabilities are encouraging. However, the single unsanitized path flow identified through taint analysis is the primary concern, and the external HTTP requests should be monitored for any potential security implications. Continued vigilance in code review and prompt patching of any future vulnerabilities will be important.

Key Concerns

  • Flow with unsanitized path found
  • Plugin makes external HTTP requests
Vulnerabilities
None known

AtomX Services Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

AtomX Services Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
124 escaped
Nonce Checks
6
Capability Checks
7
File Operations
0
External Requests
2
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

99% escaped125 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
render_orders_tab (includes\Admin\class-atomx-wcs-admin.php:232)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

AtomX Services Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 5

authwp_ajax_atomx_add_orderincludes\Admin\class-atomx-wcs-ajax.php:10
authwp_ajax_atomx_delete_orderincludes\Admin\class-atomx-wcs-ajax.php:11
authwp_ajax_atomx_get_orderincludes\Admin\class-atomx-wcs-ajax.php:12
authwp_ajax_atomx_update_orderincludes\Admin\class-atomx-wcs-ajax.php:13
authwp_ajax_atomx_search_productsincludes\Admin\class-atomx-wcs-ajax.php:14
WordPress Hooks 18
actionplugins_loadedatomx-services.php:32
actionadmin_noticesatomx-services.php:33
actionadmin_menuincludes\class-atomx-wcs-plugin.php:47
actionadmin_initincludes\class-atomx-wcs-plugin.php:48
actionadmin_enqueue_scriptsincludes\class-atomx-wcs-plugin.php:49
actionwoocommerce_checkout_subscription_createdincludes\class-atomx-wcs-plugin.php:52
actionwoocommerce_subscription_status_pending-cancelincludes\class-atomx-wcs-plugin.php:53
actionwoocommerce_subscription_status_cancelledincludes\class-atomx-wcs-plugin.php:54
actionwoocommerce_subscription_status_on-holdincludes\class-atomx-wcs-plugin.php:55
actionwoocommerce_subscription_status_activeincludes\class-atomx-wcs-plugin.php:56
actionwoocommerce_scheduled_subscription_expirationincludes\class-atomx-wcs-plugin.php:57
actionwoocommerce_subscription_status_expiredincludes\class-atomx-wcs-plugin.php:58
actionwcs_subscription_details_table_after_datesincludes\class-atomx-wcs-plugin.php:59
actionwoocommerce_order_status_processingincludes\class-atomx-wcs-plugin.php:62
actionwoocommerce_order_status_completedincludes\class-atomx-wcs-plugin.php:63
actionwoocommerce_order_status_refundedincludes\class-atomx-wcs-plugin.php:64
actionwoocommerce_order_status_cancelledincludes\class-atomx-wcs-plugin.php:65
actionwoocommerce_order_details_after_order_table_itemsincludes\class-atomx-wcs-plugin.php:66
Maintenance & Trust

AtomX Services Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMar 8, 2026
PHP min version7.4
Downloads283

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

AtomX Services Developer Profile

getatomx

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AtomX Services

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/atomx-services/assets/admin.js/wp-content/plugins/atomx-services/assets/admin.css/wp-content/plugins/atomx-services/assets/select2.min.js/wp-content/plugins/atomx-services/assets/select2.min.css
Script Paths
/wp-content/plugins/atomx-services/assets/admin.js/wp-content/plugins/atomx-services/assets/select2.min.js
Version Parameters
atomx-services/assets/admin.js?ver=atomx-services/assets/admin.css?ver=atomx-services/assets/select2.min.js?ver=atomx-services/assets/select2.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
tablinksactive
Data Attributes
data-select2-id
JS Globals
atomx_ajax_vars
FAQ

Frequently Asked Questions about AtomX Services