
Site.pro for WooCommerce Security & Risk Analysis
wordpress.org/plugins/b1-accountingĮskiepis skirtas sinchronizuoti produktus ir užsakymus tarp WooCommerce ir Site.pro.
Is Site.pro for WooCommerce Safe to Use in 2026?
Generally Safe
Score 98/100Site.pro for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The b1-accounting plugin version 2.2.65 exhibits a concerning security posture primarily due to its extensive attack surface of unprotected AJAX handlers. While the plugin shows good practices in terms of SQL query preparation and a lack of dangerous functions or file operations, the presence of 14 AJAX handlers without any authentication checks represents a significant vulnerability. This means that any unauthenticated user could potentially trigger these handlers, leading to unintended actions or information disclosure.
Taint analysis reveals two flows with unsanitized paths, though thankfully no critical or high severity issues were identified in this area. However, the plugin's vulnerability history is a significant red flag. With two known CVEs, one high and one medium, and a recent vulnerability discovered in July 2025, it indicates a pattern of security weaknesses. The common vulnerability types of SQL Injection and Missing Authorization directly correlate with the observed unprotected AJAX handlers.
In conclusion, while the plugin demonstrates some strengths in secure coding practices like prepared statements, the critical flaw of numerous unprotected AJAX endpoints and a history of significant vulnerabilities heavily outweigh these positives. The likelihood of exploitation is high due to the large, accessible attack surface, and the plugin's past suggests a recurring inability to address authorization and input sanitization effectively.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Missing Authorization (implied by vuln history and unprotected AJAX)
- Unescaped output
- High severity CVE (past)
- Medium severity CVE (past)
Site.pro for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
B1.lt for WooCommerce <= 2.2.56 - Authenticated (Subscriber+) SQL Injection
B1.lt for WooCommerce <= 2.2.57 - Missing Authorization to Authenticated (Subscriber+) Arbitrary SQL Injection
Site.pro for WooCommerce Release Timeline
Site.pro for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Site.pro for WooCommerce Attack Surface
AJAX Handlers 14
WordPress Hooks 12
Scheduled Events 3
Maintenance & Trust
Site.pro for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Site.pro for WooCommerce Alternatives
MOA Accounting
moa-accounting
A lightweight accounting plugin for WooCommerce that automatically calculates order profit and loss with a modern management dashboard.
Advanced Order Export For WooCommerce
woo-order-export-lite
Export WooCommerce orders to Excel, CSV, XML, JSON, PDF and HTML. Best free order export plugin for WooCommerce.
Order Export & Order Import for WooCommerce
order-import-export-for-woocommerce
The best order export import plugin for WooCommerce. Easily import and export WooCommerce orders and WooCommerce coupons using CSV.
ATUM WooCommerce Inventory Management and Stock Tracking
atum-stock-manager-for-woocommerce
WooCommerce Full Inventory Management, Purchase Orders, Suppliers, Inbound Stock, Inventory Logs, WooCommerce Sales Statistics, and More.
Orders Tracking for WooCommerce
woo-orders-tracking
Easily import/manage your tracking numbers, add tracking numbers to PayPal and send email notifications to customers.
Site.pro for WooCommerce Developer Profile
2 plugins · 200 total installs
How We Detect Site.pro for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/b1-accounting/css/b1-accounting-admin.css/wp-content/plugins/b1-accounting/js/b1-accounting-admin.js/wp-content/plugins/b1-accounting/js/b1-accounting-admin.jsb1-accounting/css/b1-accounting-admin.css?ver=b1-accounting/js/b1-accounting-admin.js?ver=HTML / DOM Fingerprints
b1-accounting-dashboard<!-- Site.pro for WooCommerce Dashboard --><!-- Site.pro Settings -->data-plugin-name="b1-accounting"data-security=""data-base-url=""b1