
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) Security & Risk Analysis
wordpress.org/plugins/barcode-scanner-lite-pos-to-manage-products-inventory-and-ordersManage and sell (POS) your inventory. It reads barcodes & finds woocommerce products/orders. Create orders right from the wp-admin.
Is Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) Safe to Use in 2026?
Mostly Safe
Score 75/100Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) is generally safe to use. 14 past CVEs were resolved. Keep it updated.
This plugin exhibits a concerning security posture due to a significant number of unprotected entry points and a history of numerous, severe vulnerabilities. The static analysis reveals 6 out of 10 total entry points lack authentication checks, including all 6 AJAX handlers. This immediately exposes the plugin to potential abuse by unauthenticated users. Furthermore, the presence of the `unserialize` function, a known vector for remote code execution when handling untrusted input, is a critical red flag. The taint analysis identifies 2 high-severity flows, indicating potential pathways for malicious data manipulation or exploitation.
While the plugin shows some positive signs like the use of prepared statements for a majority of SQL queries and a relatively high percentage of properly escaped output, these strengths are overshadowed by its historical vulnerability patterns. The plugin has a history of 14 CVEs, including critical and high-severity issues such as Path Traversal, Information Exposure, SQL Injection, and CSRF. The commonality of these vulnerability types suggests recurring weaknesses in input validation and authorization logic. The most recent vulnerability reported in 2025 is concerning, indicating a continued struggle to maintain a secure codebase. Overall, while efforts are made in certain areas of security, the substantial number of unprotected entry points and the extensive vulnerability history paint a picture of a high-risk plugin that requires immediate attention and remediation.
Key Concerns
- Unprotected AJAX handlers
- Dangerous function 'unserialize' found
- High severity taint flows identified
- Large number of total CVEs
- Previous critical severity CVEs
- Previous high severity CVEs
- Common vulnerability types (Path Traversal, SQLi, etc.)
- Missing nonce checks
- Limited capability checks
- Unsanitized paths in taint flows
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) Security Vulnerabilities
CVEs by Year
Severity Breakdown
14 total CVEs
Barcode Scanner with Inventory & Order Manager <= 1.10.4 - Authenticated (Shop Manager+) Directory Traversal
Barcode Scanner with Inventory & Order Manager <= 1.9.0 - Authenticated (Admin+) Arbitrary File Download
Barcode Scanner with Inventory & Order Manager <= 1.6.7 - Authenticated (Admin+) Arbitrary File Upload
Barcode Scanner with Inventory & Order Manager <= 1.6.6 - Reflected Cross-Site Scripting
Barcode Scanner with Inventory & Order Manager <= 1.6.1 - Authenticated (Subscriber+) SQL Injection
Barcode Scanner with Inventory & Order Manager <= 1.5.4 - Unauthenticated Information Exposure
Barcode Scanner with Inventory & Order Manager <= 1.5.4 - Cross-Site Request Forgery
Barcode Scanner with Inventory & Order Manager <= 1.5.4 - Authenticated (Subscriber+) SQL Injection
Barcode Scanner with Inventory & Order Manager <= 1.5.3 - Missing Authorization
Barcode Scanner with Inventory & Order Manager <= 1.5.3 - Unauthenticated Privilege Escalation
Barcode Scanner with Inventory & Order Manager <= 1.5.3 - Missing Authorization
Barcode Scanner with Inventory & Order Manager <= 1.5.3 - Reflected Cross-Site Scripting
Barcode Scanner with Inventory & Order Manager <= 1.5.1 - Unauthenticated Arbitrary File Upload via uploadFile
Barcode Scanner with Inventory & Order Manager <= 1.5.1 - Unauthenticated SQL Injection via userToken
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) Attack Surface
AJAX Handlers 6
Shortcodes 4
WordPress Hooks 115
Maintenance & Trust
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) Maintenance & Trust
Maintenance Signals
Community Trust
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) Alternatives
WCPOS – Point of Sale (POS) plugin for WooCommerce
woocommerce-pos
WCPOS is a simple application for taking orders at the Point of Sale (POS) using your WooCommerce store.
SimpanKira for WooCommerce
simpankira-for-woocommerce
SimpanKira integration for WooCommerce.
Vitepos – Point of Sale (POS) for WooCommerce
vitepos-lite
Fast, modern WooCommerce POS plugin for managing sales, outlets, and cashiers directly in WordPress.
wePOS – Point Of Sale (POS) for WooCommerce
wepos
WooCommerce point of sale WordPress plugin.
Oliver POS – A WooCommerce Point of Sale (POS)
oliver-pos
Oliver POS is a WooCommerce Point of Sale (POS) integrated into your shop. Always in sync with your e-commerce shop, Oliver POS lets you sell in-store …
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) Developer Profile
5 plugins · 3K total installs
How We Detect Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/assets/css/barcode-scanner-lite-pos.css/wp-content/plugins/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/assets/css/backend.css/wp-content/plugins/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/assets/css/frontend.css/wp-content/plugins/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/assets/css/loading.css/wp-content/plugins/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/assets/js/barcode-scanner-lite-pos.js/wp-content/plugins/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/assets/js/backend.js/wp-content/plugins/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/assets/js/frontend.js/wp-content/plugins/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/assets/js/settings.jsvendor/ckeditor/ckeditor/ckeditor.jsassets/js/frontend.jsassets/js/backend.jsassets/js/settings.jsassets/js/barcode-scanner-lite-pos.js/wp-content/plugins/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/assets/css/barcode-scanner-lite-pos.css?ver=/wp-content/plugins/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/assets/css/backend.css?ver=/wp-content/plugins/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/assets/css/frontend.css?ver=/wp-content/plugins/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/assets/css/loading.css?ver=/wp-content/plugins/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/assets/js/barcode-scanner-lite-pos.js?ver=/wp-content/plugins/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/assets/js/backend.js?ver=/wp-content/plugins/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/assets/js/frontend.js?ver=/wp-content/plugins/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/assets/js/settings.js?ver=HTML / DOM Fingerprints
usbs-main-wrapperusbs-scanner-wrapperusbs-barcode-scanner-btn<!-- USBS-SCANNER-HTML-START --><!-- USBS-SCANNER-HTML-END -->data-usbs-actiondata-usbs-iddata-usbs-roleusbs_backend_paramsusbs_frontend_paramsusbs_settings_params/wp-json/us-barcode-scanner/v1/products/wp-json/us-barcode-scanner/v1/orders/wp-json/us-barcode-scanner/v1/locations/wp-json/us-barcode-scanner/v1/logs/wp-json/us-barcode-scanner/v1/settings/wp-json/us-barcode-scanner/v1/scanner/wp-json/us-barcode-scanner/v1/sync