Base (formerly BaseLinker) – 300+ marketplaces, 150+ carriers & PIM & OMS & WMS in one Security & Risk Analysis

wordpress.org/plugins/baselinker-woo

Additional REST API endpoints for integration with BaseLinker.

4K active installs v1.0.28 PHP + WP 4.5.0+ Updated Oct 9, 2025
marketplace-integrationsomspimsales-managementwarehouse-management
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Base (formerly BaseLinker) – 300+ marketplaces, 150+ carriers & PIM & OMS & WMS in one Safe to Use in 2026?

Generally Safe

Score 100/100

Base (formerly BaseLinker) – 300+ marketplaces, 150+ carriers & PIM & OMS & WMS in one has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "baselinker-woo" plugin v1.0.28 exhibits a mixed security posture. On the positive side, the plugin demonstrates strong security practices in several key areas. It utilizes prepared statements for all its SQL queries, has no file operations, performs no external HTTP requests, and all detected output is properly escaped. Furthermore, there is no recorded vulnerability history, indicating a potentially stable and secure past. This suggests a development team that is generally aware of secure coding principles.

However, significant concerns arise from the static analysis of its attack surface. The plugin exposes 5 REST API routes, and critically, 3 of these lack proper permission callbacks. This creates a direct and exploitable pathway for unauthenticated attackers to interact with potentially sensitive plugin functionalities. The absence of nonce checks on AJAX handlers, while there are none, also leaves a potential vulnerability if any were to be added without proper security considerations. The lack of capability checks in any of the identified entry points further exacerbates the risk associated with the unprotected REST API routes.

Given the complete absence of any known historical vulnerabilities, it might suggest a lack of targeted attacks or a consistent security development lifecycle. However, the identified unprotected REST API routes represent a clear and present danger that could be leveraged by attackers regardless of past history. The plugin's strengths in SQL and output handling are overshadowed by the significant risk posed by its exposed and unauthenticated REST API endpoints.

Key Concerns

  • Unprotected REST API routes
  • No capability checks on entry points
  • No nonce checks on AJAX handlers (if added)
Vulnerabilities
None known

Base (formerly BaseLinker) – 300+ marketplaces, 150+ carriers & PIM & OMS & WMS in one Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Base (formerly BaseLinker) – 300+ marketplaces, 150+ carriers & PIM & OMS & WMS in one Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
7 prepared
Unescaped Output
0
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

88% prepared8 total queries

Output Escaping

100% escaped3 total outputs
Attack Surface
3 unprotected

Base (formerly BaseLinker) – 300+ marketplaces, 150+ carriers & PIM & OMS & WMS in one Attack Surface

Entry Points5
Unprotected3

REST API Routes 5

GET/wp-json/bl/v2/shipping_methods/baselinker.php:650
GET/wp-json/wc-bl/v2/product_list/baselinker.php:651
GET/wp-json/wc-bl/v2/category_list/baselinker.php:652
GET/wp-json/bl/v2/additional_order_statuses/baselinker.php:653
GET/wp-json/bl/v2/version/baselinker.php:654
WordPress Hooks 10
filterposts_searchbaselinker.php:604
actionrest_api_initbaselinker.php:649
actionbefore_woocommerce_initbaselinker.php:658
actionplugins_loadedbaselinker.php:665
filterwoocommerce_rest_prepare_shop_order_objectbaselinker.php:669
filterwoocommerce_rest_insert_shop_order_objectbaselinker.php:670
filterwoocommerce_rest_shop_order_object_querybaselinker.php:671
filterwoocommerce_rest_prepare_product_objectbaselinker.php:672
filterwoocommerce_rest_product_object_querybaselinker.php:673
filterwoocommerce_product_data_store_cpt_get_products_querybaselinker.php:674
Maintenance & Trust

Base (formerly BaseLinker) – 300+ marketplaces, 150+ carriers & PIM & OMS & WMS in one Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 9, 2025
PHP min version
Downloads17K

Community Trust

Rating84/100
Number of ratings5
Active installs4K
Developer Profile

Base (formerly BaseLinker) – 300+ marketplaces, 150+ carriers & PIM & OMS & WMS in one Developer Profile

base

1 plugin · 4K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Base (formerly BaseLinker) – 300+ marketplaces, 150+ carriers & PIM & OMS & WMS in one

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/baselinker-woo/baselinker-woo.php
Version Parameters
baselinker-woo/baselinker-woo.php?ver=

HTML / DOM Fingerprints

JS Globals
baselinker_ajax_object
REST Endpoints
/wp-json/baselinker-woo/
FAQ

Frequently Asked Questions about Base (formerly BaseLinker) – 300+ marketplaces, 150+ carriers & PIM & OMS & WMS in one