
Base (formerly BaseLinker) – 300+ marketplaces, 150+ carriers & PIM & OMS & WMS in one Security & Risk Analysis
wordpress.org/plugins/baselinker-wooAdditional REST API endpoints for integration with BaseLinker.
Is Base (formerly BaseLinker) – 300+ marketplaces, 150+ carriers & PIM & OMS & WMS in one Safe to Use in 2026?
Generally Safe
Score 100/100Base (formerly BaseLinker) – 300+ marketplaces, 150+ carriers & PIM & OMS & WMS in one has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "baselinker-woo" plugin v1.0.28 exhibits a mixed security posture. On the positive side, the plugin demonstrates strong security practices in several key areas. It utilizes prepared statements for all its SQL queries, has no file operations, performs no external HTTP requests, and all detected output is properly escaped. Furthermore, there is no recorded vulnerability history, indicating a potentially stable and secure past. This suggests a development team that is generally aware of secure coding principles.
However, significant concerns arise from the static analysis of its attack surface. The plugin exposes 5 REST API routes, and critically, 3 of these lack proper permission callbacks. This creates a direct and exploitable pathway for unauthenticated attackers to interact with potentially sensitive plugin functionalities. The absence of nonce checks on AJAX handlers, while there are none, also leaves a potential vulnerability if any were to be added without proper security considerations. The lack of capability checks in any of the identified entry points further exacerbates the risk associated with the unprotected REST API routes.
Given the complete absence of any known historical vulnerabilities, it might suggest a lack of targeted attacks or a consistent security development lifecycle. However, the identified unprotected REST API routes represent a clear and present danger that could be leveraged by attackers regardless of past history. The plugin's strengths in SQL and output handling are overshadowed by the significant risk posed by its exposed and unauthenticated REST API endpoints.
Key Concerns
- Unprotected REST API routes
- No capability checks on entry points
- No nonce checks on AJAX handlers (if added)
Base (formerly BaseLinker) – 300+ marketplaces, 150+ carriers & PIM & OMS & WMS in one Security Vulnerabilities
Base (formerly BaseLinker) – 300+ marketplaces, 150+ carriers & PIM & OMS & WMS in one Code Analysis
SQL Query Safety
Output Escaping
Base (formerly BaseLinker) – 300+ marketplaces, 150+ carriers & PIM & OMS & WMS in one Attack Surface
REST API Routes 5
WordPress Hooks 10
Maintenance & Trust
Base (formerly BaseLinker) – 300+ marketplaces, 150+ carriers & PIM & OMS & WMS in one Maintenance & Trust
Maintenance Signals
Community Trust
Base (formerly BaseLinker) – 300+ marketplaces, 150+ carriers & PIM & OMS & WMS in one Alternatives
TomS reCAPTCHA
toms-recaptcha
Integrated Google ReCaptcha for WordPress.Protect the login, register, lostpassword and comment forms. Support Woocommerce, Ultimate Member and more p …
Popcustoms – Print on demand & dropshipping, Free Personalizer
popcustoms-integration-for-woocommerce
Print on demand products & embroidery provider, fulfillment & global dropshipping, customize shoes, T-shirt, hats, hoodie, jacket, blanket and more.
CI HUB Connector
ci-hub-connector
Work better with images, text and video by connecting your WordPress Site to your cloud storage or the stock media platform of your choice.
Pimp my Site – Christmas Edition
pimp-my-site-christmas-edition
Pimp your WordPress Site with Awesome Christmas Effects
Comscore tag
comscore-tag
Simply add Comscore tracking code.
Base (formerly BaseLinker) – 300+ marketplaces, 150+ carriers & PIM & OMS & WMS in one Developer Profile
1 plugin · 4K total installs
How We Detect Base (formerly BaseLinker) – 300+ marketplaces, 150+ carriers & PIM & OMS & WMS in one
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/baselinker-woo/baselinker-woo.phpbaselinker-woo/baselinker-woo.php?ver=HTML / DOM Fingerprints
baselinker_ajax_object/wp-json/baselinker-woo/