Bazario Security & Risk Analysis

wordpress.org/plugins/bazario

Bazario Elementor widgets is a plugin that adds innovative features to websites.

0 active installs v1.0.1 PHP 7.4+ WP 5.4+ Updated Feb 24, 2025
bazaarelementormarketplacewidgets
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bazario Safe to Use in 2026?

Generally Safe

Score 92/100

Bazario has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "bazario" v1.0.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices in several areas. Notably, there are no dangerous function calls, all SQL queries are properly prepared, and external HTTP requests are absent. The presence of a significant number of nonce and capability checks suggests an effort to implement access control. However, a concerning aspect is the substantial attack surface exposed without proper authorization. A significant portion of AJAX handlers and a REST API route lack authentication or permission callbacks, creating potential entry points for malicious actors. While the plugin has no recorded vulnerability history, this does not guarantee future security, especially given the identified vulnerabilities in its attack surface. The taint analysis also revealed flows with unsanitized paths, although currently rated as low severity, this warrants attention. Overall, "bazario" v1.0.1 has strengths in its handling of core security functions but suffers from weaknesses in access control for its exposed entry points.

Key Concerns

  • Unprotected AJAX handlers
  • Unprotected REST API route
  • Taint flows with unsanitized paths
  • Bundled library (Select2) may be outdated
Vulnerabilities
None known

Bazario Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Bazario Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Bazario Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
160
726 escaped
Nonce Checks
10
Capability Checks
14
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

100% prepared2 total queries

Output Escaping

82% escaped886 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
load_quickview (modules\quick-view\QuickView.php:66)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
7 unprotected

Bazario Attack Surface

Entry Points13
Unprotected7

AJAX Handlers 12

authwp_ajax_bazario_open_template_popupbuilder\template-cpt.php:42
authwp_ajax_bazario_save_templatebuilder\template-cpt.php:43
authwp_ajax_bazario_load_quickviewmodules\quick-view\QuickView.php:12
noprivwp_ajax_bazario_load_quickviewmodules\quick-view\QuickView.php:13
authwp_ajax_bazario_add_to_cartmodules\quick-view\QuickView.php:16
noprivwp_ajax_bazario_add_to_cartmodules\quick-view\QuickView.php:17
authwp_ajax_bazario_update_cart_infoutils\cart-utils.php:10
noprivwp_ajax_bazario_update_cart_infoutils\cart-utils.php:11
authwp_ajax_bazario_update_cart_quantityutils\cart-utils.php:14
noprivwp_ajax_bazario_update_cart_quantityutils\cart-utils.php:15
authwp_ajax_bazario_clear_cartutils\cart-utils.php:18
noprivwp_ajax_bazario_clear_cartutils\cart-utils.php:19

REST API Routes 1

GET/wp-json/bazario/v1/advanced-searchutils\api-utils.php:14
WordPress Hooks 66
actionwp_enqueue_scriptsbazario.php:54
actioninitbazario.php:55
actionwoocommerce_after_shop_loop_item_titlebazario.php:82
actionelementor/editor/after_enqueue_stylesbazario.php:116
filtertemplate_includebuilder\class-woo.php:11
actioninitbuilder\template-cpt.php:28
actioninitbuilder\template-cpt.php:29
actionadd_meta_boxesbuilder\template-cpt.php:34
actionsave_postbuilder\template-cpt.php:35
actionadmin_noticesbuilder\template-cpt.php:38
actionadmin_enqueue_scriptsbuilder\template-cpt.php:39
actionpre_get_postsbuilder\template-cpt.php:51
actionwoocommerce_before_add_to_cart_quantityelements\widgets\add-to-cart\add-to-cart.php:2906
actionwoocommerce_after_add_to_cart_quantityelements\widgets\add-to-cart\add-to-cart.php:2928
filterwoocommerce_before_shop_loop_item_titleelements\widgets\archive-products\archive-products.php:2537
filterwoocommerce_before_shop_loop_item_titleelements\widgets\archive-products\archive-products.php:2545
filterwoocommerce_product_get_rating_htmlelements\widgets\archive-products\archive-products.php:2551
actionwoocommerce_after_shop_loop_itemelements\widgets\archive-products\archive-products.php:2561
actionwoocommerce_shop_loop_item_titleelements\widgets\archive-products\archive-products.php:2610
actionwoocommerce_after_shop_loop_item_titleelements\widgets\archive-products\archive-products.php:2627
filterwoocommerce_pagination_argselements\widgets\archive-products\archive-products.php:2670
filterwoocommerce_reviews_titleelements\widgets\single-product-tabs\single-product-tabs.php:1856
filterwoocommerce_product_tabselements\widgets\single-product-tabs\single-product-tabs.php:1858
filtercomments_templateelements\widgets\single-product-tabs\single-product-tabs.php:1922
actionadmin_menuinc\admin.php:11
actioninitinc\class-tgm-plugin-activation.php:268
filterload_textdomain_mofileinc\class-tgm-plugin-activation.php:269
actioninitinc\class-tgm-plugin-activation.php:272
actionadmin_menuinc\class-tgm-plugin-activation.php:421
actionadmin_headinc\class-tgm-plugin-activation.php:422
filterinstall_plugin_complete_actionsinc\class-tgm-plugin-activation.php:425
filterupdate_plugin_complete_actionsinc\class-tgm-plugin-activation.php:426
actionadmin_noticesinc\class-tgm-plugin-activation.php:429
actionadmin_initinc\class-tgm-plugin-activation.php:430
actionadmin_enqueue_scriptsinc\class-tgm-plugin-activation.php:431
actionadmin_menuinc\class-tgm-plugin-activation.php:434
actionload-plugins.phpinc\class-tgm-plugin-activation.php:438
actionswitch_themeinc\class-tgm-plugin-activation.php:441
actionswitch_themeinc\class-tgm-plugin-activation.php:444
actionadmin_initinc\class-tgm-plugin-activation.php:449
actionswitch_themeinc\class-tgm-plugin-activation.php:454
actionload_textdomain_mofileinc\class-tgm-plugin-activation.php:477
filterupgrader_source_selectioninc\class-tgm-plugin-activation.php:892
actionplugins_loadedinc\class-tgm-plugin-activation.php:2115
filtertgmpa_table_data_itemsinc\class-tgm-plugin-activation.php:2239
filterupgrader_source_selectioninc\class-tgm-plugin-activation.php:2979
actionadmin_initinc\class-tgm-plugin-activation.php:3149
actionupgrader_process_completeinc\class-tgm-plugin-activation.php:3244
filterupgrader_post_installinc\class-tgm-plugin-activation.php:3303
filterupgrader_post_installinc\class-tgm-plugin-activation.php:3448
actionelementor/editor/after_enqueue_scriptsinc\elementor-addon.php:58
actionelementor/initinc\elementor-addon.php:65
actionelementor/element/before_section_endinc\elementor-addon.php:85
actionelementor/element/section/section_advanced/after_section_endinc\elementor-extras.php:11
actiontgmpa_registerinc\plugin-install.php:27
actiontgmpa_registerinc\plugin-install.php:31
actionelementor/widgets/registerinit.php:26
actionelementor/frontend/after_enqueue_scriptsinit.php:29
actionelementor/frontend/after_register_scriptsinit.php:40
actionelementor/frontend/after_register_scriptsinit.php:51
actionelementor/frontend/after_enqueue_stylesinit.php:63
actionelementor/frontend/after_enqueue_stylesinit.php:75
actionwp_enqueue_scriptsmodules\quick-view\QuickView.php:9
actionwp_footermodules\quick-view\QuickView.php:20
actionrest_api_initutils\api-utils.php:10
actionwp_enqueue_scriptsutils\cart-utils.php:22
Maintenance & Trust

Bazario Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 24, 2025
PHP min version7.4
Downloads389

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Bazario Developer Profile

wpdive

8 plugins · 7K total installs

77
trust score
Avg Security Score
84/100
Avg Patch Time
40 days
View full developer profile
Detection Fingerprints

How We Detect Bazario

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bazario/assets/css/style.css/wp-content/plugins/bazario/assets/js/script.js
Script Paths
/wp-content/plugins/bazario/assets/js/script.js
Version Parameters
bazario/style.css?ver=bazario/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
bazario-custom-message
FAQ

Frequently Asked Questions about Bazario