
Better WishList API Security & Risk Analysis
wordpress.org/plugins/better-wlm-apiA better version of the WishList Member API. Created to make the connection to external services like ActiveCampaign and Autorespond a lot easier.
Is Better WishList API Safe to Use in 2026?
Generally Safe
Score 90/100Better WishList API has a strong security track record. Known vulnerabilities have been patched promptly.
The "better-wlm-api" plugin v1.1.5 presents a mixed security posture. While it shows strengths such as a lack of external HTTP requests and no bundled outdated libraries, significant concerns emerge from the static analysis. The presence of an unprotected AJAX handler creates a substantial attack vector. The taint analysis indicates that all analyzed flows involve unsanitized paths, and a concerningly low percentage (34%) of output is properly escaped, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities.
The vulnerability history reveals a pattern of past security issues, including a high-severity vulnerability and a medium-severity one, with the last recorded vulnerability being quite recent. This suggests a recurring struggle with secure coding practices within the plugin. Although there are currently no unpatched CVEs, the historical trend and the findings from the static analysis indicate a need for considerable improvement in security.
In conclusion, despite some positive aspects, the "better-wlm-api" plugin v1.1.5 is currently considered a high-risk plugin due to the unprotected entry point, pervasive unsanitized taint flows, inadequate output escaping, and a history of past vulnerabilities. Users should exercise extreme caution and prioritize updating to a version that addresses these identified weaknesses.
Key Concerns
- Unprotected AJAX handler
- Flows with unsanitized paths
- Low output escaping percentage
- SQL queries without prepared statements
- Missing nonce checks
- Missing capability checks
- High severity historical vulnerability
- Medium severity historical vulnerability
Better WishList API Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Better WishList API <= 1.1.4 - Reflected Cross-Site Scripting
Better WishList API <= 1.1.3 - Unauthenticated Stored Cross-Site Scripting
Better WishList API Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Better WishList API Attack Surface
AJAX Handlers 1
WordPress Hooks 6
Maintenance & Trust
Better WishList API Maintenance & Trust
Maintenance Signals
Community Trust
Better WishList API Alternatives
Better OM API
better-om-api
A better version of the OptimizeMember API, specially tailored for the Dutch service Autorespond.
Meta for WooCommerce
facebook-for-woocommerce
Get the Official Meta for WooCommerce plugin for powerful ways to help grow your business.
PixelYourSite – Your smart PIXEL (TAG) & API Manager
pixelyoursite
Add Meta Pixel with Conversion API, Google Analytics (GA4) + Consent Mode, Google Tag Manager, and Head & Footer scripts.
Meta pixel for WordPress
official-facebook-pixel
Grow your business with Meta for WordPress!
WooCommerce Legacy REST API
woocommerce-legacy-rest-api
The WooCommerce Legacy REST API, which is now part of WooCommerce itself but will be removed in WooCommerce 9.0.
Better WishList API Developer Profile
2 plugins · 210 total installs
How We Detect Better WishList API
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/better-wlm-api/assets/css/style-admin.cssHTML / DOM Fingerprints
<!-- hint: register our custom menus --><!-- hint: register plugin options --><!-- hint: register custom css --><!-- hint: put the API in the loop -->+13 more