
bidorbuy Store Integrator Security & Risk Analysis
wordpress.org/plugins/bidorbuystoreintegratorLooking for a new place for Your Ecommerce Business?
Is bidorbuy Store Integrator Safe to Use in 2026?
High Risk
Score 38/100bidorbuy Store Integrator carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
The bidorbuystoreintegrator plugin v2.12.0 presents a mixed security picture. On the positive side, the static analysis indicates a clean attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication. The plugin also demonstrates good practices by largely utilizing prepared statements for its SQL queries and having no external HTTP requests or file operations, which are common vectors for exploitation. However, significant concerns arise from the low percentage of properly escaped output (11%), indicating a high potential for cross-site scripting (XSS) vulnerabilities. Furthermore, the complete absence of nonce checks and a single, unconfirmed capability check on entry points suggest a lack of robust authorization and input validation mechanisms.
The vulnerability history is a major red flag. With two known CVEs, both of which are currently unpatched, the plugin has a history of critical and high-severity issues, specifically Cross-site Scripting and Code Injection. The fact that the last vulnerability was dated in the future (2026-01-16) is highly unusual and likely an anomaly in the data reporting, but the existence of unpatched vulnerabilities remains a severe risk. These past vulnerabilities, coupled with the current code analysis showing insufficient output escaping and weak authorization checks, strongly suggest that this plugin is a high-risk component for any WordPress installation. While the attack surface is small, the potential impact of exploiting existing, unpatched vulnerabilities remains significant.
Key Concerns
- Two unpatched CVEs
- Low percentage of properly escaped output
- Zero nonce checks on entry points
- Only one capability check found
bidorbuy Store Integrator Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
bidorbuy Store Integrator <= 2.12.0 - Reflected Cross-Site Scripting
bidorbuy Store Integrator <= 2.12.0 - Authenticated (Admin+) Remote Code Execution
bidorbuy Store Integrator Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
bidorbuy Store Integrator Attack Surface
WordPress Hooks 31
Maintenance & Trust
bidorbuy Store Integrator Maintenance & Trust
Maintenance Signals
Community Trust
bidorbuy Store Integrator Alternatives
Import WooCommerce Suite
import-woocommerce
Use the WooCommerce Import Suite to import Products, Orders, Coupons, Customers, and Reviews with ease. Requires the WP Ultimate CSV Importer Free plu …
WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel
wp-all-export
Easily export data from any post type, custom field, or taxonomy to a CSV, XML, or Excel file of any custom format. Supports WooCommerce products, ord …
Product Import Export for WooCommerce – Import Export Product CSV Suite
product-import-export-for-woo
Easily import/export WooCommerce products (simple, grouped, external/affiliate) via CSV. Transfer product data, including images, reviews, categories, …
YITH WooCommerce Catalog Mode
yith-woocommerce-catalog-mode
YITH WooCommerce Catalog Mode, a plugin for disabling sales in your e-commerce and turn it into an e-commerce into an online catalogue.
افزونه رسمی ترب
products-extractor-for-woocommerce
این پلاگین جهت دریافت تمامی محصولات فروشگاه های وردپرسی که از پلاگین ووکامرس استفاده می کنند، توسعه یافته است.
bidorbuy Store Integrator Developer Profile
5 plugins · 100 total installs
How We Detect bidorbuy Store Integrator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bidorbuystoreintegrator/includes/assets/css/admin.css/wp-content/plugins/bidorbuystoreintegrator/includes/assets/css/styles.css/wp-content/plugins/bidorbuystoreintegrator/includes/assets/js/admin.js/wp-content/plugins/bidorbuystoreintegrator/includes/assets/js/scripts.js/wp-content/plugins/bidorbuystoreintegrator/includes/assets/js/admin.js/wp-content/plugins/bidorbuystoreintegrator/includes/assets/js/scripts.jsbidorbuystoreintegrator/includes/assets/css/admin.css?ver=bidorbuystoreintegrator/includes/assets/css/styles.css?ver=bidorbuystoreintegrator/includes/assets/js/admin.js?ver=bidorbuystoreintegrator/includes/assets/js/scripts.js?ver=HTML / DOM Fingerprints
bobsi-settings-page<!-- WARNING: bidorbuy Store Integrator requires WooCommerce to be activated. -->data-bidorbuy-tokenbobsi_product_idbobsi_variation_idbobsi_ajax_url/wp-json/bidorbuystoreintegrator/v1/products/wp-json/bidorbuystoreintegrator/v1/orders[bidorbuy_product_list][bidorbuy_featured_products][bidorbuy_product_details]