Bizuno Accounting – Powerful ERP & Accounting for WordPress Security & Risk Analysis

wordpress.org/plugins/bizuno-accounting

Bizuno Accounting: Transform WordPress into a robust ERP hub with double-entry accounting, inventory, CRM, and WooCommerce integration – by PhreeSoft.

10 active installs v7.3.7 PHP 8.0+ WP 6.5+ Updated Unknown
accountingbookkeepingcrmerpinventory
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bizuno Accounting – Powerful ERP & Accounting for WordPress Safe to Use in 2026?

Generally Safe

Score 100/100

Bizuno Accounting – Powerful ERP & Accounting for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The bizuno-accounting plugin version 7.3.7 presents a mixed security posture. While there are no recorded historical vulnerabilities or critical taint analysis findings, the static analysis reveals significant areas of concern. The plugin has two AJAX handlers, both of which lack proper authentication checks. This creates a substantial attack surface where unauthenticated users could potentially interact with sensitive plugin functionality. Additionally, the plugin uses raw SQL queries without prepared statements, which is a common vector for SQL injection vulnerabilities. While the plugin does have some output escaping in place, its effectiveness is limited by the presence of unescaped outputs.

The absence of recorded CVEs is a positive sign, suggesting the plugin may have been developed with some security awareness or has not been a target of extensive research. However, the static analysis findings, particularly the unprotected AJAX endpoints and the unparameterized SQL queries, indicate potential weaknesses that could be exploited. The limited number of entry points is a strength, but the lack of security controls on these entry points overshadows this advantage. A balanced conclusion would be that while the plugin has avoided public vulnerabilities to date, the presence of exploitable patterns in its code warrants caution and suggests a need for immediate remediation of the identified security flaws.

Key Concerns

  • Unprotected AJAX handlers
  • Raw SQL queries without prepared statements
  • Partial output escaping
Vulnerabilities
None known

Bizuno Accounting – Powerful ERP & Accounting for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Bizuno Accounting – Powerful ERP & Accounting for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
0 prepared
Unescaped Output
2
2 escaped
Nonce Checks
1
Capability Checks
1
File Operations
4
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared3 total queries

Output Escaping

50% escaped4 total outputs
Attack Surface
2 unprotected

Bizuno Accounting – Powerful ERP & Accounting for WordPress Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_bizuno_ajaxbizuno-accounting.php:36
noprivwp_ajax_bizuno_ajaxbizuno-accounting.php:37
WordPress Hooks 10
actioninitbizuno-accounting.php:30
actionadmin_initbizuno-accounting.php:31
actionadmin_menubizuno-accounting.php:32
actionwp_before_admin_bar_renderbizuno-accounting.php:33
actionphpmailer_initbizuno-accounting.php:34
actiontemplate_redirectbizuno-accounting.php:35
actionbizuno_daily_eventbizuno-accounting.php:38
filterplugin_requirementsbizuno-accounting.php:40
filterxmlrpc_methodsbizuno-accounting.php:41
actionadmin_noticesbizuno-accounting.php:50

Scheduled Events 1

bizuno_daily_event
Maintenance & Trust

Bizuno Accounting – Powerful ERP & Accounting for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version8.0
Downloads15K

Community Trust

Rating90/100
Number of ratings4
Active installs10
Developer Profile

Bizuno Accounting – Powerful ERP & Accounting for WordPress Developer Profile

David Premo

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bizuno Accounting – Powerful ERP & Accounting for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bizuno-accounting/icon_16.png

HTML / DOM Fingerprints

JS Globals
BIZUNO_URL_VIEWBIZUNO_URL_PORTALmsgStackcleaneriodb
Shortcode Output
This page is reserved for authorized users of Bizuno Accounting/ERP. To access Bizuno, please <a href="/wp-login.php">click here</a> to log into your WordPress site and
FAQ

Frequently Asked Questions about Bizuno Accounting – Powerful ERP & Accounting for WordPress