
Boopis WooCommerce RFQ Security & Risk Analysis
wordpress.org/plugins/boopis-woocommerce-rfqReplaces products with a price of zero to an open form for inquiry
Is Boopis WooCommerce RFQ Safe to Use in 2026?
Generally Safe
Score 92/100Boopis WooCommerce RFQ has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "boopis-woocommerce-rfq" plugin v3.0.9 presents a mixed security posture. While it shows a clean vulnerability history with no known CVEs and no bundled libraries, the static analysis reveals several areas of concern regarding its attack surface and code hygiene. A significant portion of its AJAX handlers, specifically 4 out of 6, lack proper authentication checks, creating potential entry points for unauthorized actions. Furthermore, the plugin's SQL queries are not prepared, indicating a risk of SQL injection vulnerabilities, and a concerning percentage of output is not properly escaped, raising concerns about cross-site scripting (XSS) vulnerabilities.
The taint analysis, while limited in scope with only 3 flows analyzed, did identify one flow with unsanitized paths. Although this flow did not reach a critical or high severity in the analysis, it is indicative of potential issues with how user-supplied data is handled, especially when combined with the lack of prepared SQL statements and unescaped output. The presence of nonce checks and capability checks is a positive sign, demonstrating some awareness of WordPress security best practices. However, the lack of these checks on a substantial number of AJAX handlers, coupled with the unescaped output and raw SQL queries, outweighs the strengths and suggests that the plugin requires significant security improvements to be considered robust.
Key Concerns
- AJAX handlers without authentication checks
- SQL queries without prepared statements
- Insufficient output escaping
- Flow with unsanitized paths (taint analysis)
Boopis WooCommerce RFQ Security Vulnerabilities
Boopis WooCommerce RFQ Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Boopis WooCommerce RFQ Attack Surface
AJAX Handlers 6
Shortcodes 1
WordPress Hooks 47
Maintenance & Trust
Boopis WooCommerce RFQ Maintenance & Trust
Maintenance Signals
Community Trust
Boopis WooCommerce RFQ Alternatives
Quotes for WooCommerce
quotes-for-woocommerce
This plugin allows the site admin the ability to accept quote requests for products. Prices can be hidden. No payments will be taken at Checkout.
Place Order Without Payment for WooCommerce
wc-place-order-without-payment
Place Order Without Payment for WooCommerce will allow users to place orders directly without payment.
Price Quote for WooCommerce
woo-price-quote-inquiry
Transform your WooCommerce store into a B2B powerhouse by allowing customers to request price quotes for products instead of direct purchasing.
ELEX WooCommerce Catalog Mode
elex-woocommerce-catalog-mode
Easily turn your WooCommerce store into catalog mode with the best plugin designed for efficiency and effectiveness.
NP Quote Request for WooCommerce
woo-rfq-for-woocommerce
NP Quote Request for WooCommerce enables your customers to easily submit quote requests to your WooCommerce store. Flexible WooCommerce Quote Request!
Boopis WooCommerce RFQ Developer Profile
1 plugin · 70 total installs
How We Detect Boopis WooCommerce RFQ
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/boopis-woocommerce-rfq/assets/css/styles.css/wp-content/plugins/boopis-woocommerce-rfq/assets/js/frontend/add-to-quote.js/wp-content/plugins/boopis-woocommerce-rfq/assets/js/frontend/add-to-quote.jsboopis-woocommerce-rfq/assets/css/styles.css?ver=boopis-woocommerce-rfq/assets/js/frontend/add-to-quote.js?ver=HTML / DOM Fingerprints
boopis-rfq-form<!-- BOOPIS RFQ TEMPLATE FILE -->data-rfq-ajax-urlboopis_rfq_ajax_obj[boopis_rfq]