
Bot for Telegram on WooCommerce Security & Risk Analysis
wordpress.org/plugins/bot-for-telegram-on-woocommerceBot for Telegram on WooCommerce is a plugin that allows you to create a telegram online store based on your website with WooCommerce.
Is Bot for Telegram on WooCommerce Safe to Use in 2026?
Mostly Safe
Score 74/100Bot for Telegram on WooCommerce is generally safe to use. 2 past CVEs were resolved. Keep it updated.
The "bot-for-telegram-on-woocommerce" plugin version 1.2.9 presents a mixed security posture. While it demonstrates good practices with a high percentage of properly escaped output and a substantial number of nonce and capability checks, several critical concerns emerge from the static analysis. The presence of 11 AJAX handlers, with one lacking authentication checks, and 5 REST API routes without permission callbacks represent significant attack vectors. Furthermore, the use of the `unserialize` function twice is a dangerous practice that could lead to code injection if user-supplied data is unserialized. The plugin's vulnerability history is also a major red flag, with two known CVEs, one of which remains unpatched and is rated as high severity. The common vulnerability types, missing authorization and exposure of sensitive information, directly correlate with the findings in the static analysis. The last vulnerability being in the future (2025-05-19) is highly unusual and suggests potential data integrity issues with the vulnerability history itself, but based on the provided data, it highlights a recent history of exploitable flaws.
Key Concerns
- Unpatched High Severity CVE
- AJAX handler without auth check
- REST API routes without permission callbacks
- Use of unserialize function
- Medium Severity CVE
Bot for Telegram on WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Bot for Telegram on WooCommerce <= 1.2.6 - Missing Authorization
Bot for Telegram on WooCommerce <= 1.2.7 - Authenticated (Subscriber+) Telegram Bot Token Disclosure to Authentication Bypass
Bot for Telegram on WooCommerce Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Bot for Telegram on WooCommerce Attack Surface
AJAX Handlers 11
REST API Routes 5
Shortcodes 1
WordPress Hooks 83
Maintenance & Trust
Bot for Telegram on WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Bot for Telegram on WooCommerce Alternatives
Site Chat on Telegram
site-chat-on-telegram
Integrate a support chat on your website with Telegram. Customers message via chat widget; admins reply in Telegram.
Đẩy Thông Báo Woocommerce tới Telegram
wc-telegram-bot
Đây là plugin giúp đẩy thông báo đơn hàng Woocommerce qua Telegram BOT. Phát triển bởi Tám Tinh Tế.
Channeller – Telegram Channel Administrator
channeller-telegram-channel-administrator
Send Text, Link, Photo, Video and Audio Files from Wordpress to Telegram Channels and Groups using bots.
ChatBot for Telegram
chatbot-for-telegram
Telegram ChatBot. Create a Chat Bot for Telegram with the power of the WPBot. Supports Simple text Responses, conversational forms and more
Teletter Telegram Newsletter
teletter-telegram-newsletter
Send Newsletter from Telegram Bot, user can subscribe to your site from Telegram Bot.
Bot for Telegram on WooCommerce Developer Profile
3 plugins · 400 total installs
How We Detect Bot for Telegram on WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bot-for-telegram-on-woocommerce/assets/css/styles.css/wp-content/plugins/bot-for-telegram-on-woocommerce/assets/js/login.jsbot-for-telegram-on-woocommerce/assets/css/styles.css?ver=bot-for-telegram-on-woocommerce/assets/js/login.js?ver=HTML / DOM Fingerprints
bftow_stylebftow_loginbftow_localize