
Brilliant Directories Sync for WooCommerce Security & Risk Analysis
wordpress.org/plugins/brilliant-directories-sync-for-woocommerceSync WooCommerce customers seamlessly with Brilliant Directories using this integration plugin.
Is Brilliant Directories Sync for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Brilliant Directories Sync for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "brilliant-directories-sync-for-woocommerce" plugin, version 1.0.6, exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and shows no recorded vulnerability history, suggesting diligent maintenance and a lack of known exploitable flaws. The absence of dangerous functions and file operations further contributes to a generally stable codebase.
However, significant concerns arise from the attack surface analysis. The presence of five AJAX handlers, with one lacking authentication checks, presents a clear and immediate risk. This unprotected entry point could be leveraged by unauthenticated attackers to trigger unintended actions within the plugin. Furthermore, the taint analysis reveals two flows with unsanitized paths, indicating potential vulnerabilities related to how external data is processed, even if they are not currently classified as critical or high severity.
The limited use of nonces and capability checks (3 and 1 respectively) in conjunction with the unprotected AJAX endpoint suggests a broader pattern of insufficient input validation and authorization. While the plugin's SQL security is strong, the output escaping is only 55% properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-controlled data is rendered without adequate sanitization. The use of Select2 as a bundled library, without information on its version, also carries a minor risk if an older, vulnerable version is included.
In conclusion, while the plugin benefits from robust SQL handling and a clean vulnerability history, the unprotected AJAX endpoint, unsanitized taint flows, and insufficient output escaping are significant weaknesses that require immediate attention. The overall security is moderate, with specific areas that significantly elevate the risk profile.
Key Concerns
- AJAX handler without authentication checks
- Flows with unsanitized paths
- Output escaping is only 55% proper
- Limited nonce checks
- Limited capability checks
Brilliant Directories Sync for WooCommerce Security Vulnerabilities
Brilliant Directories Sync for WooCommerce Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Brilliant Directories Sync for WooCommerce Attack Surface
AJAX Handlers 5
WordPress Hooks 14
Scheduled Events 4
Maintenance & Trust
Brilliant Directories Sync for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Brilliant Directories Sync for WooCommerce Alternatives
WP User Merger
wp-user-merger
WP User Merger is a WordPress plugin that allows you to merge two different users with seletable user fields.
Conditional Logic for Beaver Builder and Woo Memberships
conditional-logic-for-beaver-builder-and-woo-memberships
Simple plugin for Beaver Builder's Beaver Themer to enable conditional logic based on WooCommerce Membership status
MailChimp Sync for WooCommerce Memberships
true-mailchimp-sync-for-woo-memberships
Allows to sync users with every status of your WooCommerce Memberships plans with MailChimp lists.
Memberships Frontend Registration
memberships-frontend-registration
Allows users to register for WooCommerce Membership plans from frontend, manage required product, and streamline the membership registration process.
PG Sync for Klaviyo and Woo Memberships and Subscriptions
pg-sync-for-klaviyo-and-woo-memberships-and-subscriptions
This is a very lightweight plugin that synchs WooCommerce Memberships (and optionally Subscriptions) to Klaviyo.
Brilliant Directories Sync for WooCommerce Developer Profile
3 plugins · 10 total installs
How We Detect Brilliant Directories Sync for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/brilliant-directories-sync-for-woocommerce/assets/css/admin-style.css/wp-content/plugins/brilliant-directories-sync-for-woocommerce/assets/js/admin-script.js/wp-content/plugins/brilliant-directories-sync-for-woocommerce/assets/css/select2.min.css/wp-content/plugins/brilliant-directories-sync-for-woocommerce/assets/js/select2.min.jsassets/js/admin-script.jsassets/js/select2.min.jsbrilliant-directories-sync-for-woocommerce/assets/css/admin-style.css?ver=brilliant-directories-sync-for-woocommerce/assets/js/admin-script.js?ver=brilliant-directories-sync-for-woocommerce/assets/css/select2.min.css?ver=brilliant-directories-sync-for-woocommerce/assets/js/select2.min.js?ver=HTML / DOM Fingerprints
swc-plugin-disabledswc-woocommerce-disabledbrildirwcsyncSettingsbrildirwcpluginSettings