Inventory Connector for Zoho and WooCommerce Security & Risk Analysis

wordpress.org/plugins/bstd-wc-zcrm

Inventory Connector for Zoho and WooCommerce integration is another well crafted wordpress plugin which enables the integration between wc and zoho in …

10 active installs v1.0 PHP 7.4+ WP 5.1+ Updated Apr 13, 2023
inventorywoocommercewoocommerce-integrationzohozoho-inventory
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Inventory Connector for Zoho and WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Inventory Connector for Zoho and WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The bstd-wc-zcrm plugin version 1.0 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any recorded vulnerabilities, including critical or high severity ones, is a very positive indicator. Furthermore, the plugin demonstrates good security practices by implementing nonce checks for all its AJAX handlers and ensuring a high percentage of output is properly escaped. The fact that there are no recorded flows with unsanitized paths or critical/high severity taint issues further strengthens this assessment.

However, there are a few areas that warrant attention. The plugin uses a significant number of SQL queries (13 total) with only 31% utilizing prepared statements. This creates a potential risk for SQL injection vulnerabilities, especially if any of these non-prepared queries handle user-supplied input. Additionally, while all AJAX handlers have nonce checks, there is only one recorded capability check across all entry points. This could leave certain AJAX actions vulnerable to privilege escalation if not adequately secured through other means.

In conclusion, the plugin's history of zero vulnerabilities is a significant strength. The static analysis also reveals good implementation of essential security features like nonce checks and output escaping. The primary concerns lie in the percentage of raw SQL queries and the limited scope of capability checks, which, despite the absence of current exploits, represent potential attack vectors that could be exploited in future versions or with more sophisticated attack methods.

Key Concerns

  • Raw SQL queries without prepared statements
  • Limited capability checks on entry points
Vulnerabilities
None known

Inventory Connector for Zoho and WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Inventory Connector for Zoho and WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
9
4 prepared
Unescaped Output
1
13 escaped
Nonce Checks
8
Capability Checks
1
File Operations
7
External Requests
3
Bundled Libraries
0

SQL Query Safety

31% prepared13 total queries

Output Escaping

93% escaped14 total outputs
Attack Surface

Inventory Connector for Zoho and WooCommerce Attack Surface

Entry Points8
Unprotected0

AJAX Handlers 8

authwp_ajax_bc_wc_generate_tokenincludes\Admin\Admin_Ajax.php:19
authwp_ajax_bc_get_log_dataincludes\Admin\Admin_Ajax.php:20
authwp_ajax_bc_get_integration_dataincludes\Admin\Admin_Ajax.php:21
authwp_ajax_bc_add_integration_dataincludes\Admin\Admin_Ajax.php:22
authwp_ajax_bc_save_integration_dataincludes\Admin\Admin_Ajax.php:23
authwp_ajax_bc_import_order_dataincludes\Admin\Admin_Ajax.php:24
authwp_ajax_bc_wc_refresh_organizationsincludes\Admin\Admin_Ajax.php:25
authwp_ajax_bc_wc_refresh_fieldsincludes\Admin\Admin_Ajax.php:26
WordPress Hooks 14
actioninitincludes\Admin\Admin_Bar.php:12
actionadmin_menuincludes\Admin\Admin_Bar.php:13
actionbc_inventory_connector_activationincludes\Core\Util\Activation.php:16
actionbc_inventory_connector_deactivationincludes\Core\Util\Deactivation.php:21
actionbc_inventory_connector_uninstallincludes\Core\Util\Uninstallation.php:40
actionwp_headincludes\Plugin.php:47
actionlogin_headincludes\Plugin.php:48
actionplugins_loadedincludes\Plugin.php:49
actionrest_api_initincludes\Plugin.php:50
actioninitincludes\Plugin.php:84
actioninitincludes\Plugin.php:87
actioninitincludes\Plugin.php:88
actionwoocommerce_loadedincludes\Plugin.php:90
actionwoocommerce_checkout_order_processedincludes\Plugin.php:91
Maintenance & Trust

Inventory Connector for Zoho and WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedApr 13, 2023
PHP min version7.4
Downloads794

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Inventory Connector for Zoho and WooCommerce Developer Profile

boostedcrm

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Inventory Connector for Zoho and WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bstd-wc-zcrm/assets/js/index.js
Script Paths
/wp-content/plugins/bstd-wc-zcrm/assets/js/index.js
Version Parameters
bstd-wc-zcrm/assets/js/index.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-tab-content
JS Globals
bc_inventory_connector
REST Endpoints
/wp-json/bcwcinventoryzoho/v1
FAQ

Frequently Asked Questions about Inventory Connector for Zoho and WooCommerce