
Bulgarisation for WooCommerce Security & Risk Analysis
wordpress.org/plugins/bulgarisation-for-woocommerceВсичко необходимо за вашият онлайн магазин за България. Включва облекчен режим за Наредба - H-18 и методи за доставка с Еконт, CVC и Спиди.
Is Bulgarisation for WooCommerce Safe to Use in 2026?
Generally Safe
Score 98/100Bulgarisation for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The 'bulgarisation-for-woocommerce' plugin exhibits a mixed security posture. While it demonstrates good practices in areas like SQL query sanitization and output escaping, it suffers from a significant and concerning lack of authorization checks on its AJAX handlers. The presence of 40 AJAX endpoints, all without authentication checks, represents a substantial attack surface that could be exploited by unauthenticated users to trigger potentially harmful actions. The taint analysis also indicates a concern with unsanitized paths, though no critical or high severity issues were identified in this specific run. The vulnerability history shows two past high-severity vulnerabilities, both related to missing authorization, which reinforces the current findings and suggests a recurring pattern of security oversight in how user input and actions are handled. While the plugin's use of prepared statements and mostly proper output escaping are positive signs, the critical flaw in AJAX endpoint security, coupled with past authorization issues, presents a notable risk that requires immediate attention.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Past high-severity vulnerabilities (Missing Authorization)
- Bundled libraries (dompdf, TCPDF)
Bulgarisation for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Bulgarisation for WooCommerce <= 3.0.14 - Cross-Site Request Forgery
Bulgarisation for WooCommerce <= 3.0.14 - Missing Authorization
Bulgarisation for WooCommerce Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Data Flow Analysis
Bulgarisation for WooCommerce Attack Surface
AJAX Handlers 40
WordPress Hooks 160
Scheduled Events 5
Maintenance & Trust
Bulgarisation for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Bulgarisation for WooCommerce Alternatives
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels
print-invoices-packing-slip-labels-for-woocommerce
Auto-generate and attach WooCommerce PDF invoices and packing slips to order emails with customizable templates & bulk print options.
The Courier Guy Shipping for WooCommerce
the-courier-guy
This is the official WooCommerce extension to ship products using The Courier Guy.
Spocket ‑ US & EU Dropshipping
spocket
Find fast shipping products from reliable suppliers, import them to your WooCommerce store and manage your orders automatically: all for free.
Biteship Shipping
biteship-shipping
Plugin pengiriman WooCommerce dengan berbagai ekspedisi untuk pengiriman Reguler, Instan, dan Kargo.
FlagShip WooCommerce Shipping
flagship-woocommerce-shipping
FlagShip WooCommerce Shipping is an e-shipping courier solution that helps you shipping anything from Canada. Beautifully.
Bulgarisation for WooCommerce Developer Profile
1 plugin · 5K total installs
How We Detect Bulgarisation for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bulgarisation-for-woocommerce/assets/css/boxnow-admin.css/wp-content/plugins/bulgarisation-for-woocommerce/assets/js/boxnow-admin.js/wp-content/plugins/bulgarisation-for-woocommerce/assets/css/speedy-admin.css/wp-content/plugins/bulgarisation-for-woocommerce/assets/js/speedy-admin.js/wp-content/plugins/bulgarisation-for-woocommerce/assets/css/cvc-admin.css/wp-content/plugins/bulgarisation-for-woocommerce/assets/js/cvc-admin.js/wp-content/plugins/bulgarisation-for-woocommerce/assets/css/econt-admin.css/wp-content/plugins/bulgarisation-for-woocommerce/assets/js/econt-admin.js/wp-content/plugins/bulgarisation-for-woocommerce/assets/js/boxnow-admin.js/wp-content/plugins/bulgarisation-for-woocommerce/assets/js/speedy-admin.js/wp-content/plugins/bulgarisation-for-woocommerce/assets/js/cvc-admin.js/wp-content/plugins/bulgarisation-for-woocommerce/assets/js/econt-admin.jsbulgarisation-for-woocommerce/assets/css/boxnow-admin.css?ver=bulgarisation-for-woocommerce/assets/js/boxnow-admin.js?ver=bulgarisation-for-woocommerce/assets/css/speedy-admin.css?ver=bulgarisation-for-woocommerce/assets/js/speedy-admin.js?ver=bulgarisation-for-woocommerce/assets/css/cvc-admin.css?ver=bulgarisation-for-woocommerce/assets/js/cvc-admin.js?ver=bulgarisation-for-woocommerce/assets/css/econt-admin.css?ver=bulgarisation-for-woocommerce/assets/js/econt-admin.js?ver=HTML / DOM Fingerprints
woo-bg--boxnow-adminwoo-bg--speedy-adminwoo-bg--cvc-adminwoo-bg--econt-admindata-vue-app="boxnow-admin"data-vue-app="speedy-admin"data-vue-app="cvc-admin"data-vue-app="econt-admin"wooBg_boxnowwooBg_speedywooBg_cvcwooBg_econt