
BusinessOnBot Security & Risk Analysis
wordpress.org/plugins/businessonbotBoosts D2C brands via WhatsApp & Instagram, maximizing user acquisition & growth through platform potential.
Is BusinessOnBot Safe to Use in 2026?
Generally Safe
Score 100/100BusinessOnBot has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "businessonbot" plugin v1.0.3 exhibits a mixed security posture. On one hand, it demonstrates strong practices in critical areas like SQL query sanitization and output escaping, with 97% of SQL queries using prepared statements and 100% of outputs properly escaped. The absence of known CVEs and its clean vulnerability history are also positive indicators, suggesting a generally well-maintained codebase.
However, significant concerns arise from the static analysis. The plugin exposes 2 AJAX handlers without any authentication checks, creating a clear attack vector. Furthermore, taint analysis reveals 3 high-severity flows with unsanitized paths. While the specific impact of these unsanitized paths isn't detailed, they represent potential vulnerabilities that could be exploited if they lead to sensitive operations or data leakage.
In conclusion, while the plugin benefits from a lack of historical vulnerabilities and robust data handling for SQL and output, the presence of unprotected AJAX endpoints and high-severity unsanitized paths in the taint analysis are notable weaknesses. Addressing these specific findings is crucial to improving the plugin's overall security.
Key Concerns
- AJAX handlers without auth checks
- High severity taint flows with unsanitized paths
BusinessOnBot Security Vulnerabilities
BusinessOnBot Release Timeline
BusinessOnBot Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
BusinessOnBot Attack Surface
AJAX Handlers 2
REST API Routes 6
WordPress Hooks 40
Maintenance & Trust
BusinessOnBot Maintenance & Trust
Maintenance Signals
Community Trust
BusinessOnBot Alternatives
Order & Abandoned Cart Notifications for WooCommerce
order-notifications-for-woocommerce
Send WhatsApp notifications for WooCommerce orders, order status updates and abandoned cart recovery using the official WhatsApp Business API.
Hello24 – Order on Chat, Abandoned cart recovery & Marketing Automation
hello24-order-on-chat-abandoned-cart-recovery-marketing-automation
Gain 5X more revenue by Abandoned cart recovery, Add Chat Button, Marketing automation, Resell/Upsell/Cross-sell using Whatsapp API
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools
woocommerce-jetpack
Supercharge WooCommerce with FREE Abandoned Cart Recovery, Product Variation Swatches, PDF Invoices & 100+ tools. Boost sales & save time.
ShopMagic – email automation
shopmagic-for-woocommerce
Flexible email automation and workflows triggered by customer and site events.
CartBounty – Save and recover abandoned carts for WooCommerce
woo-save-abandoned-carts
Save abandoned carts and send automated abandoned cart recovery messages. Get more leads, reduce cart abandonment, and increase sales.
BusinessOnBot Developer Profile
1 plugin · 10 total installs
How We Detect BusinessOnBot
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/businessonbot/assets/css/businessonbot.css/wp-content/plugins/businessonbot/assets/js/businessonbot.js/wp-content/plugins/businessonbot/assets/js/businessonbot.jsbusinessonbot/assets/css/businessonbot.css?ver=businessonbot/assets/js/businessonbot.js?ver=HTML / DOM Fingerprints
businessonbot_save_guest_ab_cart