BusinessOnBot Security & Risk Analysis

wordpress.org/plugins/businessonbot

Boosts D2C brands via WhatsApp & Instagram, maximizing user acquisition & growth through platform potential.

10 active installs v1.0.3 PHP 7.4+ WP 6.2+ Updated Dec 3, 2025
abandoned-cartwhatsapp-apiwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BusinessOnBot Safe to Use in 2026?

Generally Safe

Score 100/100

BusinessOnBot has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "businessonbot" plugin v1.0.3 exhibits a mixed security posture. On one hand, it demonstrates strong practices in critical areas like SQL query sanitization and output escaping, with 97% of SQL queries using prepared statements and 100% of outputs properly escaped. The absence of known CVEs and its clean vulnerability history are also positive indicators, suggesting a generally well-maintained codebase.

However, significant concerns arise from the static analysis. The plugin exposes 2 AJAX handlers without any authentication checks, creating a clear attack vector. Furthermore, taint analysis reveals 3 high-severity flows with unsanitized paths. While the specific impact of these unsanitized paths isn't detailed, they represent potential vulnerabilities that could be exploited if they lead to sensitive operations or data leakage.

In conclusion, while the plugin benefits from a lack of historical vulnerabilities and robust data handling for SQL and output, the presence of unprotected AJAX endpoints and high-severity unsanitized paths in the taint analysis are notable weaknesses. Addressing these specific findings is crucial to improving the plugin's overall security.

Key Concerns

  • AJAX handlers without auth checks
  • High severity taint flows with unsanitized paths
Vulnerabilities
None known

BusinessOnBot Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

BusinessOnBot Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
96 prepared
Unescaped Output
0
19 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

97% prepared99 total queries

Output Escaping

100% escaped19 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
load_checkout_from_link (businessonbot.php:329)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

BusinessOnBot Attack Surface

Entry Points8
Unprotected2

AJAX Handlers 2

noprivwp_ajax_businessonbot_save_guest_ab_cartbusinessonbot.php:135
noprivwp_ajax_businessonbot_gdpr_refusedbusinessonbot.php:139

REST API Routes 6

GET/wp-json/wc-bob/v1/add-scriptbusinessonbot.php:495
GET/wp-json/wc-bob/v1/del-scriptbusinessonbot.php:504
GET/wp-json/wc-bob/v1/list-scriptbusinessonbot.php:513
GET/wp-json/wc-bob/v1/manage-configbusinessonbot.php:522
GET/wp-json/wc-bob/v1/create-checkoutbusinessonbot.php:531
GET/wp-json/wc-bob/v1/list-checkout/(?P<checkouthash>[a-zA-Z0-9-]+)businessonbot.php:540
WordPress Hooks 40
actionadmin_noticesbusinessonbot.php:56
actionplugins_loadedbusinessonbot.php:59
actioninitbusinessonbot.php:62
actionbefore_woocommerce_initbusinessonbot.php:65
actionplugins_loadedbusinessonbot.php:72
actioninitbusinessonbot.php:94
actionadmin_menubusinessonbot.php:97
actionadmin_initbusinessonbot.php:114
actionwoocommerce_add_to_cartbusinessonbot.php:117
actionwoocommerce_cart_item_removedbusinessonbot.php:118
actionwoocommerce_cart_item_restoredbusinessonbot.php:119
actionwoocommerce_after_cart_item_quantity_updatebusinessonbot.php:120
actionwoocommerce_calculate_totalsbusinessonbot.php:121
filtertemplate_includebusinessonbot.php:124
actionwoocommerce_after_checkout_billing_formbusinessonbot.php:130
actioninitbusinessonbot.php:131
filterwoocommerce_checkout_fieldsbusinessonbot.php:140
actionwoocommerce_coupon_errorbusinessonbot.php:142
actionwoocommerce_applied_couponbusinessonbot.php:143
actionwoocommerce_before_cart_tablebusinessonbot.php:145
actionwoocommerce_before_checkout_formbusinessonbot.php:147
actionwp_headbusinessonbot.php:150
actionrest_api_initbusinessonbot.php:153
actiontemplate_redirectbusinessonbot.php:156
actionwoocommerce_after_single_productbusinessonbot.php:159
filterwoocommerce_order_details_after_order_tablebusinessonbot.php:162
actionwoocommerce_order_status_changedbusinessonbot.php:163
actionwoocommerce_checkout_order_processedbusinessonbot.php:164
filterwoocommerce_payment_complete_order_statusbusinessonbot.php:165
filterwoocommerce_webhook_topicsbusinessonbot.php:168
filterwoocommerce_webhook_topic_hooksbusinessonbot.php:169
filterwoocommerce_valid_webhook_resourcesbusinessonbot.php:170
filterwoocommerce_valid_webhook_eventsbusinessonbot.php:171
filterwoocommerce_webhook_payloadbusinessonbot.php:172
filterwoocommerce_webhook_deliver_asyncbusinessonbot.php:173
actionbusinessonbot_cart_recoveredbusinessonbot.php:176
actionbusinessonbot_webhook_after_abancartbusinessonbot.php:177
actionbusinessonbot_abandoned_productsbusinessonbot.php:178
actionwp_loginbusinessonbot.php:181
filterwoocommerce_login_redirectbusinessonbot.php:182
Maintenance & Trust

BusinessOnBot Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 3, 2025
PHP min version7.4
Downloads723

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

BusinessOnBot Developer Profile

BusinessOnBot

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BusinessOnBot

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/businessonbot/assets/css/businessonbot.css/wp-content/plugins/businessonbot/assets/js/businessonbot.js
Script Paths
/wp-content/plugins/businessonbot/assets/js/businessonbot.js
Version Parameters
businessonbot/assets/css/businessonbot.css?ver=businessonbot/assets/js/businessonbot.js?ver=

HTML / DOM Fingerprints

JS Globals
businessonbot_save_guest_ab_cart
FAQ

Frequently Asked Questions about BusinessOnBot