Buyience NovaCore B2B Quote Engine Security & Risk Analysis

wordpress.org/plugins/buyience-novacore-b2b-quote-engine

Add B2B quote requests and buyer workflows to WooCommerce with optional hosted quoting features.

0 active installs v1.2.5 PHP 7.4+ WP 5.8+ Updated Feb 23, 2026
b2bquoterequest-a-quoterfqwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Buyience NovaCore B2B Quote Engine Safe to Use in 2026?

Generally Safe

Score 100/100

Buyience NovaCore B2B Quote Engine has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The plugin 'buyience-novacore-b2b-quote-engine' v1.2.5 exhibits a strong security posture based on the provided static analysis and vulnerability history. The code analysis reveals no dangerous functions, all SQL queries are properly prepared, and output escaping is consistently applied. Furthermore, there are no identified taint flows with unsanitized paths or critical/high severity issues, indicating careful development practices. The plugin also demonstrates good security hygiene by including nonce and capability checks for its entry points, and all AJAX handlers and REST API routes appear to have permission callbacks. Its vulnerability history is completely clean, with zero recorded CVEs of any severity, suggesting a history of secure development and maintenance.

Vulnerabilities
None known

Buyience NovaCore B2B Quote Engine Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Buyience NovaCore B2B Quote Engine Release Timeline

v1.2.5Current
Code Analysis
Analyzed Apr 16, 2026

Buyience NovaCore B2B Quote Engine Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
0
340 escaped
Nonce Checks
7
Capability Checks
15
File Operations
0
External Requests
3
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

100% escaped340 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

3 flows
ajax_save_subdomain (includes/class-buyncbqe2-admin.php:335)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Buyience NovaCore B2B Quote Engine Attack Surface

Entry Points14
Unprotected0

AJAX Handlers 6

authwp_ajax_buyncbqe2_clear_cacheincludes/class-buyncbqe2-admin.php:22
authwp_ajax_buyncbqe2_save_developer_modeincludes/class-buyncbqe2-admin.php:23
authwp_ajax_buyncbqe2_save_subdomainincludes/class-buyncbqe2-admin.php:24
authwp_ajax_buyncbqe2_get_migration_logsincludes/class-buyncbqe2-admin.php:25
authwp_ajax_buyncbqe2_toggle_schedulerincludes/class-buyncbqe2-admin.php:26
authwp_ajax_buyncbqe2_migrate_productsincludes/class-buyncbqe2-migration.php:18

REST API Routes 6

POST/wp-json/buyience-novacore-b2b-quote-engine/v1/authorization/refreshincludes/class-buyncbqe2-authorization.php:76
POST/wp-json/buyience-novacore-b2b-quote-engine/v1/authorization/validateincludes/class-buyncbqe2-authorization.php:84
POST/wp-json/buyience-novacore-b2b-quote-engine/v1/settings/subdomainincludes/class-buyncbqe2-authorization.php:90
POST/wp-json/buyience-novacore-b2b-quote-engine/v1/authorization/buyience-disconnectincludes/class-buyncbqe2-authorization.php:97
POST/wp-json/buyience-novacore-b2b-quote-engine/v1/authorization/buyience-authorizeincludes/class-buyncbqe2-authorization.php:103
POST/wp-json/buyience-novacore-b2b-quote-engine/v1/authorization/save-authorizationincludes/class-buyncbqe2-authorization.php:110

Shortcodes 2

[buyncbqe2_quote_builder] buyience-novacore-b2b-quote-engine.php:134
[buyncbqe2_dashboard_button] buyience-novacore-b2b-quote-engine.php:168
WordPress Hooks 19
actioninitbuyience-novacore-b2b-quote-engine.php:191
actionrest_api_initbuyience-novacore-b2b-quote-engine.php:196
actionadmin_initbuyience-novacore-b2b-quote-engine.php:232
actionadmin_menuincludes/class-buyncbqe2-admin.php:18
actionadmin_initincludes/class-buyncbqe2-admin.php:19
actionadmin_enqueue_scriptsincludes/class-buyncbqe2-admin.php:20
filteradmin_body_classincludes/class-buyncbqe2-admin.php:21
filterwp_nav_menu_itemsincludes/class-buyncbqe2-navbar.php:42
actionadmin_initincludes/class-buyncbqe2-scheduler.php:28
actionupdate_optionincludes/class-buyncbqe2-settings.php:251
actionupdate_option_buyncbqe2_subdomainincludes/class-buyncbqe2-settings.php:254
filterpre_update_option_buyncbqe2_buyience_api_urlincludes/class-buyncbqe2-settings.php:257
filterpre_update_option_buyncbqe2_woo_api_urlincludes/class-buyncbqe2-settings.php:260
actionwp_enqueue_scriptsincludes/class-buyncbqe2-woocommerce.php:22
actionwoocommerce_single_product_summaryincludes/class-buyncbqe2-woocommerce.php:23
actionwoocommerce_after_add_to_cart_buttonincludes/class-buyncbqe2-woocommerce.php:24
actionwoocommerce_after_shop_loop_itemincludes/class-buyncbqe2-woocommerce.php:25
filterwoocommerce_is_purchasableincludes/class-buyncbqe2-woocommerce.php:26
filterwoocommerce_get_price_htmlincludes/class-buyncbqe2-woocommerce.php:27
Maintenance & Trust

Buyience NovaCore B2B Quote Engine Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 23, 2026
PHP min version7.4
Downloads167

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Buyience NovaCore B2B Quote Engine Developer Profile

girishklaathar

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Buyience NovaCore B2B Quote Engine

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/buyience-novacore-b2b-quote-engine/assets/css/shortcode-link-card.css/wp-content/plugins/buyience-novacore-b2b-quote-engine/assets/css/dashboard-button.css
Version Parameters
buyience-novacore-b2b-quote-engine/assets/css/shortcode-link-card.css?ver=buyience-novacore-b2b-quote-engine/assets/css/dashboard-button.css?ver=

HTML / DOM Fingerprints

CSS Classes
buyncbqe2-shortcode-link-cardbuyncbqe2-shortcode-link-card-titlebuyncbqe2-shortcode-link-card-descriptionbuyncbqe2-shortcode-link-card-buttonbuyncbqe2-dashboard-buttonbuyncbqe2-dashboard-link
Data Attributes
buyncbqe2_quote_builderbuyncbqe2_dashboard_button
REST Endpoints
/wp-json/buyience-novacore-b2b-quote-engine/v1/
Shortcode Output
<div class="buyncbqe2-shortcode-link-card"><h3 class="buyncbqe2-shortcode-link-card-title">B2B Quote Builder</h3><p class="buyncbqe2-shortcode-link-card-description">Click below to open the B2B Quote Builder in a new tab.</p><a href="" target="_blank" rel="noopener noreferrer" class="buyncbqe2-shortcode-link-card-button" aria-label="Opens in a new tab">Open B2B Quote Builder</a></div><a href="" target="_blank" rel="noopener noreferrer" class="buyncbqe2-dashboard-button buyncbqe2-dashboard-link
FAQ

Frequently Asked Questions about Buyience NovaCore B2B Quote Engine