
Bzhy – Feature Enhancements for WooCommerce Security & Risk Analysis
wordpress.org/plugins/bzhy-feature-enhancements-for-woocommerceBzhy is a WordPress plugin for enhancing WooCommerce features.This plugin is under continuous modular development.
Is Bzhy – Feature Enhancements for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Bzhy – Feature Enhancements for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "bzhy-feature-enhancements-for-woocommerce" v1.2.2 exhibits a generally strong security posture due to its adherence to several best practices. Notably, all identified SQL queries utilize prepared statements, and a significant majority of output operations are properly escaped. The plugin also demonstrates a good awareness of WordPress security by implementing nonce and capability checks on many of its entry points, and its vulnerability history is clean, with no recorded CVEs. This suggests a proactive approach to security by the developers.
However, the static analysis reveals a concerning pattern in the taint analysis. A significant number of flows (24 out of 38) were found with unsanitized paths, and critically, all of these are flagged as high severity. While the static analysis itself did not uncover exploitable vulnerabilities, these unsanitized path flows represent potential entry points for attackers if user-supplied data is not handled with extreme care before being used in file operations or other sensitive contexts. The presence of 8 file operations without further context on their sanitization or authorization is also a point of attention, especially in conjunction with the taint analysis results.
In conclusion, while the plugin's foundational security practices like prepared SQL statements and robust output escaping are commendable, the high number of high-severity unsanitized path flows in the taint analysis is a significant weakness that requires immediate investigation and remediation. The absence of a known vulnerability history is positive, but it does not negate the potential risks highlighted by the taint analysis. Addressing these unsanitized paths is crucial to ensure the plugin's overall security.
Key Concerns
- High severity unsanitized path flows
- 24/38 taint flows have unsanitized paths
- 8 file operations
Bzhy – Feature Enhancements for WooCommerce Security Vulnerabilities
Bzhy – Feature Enhancements for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Bzhy – Feature Enhancements for WooCommerce Attack Surface
AJAX Handlers 4
REST API Routes 2
Shortcodes 4
WordPress Hooks 88
Maintenance & Trust
Bzhy – Feature Enhancements for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Bzhy – Feature Enhancements for WooCommerce Alternatives
No alternatives data available yet.
Bzhy – Feature Enhancements for WooCommerce Developer Profile
1 plugin · 0 total installs
How We Detect Bzhy – Feature Enhancements for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bzhy-feature-enhancements-for-woocommerce/public/js/bzhy_admin.js/wp-content/plugins/bzhy-feature-enhancements-for-woocommerce/public/css/bzhy_admin.csswp-content/plugins/bzhy-feature-enhancements-for-woocommerce/public/js/bzhy_admin.jsbzhy_admin.js?ver=bzhy_admin.css?ver=HTML / DOM Fingerprints
bzhy_admin_activebzhy_admin_disactivedata-bzhy-typebzhy_admin