Crawlaco | کرالاکو Security & Risk Analysis

wordpress.org/plugins/crawlaco

Connect your WordPress/WooCommerce site to Crawlaco dashboard for seamless product and inventory management.

0 active installs v1.2.5 PHP 7.4+ WP 5.0+ Updated Unknown
crawlacoecommerceproduct-management%da%a9%d8%b1%d8%a7%d9%84%d8%a7%da%a9%d9%88woocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Crawlaco | کرالاکو Safe to Use in 2026?

Generally Safe

Score 100/100

Crawlaco | کرالاکو has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "crawlaco" v1.2.5 plugin exhibits a strong security posture with a clean vulnerability history and a well-protected attack surface. The static analysis reveals robust security practices, including the absence of dangerous functions and a significant percentage of SQL queries using prepared statements. Furthermore, a high proportion of output is properly escaped, and the presence of numerous nonce and capability checks on entry points indicates a good understanding of WordPress security principles. The taint analysis did not reveal any critical or high-severity vulnerabilities, suggesting that data is generally handled safely.

Key Concerns

  • Flows with unsanitized paths found
  • SQL queries not using prepared statements (33% of total)
  • Output not properly escaped (15% of total)
Vulnerabilities
None known

Crawlaco | کرالاکو Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Crawlaco | کرالاکو Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
2 prepared
Unescaped Output
17
96 escaped
Nonce Checks
12
Capability Checks
16
File Operations
2
External Requests
9
Bundled Libraries
0

SQL Query Safety

67% prepared3 total queries

Output Escaping

85% escaped113 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
ajax_check_task_status (includes\class-crawlaco-api.php:243)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Crawlaco | کرالاکو Attack Surface

Entry Points11
Unprotected0

AJAX Handlers 9

authwp_ajax_crawlaco_update_settingsincludes\class-crawlaco-admin.php:23
authwp_ajax_crawlaco_deactivateincludes\class-crawlaco-admin.php:24
authwp_ajax_generate_api_keysincludes\class-crawlaco-api-keys.php:10
authwp_ajax_generate_wc_api_keysincludes\class-crawlaco-api-keys.php:11
authwp_ajax_validate_website_keyincludes\class-crawlaco-api.php:19
authwp_ajax_initiate_data_fetchincludes\class-crawlaco-api.php:20
authwp_ajax_check_task_statusincludes\class-crawlaco-api.php:21
authwp_ajax_save_attribute_mappingincludes\class-crawlaco-api.php:22
authwp_ajax_finalize_setupincludes\class-crawlaco-api.php:23

REST API Routes 2

POST/wp-json/custom-rankmath/v1/add-redirectcustom-functions.php:182
POST/wp-json/crawlaco/v1/validate-keyincludes\class-crawlaco-api.php:30
WordPress Hooks 20
actionadmin_enqueue_scriptsadmin\pages\status.php:20
actioninitcrawlaco.php:146
actionplugins_loadedcrawlaco.php:150
actioncrawlaco_admin_noticescrawlaco.php:180
actionadmin_initcrawlaco.php:182
actionwoocommerce_product_after_variable_attributescustom-functions.php:44
actionwoocommerce_product_after_variable_attributescustom-functions.php:62
actionwoocommerce_save_product_variationcustom-functions.php:101
actionwoocommerce_product_options_general_product_datacustom-functions.php:146
actionwoocommerce_process_product_metacustom-functions.php:177
actionrest_api_initcustom-functions.php:181
actioninitcustom-functions.php:321
actionrest_insert_postcustom-functions.php:326
actionrest_insert_productcustom-functions.php:358
actionadmin_menuincludes\class-crawlaco-admin.php:11
actionadmin_initincludes\class-crawlaco-admin.php:14
actionadmin_enqueue_scriptsincludes\class-crawlaco-admin.php:17
actionadmin_enqueue_scriptsincludes\class-crawlaco-admin.php:20
actionrest_api_initincludes\class-crawlaco-api.php:16
actionadmin_post_crawlaco_update_settingsincludes\class-settings-handler.php:17
Maintenance & Trust

Crawlaco | کرالاکو Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.4
Downloads596

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Crawlaco | کرالاکو Developer Profile

Crawlaco team

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Crawlaco | کرالاکو

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/crawlaco/admin/css/admin.css
Version Parameters
crawlaco/admin/css/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
crawlaco-headercrawlaco-admincrawlaco-admin-noticecrawlaco-dashboard-overviewcrawlaco-completion-sectioncrawlaco-completion-actions
FAQ

Frequently Asked Questions about Crawlaco | کرالاکو