
CURBON Security & Risk Analysis
wordpress.org/plugins/curbonCURBON lets your customers decrease the carbon impact of their purchases on your online store
Is CURBON Safe to Use in 2026?
Generally Safe
Score 85/100CURBON has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "curbon" v1.0.0 plugin exhibits a generally good security posture based on the static analysis. The plugin demonstrates strong adherence to secure coding practices by utilizing prepared statements for a significant majority of its SQL queries and properly escaping nearly all its output. The absence of known vulnerabilities, both historically and currently, is a positive indicator. Furthermore, the limited attack surface, with only one shortcode and no identified AJAX handlers or REST API routes that lack authentication checks, suggests a thoughtful approach to development.
Despite these strengths, there are areas that warrant attention. The presence of four taint flows with unsanitized paths, even without critical or high severity, indicates a potential for unintended data handling that could be exploited under specific circumstances. While the plugin has no recorded CVEs, the extensive number of external HTTP requests (88) is a notable concern, as each request represents a potential avenue for third-party vulnerabilities or data exposure. The lack of capability checks also means that the plugin's functionality might be accessible to users who shouldn't have access, depending on how its shortcode is implemented and what actions it performs.
Key Concerns
- Taint flows with unsanitized paths
- No capability checks
- Large number of external HTTP requests
CURBON Security Vulnerabilities
CURBON Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
CURBON Attack Surface
Shortcodes 1
WordPress Hooks 35
Maintenance & Trust
CURBON Maintenance & Trust
Maintenance Signals
Community Trust
CURBON Alternatives
Carbon Balance: Carbon calculation and offsetting for WooCommerce
carbonbalance-for-woocommerce
Empower your customers to make their order more climate Friendly
ClimateClick: Climate Action for all
co2ok-for-woocommerce
Empower your customers to make their order climate neutral
CURBON Developer Profile
1 plugin · 0 total installs
How We Detect CURBON
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/curbon/assets/css/jquery-ui.css/wp-content/plugins/curbon/assets/css/curbon-admin-style.css/wp-content/plugins/curbon/assets/js/curbon-admin-script.js/wp-content/plugins/curbon/assets/js/curbon-admin-script.jscurbon-admin-stylecurbon-admin-scriptcurbon-jquery-uiHTML / DOM Fingerprints
toplevel_page_curbon-dashboardcurbonAdminObj