Doliconnect Security & Risk Analysis
wordpress.org/plugins/doliconnectThis plugin will interface your Dolibarr within a customer interface in WordPress
Is Doliconnect Safe to Use in 2026?
Generally Safe
Score 98/100Doliconnect has a strong security track record. Known vulnerabilities have been patched promptly.
The doliconnect plugin v10.0.33 presents a mixed security posture. While it shows strengths in output escaping (86%) and a substantial number of nonce and capability checks (42 and 10 respectively), significant concerns arise from its attack surface and handling of potentially dangerous functions. The presence of 23 AJAX handlers, with two lacking authentication checks, creates a direct entry point for unauthenticated actions, which is a notable risk. Furthermore, the use of the `unserialize` function is a critical red flag, as it can lead to Remote Code Execution if processing untrusted input. Taint analysis, while reporting no critical or high severity flows, did indicate a high number of flows with unsanitized paths (43 out of 45), suggesting a potential for vulnerabilities that might not have been fully captured by this specific analysis or require further manual inspection.
The vulnerability history shows two past medium-severity CVEs, both related to Cross-Site Request Forgery and Cross-site Scripting. The fact that these are unpatched in the past but currently have 0 unpatched CVEs is a positive sign. However, the pattern of CSRF and XSS vulnerabilities suggests that input sanitization and CSRF protection might be areas requiring ongoing attention. The plugin's strengths lie in its proper output escaping and use of security checks. The weaknesses are primarily the unprotected AJAX endpoints and the dangerous use of `unserialize`, coupled with the high rate of unsanitized taint flows.
Key Concerns
- Unprotected AJAX handlers detected
- Use of dangerous unserialize function
- High percentage of unsanitized taint flows
- SQL queries with low prepared statement usage
- Past medium vulnerabilities (CSRF, XSS)
Doliconnect Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Doliconnect <= 9.5.7 - Cross-Site Request Forgery
Doliconnect <= 9.3.2 - Reflected Cross-Site Scripting
Doliconnect Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Doliconnect Attack Surface
AJAX Handlers 23
WordPress Hooks 119
Scheduled Events 2
Maintenance & Trust
Doliconnect Maintenance & Trust
Maintenance Signals
Community Trust
Doliconnect Alternatives
SureContact – Newsletters, Email Marketing, Automation, Revenue Tracking & CRM
surecontact
Send newsletters, set up email automations, manage contacts and track ecommerce revenue in a CRM for WordPress.
Cloodo WP Workplace – CRM & Project Management for Services Business
cloodo-worksuite
Turn your WordPress site into a complete Digital Workplace — manage CRM, ERP, Projects, Helpdesk, Services, and Client Portal in one connected system …
Splash Sync
splash-connector
Splash Sync, the synchronization system of innovative companies! Synchronize your website with all your business applications.
Unify
unify
A CRM payment plugin which enables connectivity with Sticky.io (Formally Limelight)/Konnektive CRM and many more.
CRM ERP Business Solution | freelancers & SME | for WordPress & WooCommerce
crm-erp-business-solution
CRM ERP BUSINESS SOLUTION for WordPress and WooCommerce for freelancers and SME to Import your Transactions, Products, Customers, Vendors, Appointment …
Doliconnect Developer Profile
1 plugin · 60 total installs
How We Detect Doliconnect
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/doliconnect/assets/css/animate.min.css/wp-content/plugins/doliconnect/assets/css/bootstrap-icons.css/wp-content/plugins/doliconnect/assets/css/doliconnect.css/wp-content/plugins/doliconnect/assets/css/fontawsome.css/wp-content/plugins/doliconnect/assets/css/owl.carousel.min.css/wp-content/plugins/doliconnect/assets/css/responsive.css/wp-content/plugins/doliconnect/assets/css/slick.css/wp-content/plugins/doliconnect/assets/css/style.css+5 more/wp-content/plugins/doliconnect/assets/js/main.js/wp-content/plugins/doliconnect/assets/js/script.js/wp-content/plugins/doliconnect/assets/css/doliconnect.css?ver=/wp-content/plugins/doliconnect/assets/css/style.css?ver=/wp-content/plugins/doliconnect/assets/js/main.js?ver=/wp-content/plugins/doliconnect/assets/js/script.js?ver=HTML / DOM Fingerprints
doliconnectdoliconnect-productsdoliconnect-products-griddoliconnect-carddoliconnect-btn-outline-darkdoliconnect-btn-lg<!-- START DOLI CONNECT WIDGET --><!-- END DOLI CONNECT WIDGET --><!-- START DOLI CONNECT PRODUCTS WIDGET --><!-- END DOLI CONNECT PRODUCTS WIDGET -->+10 moredata-doli-iddata-doli-qtydata-doli-pricedata-doli-linkdoliconnect_ajax_object/wp-json/doliconnect/v1/products/wp-json/doliconnect/v1/product//wp-json/doliconnect/v1/agendaevents[doliconnect_products[doliconnect_products_grid[doliconnect_product_detail[doliconnect_calendar