e-Boekhouden.nl Security & Risk Analysis

wordpress.org/plugins/e-boekhoudennl-connector

A plugin which exports orders to e-Boekhouden.nl

100 active installs v1.9.3 PHP + WP 4.0+ Updated Sep 6, 2016
administratieboekhoudene-boekhouden-nleboekhoudenonline-boekhouden
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEAug 21, 2025
Safety Verdict

Is e-Boekhouden.nl Safe to Use in 2026?

Use With Caution

Score 63/100

e-Boekhouden.nl has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Aug 21, 2025Updated 9yr ago
Risk Assessment

The e-boekhoudennl-connector v1.9.3 plugin presents a mixed security posture. On one hand, it demonstrates good practices by having a limited attack surface with no apparent unprotected entry points like AJAX handlers, REST API routes, or shortcodes. Furthermore, it avoids dangerous functions and external HTTP requests. However, significant concerns arise from its handling of SQL queries, with 100% of them not using prepared statements, indicating a high risk of SQL injection vulnerabilities. The low percentage of properly escaped output (26%) also points to potential Cross-Site Scripting (XSS) vulnerabilities.

The vulnerability history reveals a concerning pattern, with one medium severity CVE historically and currently unpatched. The common vulnerability type being Cross-Site Scripting further corroborates the risks identified in the code analysis. The presence of an unpatched vulnerability, even if medium severity, poses an immediate risk to users of this plugin.

In conclusion, while the plugin has strengths in limiting its attack surface and avoiding certain risky coding patterns, the prevalent use of raw SQL queries and the documented unpatched XSS vulnerability create substantial security risks. The 100% unsanitized taint flows with unsanitized paths are particularly alarming, suggesting that user-supplied data is not being properly handled, potentially leading to various injection attacks.

Key Concerns

  • Unpatched CVE (medium severity)
  • SQL queries without prepared statements
  • Low percentage of properly escaped output
  • Flows with unsanitized paths
  • File operations detected
  • External HTTP requests detected
  • No nonce checks
Vulnerabilities
1

e-Boekhouden.nl Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-53225medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

e-Boekhouden.nl <= 1.9.3 - Reflected Cross-Site Scripting

Aug 21, 2025Unpatched
Version History

e-Boekhouden.nl Release Timeline

v1.031 CVE
v1.021 CVE
v1.011 CVE
v1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

e-Boekhouden.nl Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
17
6 escaped
Nonce Checks
0
Capability Checks
1
File Operations
1
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

26% escaped23 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
ebh_export_orders (eboekhouden.php:227)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

e-Boekhouden.nl Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_menueboekhouden-settings.php:18
actionadmin_initeboekhouden-settings.php:19
actioniniteboekhouden.php:7
actioniniteboekhouden.php:61
actionadmin_initeboekhouden.php:62
actionadmin_menueboekhouden.php:63
actioniniteboekhouden.php:66
actionadmin_action_ebhassignlargenumbereboekhouden.php:73
actionadmin_headincludes\lists\eboekhouden-order-list-table.php:41
actionadmin_headincludes\lists\eboekhouden-product-list-table.php:47
Maintenance & Trust

e-Boekhouden.nl Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedSep 6, 2016
PHP min version
Downloads6K

Community Trust

Rating26/100
Number of ratings6
Active installs100
Developer Profile

e-Boekhouden.nl Developer Profile

eboekhouden

1 plugin · 100 total installs

68
trust score
Avg Security Score
63/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect e-Boekhouden.nl

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/e-boekhoudennl-connector/css/e-boekhouden-admin.css/wp-content/plugins/e-boekhoudennl-connector/js/e-boekhouden-admin.js
Script Paths
/wp-content/plugins/e-boekhoudennl-connector/js/e-boekhouden-admin.js
Version Parameters
e-boekhoudennl-connector/css/e-boekhouden-admin.css?ver=e-boekhoudennl-connector/js/e-boekhouden-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wrape-Boekhouden.nl
HTML Comments
<!-- RBS FIX-->
Data Attributes
data-pagedata-id
JS Globals
window.location
FAQ

Frequently Asked Questions about e-Boekhouden.nl