{eac}SoftwareRegistry WooCommerce Webhook Endpoints Security & Risk Analysis

wordpress.org/plugins/eacsoftwareregistry-webhook-endpoints

Enables the use of WooCommerce Webhooks to create or update a software registration in {eac}SoftwareRegistry when an order or subscription is created …

0 active installs v1.1.5 PHP 7.4+ WP 5.8+ Updated Sep 4, 2025
software-licensesoftware-registrationsoftware-registrywebhookswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is {eac}SoftwareRegistry WooCommerce Webhook Endpoints Safe to Use in 2026?

Generally Safe

Score 100/100

{eac}SoftwareRegistry WooCommerce Webhook Endpoints has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The plugin 'eacsoftwareregistry-webhook-endpoints' v1.1.5 exhibits a strong security posture based on the provided static analysis. The absence of any identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code adheres to secure coding practices by utilizing prepared statements for its single SQL query and properly escaping all output. The lack of file operations, external HTTP requests, and the absence of any identified dangerous functions or taint flows are all positive indicators of secure development.

However, the static analysis does highlight some areas that, while not directly indicating vulnerabilities in this specific version, warrant attention in a broader context. The complete absence of nonce checks and capability checks across all entry points (even though there are zero identified) suggests a potential oversight in the plugin's architecture. If future versions introduce new entry points, the lack of these fundamental WordPress security mechanisms could become a significant concern. The vulnerability history is also remarkably clean, with no recorded CVEs. While this is excellent, it's important to remember that a clean history does not guarantee future safety, especially for plugins with limited observed security testing or a small user base.

In conclusion, the current version of 'eacsoftwareregistry-webhook-endpoints' appears to be very secure, with no immediate threats detected through static analysis. Its strengths lie in its minimal attack surface and adherence to secure coding practices for its observed code. The primary weakness, though not currently exploitable due to the absence of entry points, is the potential for future vulnerabilities if nonce and capability checks are not implemented as new features are added. The excellent vulnerability history is a strong positive, but should be monitored alongside ongoing security practices.

Key Concerns

  • Lack of nonce checks
  • Lack of capability checks
Vulnerabilities
None known

{eac}SoftwareRegistry WooCommerce Webhook Endpoints Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

{eac}SoftwareRegistry WooCommerce Webhook Endpoints Release Timeline

v1.1.5Current
v1.1.4
v1.1.3
v1.1.2
v1.1.1
v1.1.0
v1.0.10
v1.0.9
v1.0.8
v1.0.7
v1.0.6
v1.0.5
v1.0.4
Code Analysis
Analyzed Apr 16, 2026

{eac}SoftwareRegistry WooCommerce Webhook Endpoints Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
0
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

100% escaped5 total outputs
Attack Surface

{eac}SoftwareRegistry WooCommerce Webhook Endpoints Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionoptions_settings_pageExtensions/class.woocommerce_webhooks.extension.php:86
actionrest_api_initExtensions/class.woocommerce_webhooks.extension.php:89
filterhttp_originExtensions/class.woocommerce_webhooks.extension.php:152
filterallowed_http_originsExtensions/class.woocommerce_webhooks.extension.php:155
filteris_registrar_optionExtensions/class.woocommerce_webhooks.extension.php:197
filtereacSoftwareRegistry_load_extensionseacSoftwareRegistry_Webhook_Endpoints.php:49
Maintenance & Trust

{eac}SoftwareRegistry WooCommerce Webhook Endpoints Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 4, 2025
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

{eac}SoftwareRegistry WooCommerce Webhook Endpoints Developer Profile

Kevin Burkholder

11 plugins · 60 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect {eac}SoftwareRegistry WooCommerce Webhook Endpoints

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/eacsoftwareregistry-webhook-endpoints/Extensions/includes/woocommerce_webhooks.options.php/wp-content/plugins/eacsoftwareregistry-webhook-endpoints/Extensions/class.woocommerce_webhooks.extension.php
Version Parameters
eacSoftwareRegistry_Webhook_Endpoints/1.1.5

HTML / DOM Fingerprints

REST Endpoints
/wp-json/eacswregistry/v1/wc-order/wp-json/eacswregistry/v1/wc-subscription
FAQ

Frequently Asked Questions about {eac}SoftwareRegistry WooCommerce Webhook Endpoints