Eber Security & Risk Analysis

wordpress.org/plugins/eber

Eber is a smart member system comes with comprehensive loyalty & rewards system, marketing and analytic tool.

20 active installs v4.8 PHP + WP 4.2+ Updated Sep 10, 2025
businessloyaltymember-cardmembershipreward
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Eber Safe to Use in 2026?

Generally Safe

Score 100/100

Eber has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The "eber" plugin v4.8 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and having no recorded vulnerability history. The absence of bundled libraries and external HTTP requests also reduces potential attack vectors. However, a significant concern arises from its attack surface, specifically the presence of four unprotected AJAX handlers. This means that any unauthenticated user could potentially interact with these endpoints, opening them up to various attacks if the handler logic is vulnerable.

While the static analysis did not reveal critical taint flows or raw SQL queries, the high percentage of improperly escaped output (44%) is a notable weakness. This could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is rendered directly without proper sanitization. The plugin's reliance on nonce checks and capability checks is positive, but these are not applied to all entry points. The vulnerability history being clean is a good indicator, but it does not negate the risks identified in the static analysis, particularly the unprotected AJAX endpoints and output escaping issues.

In conclusion, "eber" v4.8 has strengths in its SQL handling and lack of historical vulnerabilities. However, the significant number of unprotected AJAX endpoints and the high rate of unescaped output represent substantial security risks that require immediate attention. Addressing these specific areas would greatly improve the plugin's overall security.

Key Concerns

  • Unprotected AJAX handlers present
  • Significant portion of output not properly escaped
Vulnerabilities
None known

Eber Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Eber Release Timeline

v4.6
v4.4
v4.3
v4.1
v3.9
v3.8
v3.7
v3.6
v3.5
v3.4
v3.2
v3.1
v3.0
v2.9
v2.8
v2.7
v2.6
v2.5
v2.4
v2.3
Code Analysis
Analyzed Apr 16, 2026

Eber Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
26
33 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

56% escaped59 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
SettingsPage (init/menu.php:53)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Eber Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

authwp_ajax_eber_initindex.php:29
authwp_ajax_eber_apiindex.php:30
noprivwp_ajax_eber_initindex.php:32
noprivwp_ajax_eber_apiindex.php:33
WordPress Hooks 12
actionwp_enqueue_scriptsindex.php:28
actionadmin_menuindex.php:39
actionedit_user_profileindex.php:40
actionedit_user_profile_updateindex.php:41
actionwoocommerce_order_status_completedindex.php:50
actionwoocommerce_thankyouindex.php:54
actionwoocommerce_order_status_changedindex.php:55
actionwoocommerce_order_actionsindex.php:58
actionwoocommerce_order_action_ns_eber_sendindex.php:59
actionplugins_loadedindex.php:63
actionuser_registration_after_user_meta_updateindex.php:65
actionprofile_updateindex.php:69
Maintenance & Trust

Eber Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedSep 10, 2025
PHP min version
Downloads12K

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

Eber Developer Profile

eberwp

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Eber

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/eber/eber-frontend.css/wp-content/plugins/eber/eber-frontend.js
Script Paths
//widget.eber.co/new-widget/initialize/
Version Parameters
eber/style.css?ver=eber/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
eber-modaleber-widget-content
Data Attributes
data-eber-widget-iddata-eber-tracking
JS Globals
eberWidgeteberConfig
REST Endpoints
/wp-json/eber/v1/data/wp-json/eber/v1/settings
Shortcode Output
[eber_rewards_points][eber_loyalty_level]
FAQ

Frequently Asked Questions about Eber