
ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support Security & Risk Analysis
wordpress.org/plugins/erpManage your business with a complete ERP system featuring powerful HR management, CRM tools, accounting, and seamless WooCommerce CRM integration.
Is ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support Safe to Use in 2026?
Generally Safe
Score 88/100ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support has a strong security track record. Known vulnerabilities have been patched promptly.
The ERP plugin v1.17.2 presents a mixed security posture. While it demonstrates a strong adherence to good security practices, with a high percentage of SQL queries using prepared statements and properly escaped output, several areas raise significant concerns. The presence of two AJAX handlers without authentication checks creates a notable attack vector, potentially allowing unauthorized actions. Furthermore, the taint analysis indicates a high number of flows with unsanitized paths, including ten flows classified as high severity, suggesting potential vulnerabilities that could lead to data exposure or manipulation. The plugin's historical vulnerability record is also a major concern, with a substantial number of known CVEs, predominantly of high and medium severity. The recurring types of vulnerabilities, such as exposure of sensitive information, authorization bypasses, and cross-site scripting, point to systemic issues in input validation and authorization enforcement. While the plugin has a robust history of patching vulnerabilities (zero currently unpatched), the sheer volume and recurring nature of past security flaws, combined with the static analysis findings, necessitate caution. The plugin's strengths lie in its output sanitization and prepared statement usage, but these are overshadowed by the risks posed by unprotected entry points, high-severity taint flows, and a history of diverse and serious vulnerabilities.
Key Concerns
- AJAX handlers without auth checks
- High severity taint flows with unsanitized paths
- Total known CVEs (20)
- High severity known CVEs (7)
- Medium severity known CVEs (13)
- Dangerous function used (unserialize)
- Flows with unsanitized paths (27)
- Bundled library (Select2)
- Bundled library (Guzzle v1.1)
ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support Security Vulnerabilities
CVEs by Year
Severity Breakdown
20 total CVEs
ERP <= 1.16.7 - Missing Authorization
ERP <= 1.16.6 - Authenticated (Subscriber+) Information Exposure
WP ERP <= 1.13.4 - Missing Authorization
WP ERP <= 1.13.3 - Authenticated (Admin+) Stored Cross-Site Scripting
WP ERP <= 1.13.3 - Authenticated (Employee+) Insecure Direct Object Reference
WP ERP <= 1.13.2 - Reflected Cross-Site Scripting
WP ERP <= 1.13.0 - Authenticated (Accounting Manager+) SQL Injection via vendor_id
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.13.1 - Authenticated (AccountingManager+) SQL Injection
WP ERP <= 1.13.0 - Authenticated (Accounting Manager+) SQL Injection
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.13.1 - Authenticated (Subscriber+) SQL Injection
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.13.1 - Unauthenticated Stored Cross-Site Scripting
WP ERP <= 1.13.0 - Authenticated (AccountingManager+) SQL Injection
WP ERP <= 1.12.9 - Authenticated (Accounting Manager+) SQL Injection via id
WP ERP <= 1.12.8 - Authenticated (Accounting manager+) SQL Injection
WP ERP <= 1.12.6 - Missing Authorization via admin notice dismissal
WP ERP <= 1.12.3 - Authenticated (Administrator+) SQL Injection via 'type'
WP ERP <= 1.12.3 - Reflected Cross-Site Scripting
WP ERP <= 1.12.3 - Reflected Cross-Site Scripting
WP ERP <=1.10.5 - Sensitive Data Exposure
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.6.3 - Cross-Site Request Forgery Bypass
ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support Attack Surface
AJAX Handlers 11
Shortcodes 1
WordPress Hooks 188
Scheduled Events 8
Maintenance & Trust
ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support Maintenance & Trust
Maintenance Signals
Community Trust
ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support Alternatives
Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation
zero-bs-crm
The CRM for small businesses. Manage leads, invoicing, billing, email marketing, clients, contacts, quotes, automation. Works with WooCommerce too.
Ever Accounting – Accounting & Invoicing Solution for Small Businesses
wp-ever-accounting
Efficiently manage your payments and expenses, and send professional invoices in multiple currencies with ease using Ever Accounting.
Fluent Connect – Connect ThriveCart with your WordPress and FluentCRM
fluent-connect
Connect ThriveCart shop with your WordPress and FluentCRM
WP-HR Manager: The Human Resources Plugin for WordPress
wp-hr-manager
Easily add a powerful HR / human resource management system and employee self service (ESS) portal to your website. = Credits = This plugin uses [WP E …
Integration with HubSpot for WooCommerce
hubwoo-integration
A very powerful plugin to integrate your WooCommerce store with HubSpot seemlesly.
ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support Developer Profile
20 plugins · 113K total installs
How We Detect ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/erp/assets/css/erp-frontend.css/wp-content/plugins/erp/assets/js/erp-frontend.js/wp-content/plugins/erp/assets/css/erp-global.css/wp-content/plugins/erp/assets/css/erp-admin.css/wp-content/plugins/erp/assets/js/erp-admin.js/wp-content/plugins/erp/modules/crm/assets/css/crm.css/wp-content/plugins/erp/modules/crm/assets/js/crm.js/wp-content/plugins/erp/modules/accounting/assets/css/accounting.css+3 moreerp/wp-content/plugins/erp/assets/js/erp-frontend.js/wp-content/plugins/erp/assets/js/erp-admin.js/wp-content/plugins/erp/modules/crm/assets/js/crm.js/wp-content/plugins/erp/modules/accounting/assets/js/accounting.js/wp-content/plugins/erp/modules/hr/assets/js/hr.jserp/assets/css/erp-frontend.css?ver=erp/assets/js/erp-frontend.js?ver=erp/assets/css/erp-global.css?ver=erp/assets/css/erp-admin.css?ver=erp/assets/js/erp-admin.js?ver=erp/modules/crm/assets/css/crm.css?ver=erp/modules/crm/assets/js/crm.js?ver=erp/modules/accounting/assets/css/accounting.css?ver=erp/modules/accounting/assets/js/accounting.js?ver=erp/modules/hr/assets/css/hr.css?ver=erp/modules/hr/assets/js/hr.js?ver=HTML / DOM Fingerprints
erp-dashboard-widgeterp-company-profileerp-quick-access-menuerp-datatableerp-modalerp-tab-naverp-form-fielderp-chart+15 more<!-- ERP Core Scripts --><!-- ERP Global Styles --><!-- ERP Admin Styles --><!-- CRM Styles -->+7 moredata-erp-user-iddata-erp-roledata-erp-moduledata-erp-actiondata-erp-noncedata-erp-view+2 moreERPAdminERPCoreERPFrontenderp_varserp_admin_paramserp_frontend_params+3 more/wp-json/erp/v1/settings/wp-json/erp/v1/company/wp-json/erp/v1/users/wp-json/erp/v1/crm/contacts/wp-json/erp/v1/crm/companies/wp-json/erp/v1/crm/deals/wp-json/erp/v1/accounting/journals/wp-json/erp/v1/accounting/chart/wp-json/erp/v1/hr/employees/wp-json/erp/v1/hr/departments/wp-json/erp/v1/hr/designations/wp-json/erp/v1/hr/leave[erp_dashboard][erp_my_tasks][erp_my_leaves][erp_my_attendance]