Flamix: Bitrix24 and WooCommerce Orders integration Security & Risk Analysis

wordpress.org/plugins/flamix-bitrix24-and-woo-integrations

Bitrix24 and WordPress WooCommerce order simple and quick integration

500 active installs v6.0.1 PHP 7.4+ WP 5.0+ Updated May 18, 2025
b24bitrixbitrix24%d0%b1%d0%b8%d1%82%d1%80%d0%b8%d0%ba%d1%81%d0%b1%d0%b8%d1%82%d1%80%d0%b8%d0%ba%d1%8124
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Flamix: Bitrix24 and WooCommerce Orders integration Safe to Use in 2026?

Generally Safe

Score 100/100

Flamix: Bitrix24 and WooCommerce Orders integration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin "flamix-bitrix24-and-woo-integrations" version 6.0.1 exhibits a concerning security posture primarily due to a significant lack of authentication checks on its entry points. With two AJAX handlers and none of them secured with proper authorization, any unauthenticated user could potentially trigger these functions, leading to unauthorized actions.

While the plugin demonstrates good practices in its use of prepared statements for all SQL queries and a lack of dangerous functions or external HTTP requests, these strengths are overshadowed by the identified weaknesses. The absence of nonce checks on AJAX handlers, coupled with a lack of capability checks overall, further exacerbates the risk, making it easier for attackers to exploit the unprotected entry points. The static analysis also indicates that a notable percentage of output is not properly escaped, potentially opening the door for cross-site scripting (XSS) vulnerabilities.

The plugin's vulnerability history is clean, with no recorded CVEs. This is a positive sign, suggesting that the developers may be diligent in addressing security issues or that past versions have not been widely targeted. However, the current version's security flaws are critical enough that the lack of past vulnerabilities should not instill a false sense of security. The focus on securing the identified entry points and ensuring proper output escaping is paramount to improving its overall security.

Key Concerns

  • Unprotected AJAX handlers
  • Missing nonce checks on AJAX
  • Missing capability checks
  • Insufficient output escaping
Vulnerabilities
None known

Flamix: Bitrix24 and WooCommerce Orders integration Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Flamix: Bitrix24 and WooCommerce Orders integration Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Flamix: Bitrix24 and WooCommerce Orders integration Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
8 prepared
Unescaped Output
18
36 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared8 total queries

Output Escaping

67% escaped54 total outputs
Attack Surface
2 unprotected

Flamix: Bitrix24 and WooCommerce Orders integration Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_flamix_b24_woo_dispatch_orderflamix-bitrix24-and-woo-integrations.php:37
authwp_ajax_flamix_b24_woo_clear_queueflamix-bitrix24-and-woo-integrations.php:38
WordPress Hooks 9
actionadmin_noticesflamix-bitrix24-and-woo-integrations.php:20
actionadmin_menuflamix-bitrix24-and-woo-integrations.php:35
filterplugin_action_links_flamix-bitrix24-and-woo-integrations/flamix-bitrix24-and-woo-integrations.phpflamix-bitrix24-and-woo-integrations.php:36
actionwpflamix-bitrix24-and-woo-integrations.php:43
actionwoocommerce_new_orderflamix-bitrix24-and-woo-integrations.php:44
actionwoocommerce_payment_completeflamix-bitrix24-and-woo-integrations.php:45
actionwoocommerce_order_status_changedflamix-bitrix24-and-woo-integrations.php:46
actionwoocommerce_thankyouflamix-bitrix24-and-woo-integrations.php:47
actionadmin_initsettings\Settings.php:51
Maintenance & Trust

Flamix: Bitrix24 and WooCommerce Orders integration Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 18, 2025
PHP min version7.4
Downloads11K

Community Trust

Rating0/100
Number of ratings0
Active installs500
Developer Profile

Flamix: Bitrix24 and WooCommerce Orders integration Developer Profile

Roman Shkabko

10 plugins · 2K total installs

95
trust score
Avg Security Score
93/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Flamix: Bitrix24 and WooCommerce Orders integration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/flamix-bitrix24-and-woo-integrations/includes/js/flamix-bitrix24-woo-orders.js/wp-content/plugins/flamix-bitrix24-and-woo-integrations/assets/css/flamix-bitrix24-woo-orders.css
Version Parameters
flamix-bitrix24-and-woo-integrations/includes/js/flamix-bitrix24-woo-orders.js?ver=flamix-bitrix24-and-woo-integrations/assets/css/flamix-bitrix24-woo-orders.css?ver=

HTML / DOM Fingerprints

CSS Classes
flamix-bitrix24-woo-orders-settings-page
HTML Comments
<!-- Created By Flamix -->
Data Attributes
data-flamix-bitrix24-woo-orders
JS Globals
FlamixBitrix24WooOrders
FAQ

Frequently Asked Questions about Flamix: Bitrix24 and WooCommerce Orders integration