h-erp integration Security & Risk Analysis

wordpress.org/plugins/h-erp-integration

h-erp integration is a WooCommerce plugin developed by Hashavshevet h-erp®

0 active installs v1.3.4 PHP 5.6+ WP 4.4+ Updated Feb 8, 2026
checkoutcredit-cardpaymentsstorewoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is h-erp integration Safe to Use in 2026?

Generally Safe

Score 100/100

h-erp integration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

Based on the static analysis and vulnerability history provided, the "h-erp-integration" v1.3.4 plugin exhibits a strong security posture. The absence of any identified entry points, coupled with the fact that all identified code signals indicate secure coding practices (like 100% prepared statements for SQL and proper output escaping), suggests a well-developed and hardened plugin. The lack of any known CVEs and the absence of any recorded vulnerabilities further bolster this assessment, indicating a history of secure development or effective patching.

However, a few areas warrant attention. The plugin performs two external HTTP requests, which can be a potential attack vector if not handled securely, though the static analysis doesn't indicate any specific issues here. More importantly, the complete absence of nonce checks and capability checks across all identified code signals is a significant concern. While the current analysis shows zero unprotected entry points, this could be a reporting artifact or a sign of a very small attack surface. A lack of these fundamental security mechanisms means that even minor future additions or modifications could inadvertently introduce vulnerabilities if not carefully implemented with authentication and authorization checks.

In conclusion, the plugin demonstrates excellent current security hygiene with robust defenses against common vulnerabilities. The primary weakness lies in the apparent lack of built-in authentication and authorization checks in its codebase, which, while not showing exploitable issues currently, represents a significant latent risk for future development or under scrutiny. Continued vigilance and the implementation of these checks in future updates are recommended.

Key Concerns

  • No nonce checks present
  • No capability checks present
  • External HTTP requests without explicit checks
Vulnerabilities
None known

h-erp integration Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

h-erp integration Release Timeline

v1.3.4Current
v1.3.3
v1.3.2
v1.3.1
v1.3
v1.3.0
v1.2.1
v1.2
Code Analysis
Analyzed Apr 16, 2026

h-erp integration Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped6 total outputs
Attack Surface

h-erp integration Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
filterwoocommerce_payment_gatewayscustom-woocommerce-payment-gateway.php:22
actionplugins_loadedcustom-woocommerce-payment-gateway.php:25
actionadmin_noticescustom-woocommerce-payment-gateway.php:55
filterwoocommerce_gateway_descriptioncustom-woocommerce-payment-gateway.php:235
actionwoocommerce_checkout_create_ordercustom-woocommerce-payment-gateway.php:284
actionwp_footercustom-woocommerce-payment-gateway.php:294
Maintenance & Trust

h-erp integration Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 8, 2026
PHP min version5.6
Downloads767

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

h-erp integration Developer Profile

hashshop

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect h-erp integration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/h-erp-integration/imgs/logo_herp.png
Version Parameters
h-erp-integration/custom-woocommerce-payment-gateway.php?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- שימוש בהגדרות: ולידציה לפי מספר תשלומים מקסימלי וסכום מינימום לתשלום (רק כשמוצג שדה תשלומים) --><!-- (2 minutes) -->
Data Attributes
data-installments-countdata-min-amount-per-installment
JS Globals
window.hash_erp_config
FAQ

Frequently Asked Questions about h-erp integration