
Holnix Security & Risk Analysis
wordpress.org/plugins/holnixHolnix permite a las librerías importar catálogos editoriales (metadata ONIX) directamente a WooCommerce.
Is Holnix Safe to Use in 2026?
Generally Safe
Score 100/100Holnix has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The holnix plugin v1.1.3 exhibits a generally strong security posture, with several positive indicators such as 100% of SQL queries using prepared statements and 97% of output being properly escaped. The limited attack surface, with all entry points having checks, and the absence of any known historical vulnerabilities are significant strengths. However, the presence of two 'unserialize' calls is a notable concern. Unserialization of untrusted data can lead to Remote Code Execution vulnerabilities if not handled with extreme care. While taint analysis did not report critical or high-severity unsanitized flows involving these, the inherent risk remains. The plugin also lacks explicit capability checks, which, combined with the 'unserialize' calls, could pose a risk if the AJAX handlers are not sufficiently protected by other means (e.g., actions that don't require elevated privileges).
Despite the 'unserialize' concern and the absence of explicit capability checks, the overall security profile appears robust due to good practices in SQL and output handling, and a clean vulnerability history. The plugin demonstrates an awareness of common web vulnerabilities. The key area for improvement would be to review and potentially refactor the use of 'unserialize' to ensure it's never exposed to untrusted user input. The lack of recorded vulnerabilities is a strong positive signal, suggesting responsible development and a good understanding of security principles.
Key Concerns
- Dangerous function call: unserialize
- Missing capability checks on entry points
Holnix Security Vulnerabilities
Holnix Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Holnix Attack Surface
AJAX Handlers 3
WordPress Hooks 11
Maintenance & Trust
Holnix Maintenance & Trust
Maintenance Signals
Community Trust
Holnix Alternatives
JSM Show Order Metadata for WooCommerce HPOS
jsm-show-order-meta
Show WooCommerce order metadata in a metabox when editing HPOS orders - a great tool for debugging issues with HPOS order metadata.
Kotobee Integration
kotobee
Control access to your Kotobee cloud ebooks and libraries using other plugins such as WooCommerce, WooCommerce Subscriptions, and Memberful.
BookPod Author Tools
bookpod-author-tools
Connect your WooCommerce store to BookPod for automated book printing and fulfillment.
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
Holnix Developer Profile
1 plugin · 10 total installs
How We Detect Holnix
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/holnix/admin/css/holnix-admin.css/wp-content/plugins/holnix/admin/js/holnix-admin.jsholnix/style.css?ver=holnix-admin-styleholnix-admin-scriptHTML / DOM Fingerprints
holnix_options_groupnotice-successnotice-errorid="holnix-modal"id="holnix-bg-modal"id="holnix-open-modal"id="holnix-close-modal"id="holnix-submit-modal"holnixModalholnixBgModalopenModalBtncloseModalBtn/wp-json/holnix/v1/data<span id="holnix-open-modal" class="button">Actualizar</span><div id="holnix-modal"><div id="holnix-bg-modal" style=""></div>