
MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics Security & Risk Analysis
wordpress.org/plugins/makewebbetter-hubspot-for-woocommerceIntegrate WooCommerce with HubSpot’s free CRM, abandoned cart tracking, email marketing, marketing automation, analytics & more.
Is MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics Safe to Use in 2026?
Generally Safe
Score 98/100MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "makewebbetter-hubspot-for-woocommerce" plugin v1.6.6 exhibits a mixed security posture. While it demonstrates good practices in many areas, such as a high percentage of properly escaped outputs and a significant use of prepared statements for SQL queries, there are notable areas of concern. The presence of 42 AJAX handlers, with 6 lacking authentication checks, presents a significant attack surface that could be exploited by unauthenticated users. The static analysis also identified the dangerous `unserialize` function, which, if not handled with extreme caution and validation, can lead to deserialization vulnerabilities. Despite a recent high-severity vulnerability in its history, it is currently patched, which is a positive sign. However, the pattern of having a high-severity vulnerability and the identified unprotected entry points suggest a potential for recurring security issues if development practices do not consistently incorporate robust authorization and input sanitization. Overall, the plugin has strengths in code hygiene but requires attention to its authentication mechanisms for AJAX endpoints and careful handling of potentially dangerous functions.
Key Concerns
- 6 unprotected AJAX handlers
- Use of unserialize function
- 1 High severity historical vulnerability
MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics <= 1.5.9 - Missing Authorization to Authenticated (Contributor+) Arbitrary Options Update
MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics Release Timeline
MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics Attack Surface
AJAX Handlers 42
WordPress Hooks 83
Maintenance & Trust
MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics Maintenance & Trust
Maintenance Signals
Community Trust
MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics Alternatives
Zoho Campaigns
zoho-campaigns
Zoho Campaigns
Constant Contact + WooCommerce
constant-contact-woocommerce
Add products to your list emails and sync your contacts.
Benchmark Email for WooCommerce
woo-benchmark-email
Connects WooCommerce with Benchmark Email - syncing customers and abandoned carts.
Auto Mail – Abandoned Cart Recovery, Newsletter Builder & Marketing Automation for WooCommerce
auto-mail
Auto Mail is an WordPress email plugin that make you can manage your customer relationships, build your email lists, send email campaigns, build funne …
MandrakeCRM – CRM & AI Marketing Automation
mandrakecrm
CRM, automations, campaigns & analytics for WooCommerce. Charges per order, not per contact. Unlimited contacts. Free 7-day trial.
MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics Developer Profile
5 plugins · 7K total installs
How We Detect MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/makewebbetter-hubspot-for-woocommerce/admin/css/bootstrap.min.css/wp-content/plugins/makewebbetter-hubspot-for-woocommerce/admin/css/bootstrap.min.css.map/wp-content/plugins/makewebbetter-hubspot-for-woocommerce/admin/css/datepicker.css/wp-content/plugins/makewebbetter-hubspot-for-woocommerce/admin/css/font-awesome.min.css/wp-content/plugins/makewebbetter-hubspot-for-woocommerce/admin/css/hover-min.css/wp-content/plugins/makewebbetter-hubspot-for-woocommerce/admin/css/jQuery.css/wp-content/plugins/makewebbetter-hubspot-for-woocommerce/admin/css/main.css/wp-content/plugins/makewebbetter-hubspot-for-woocommerce/admin/css/owl.carousel.min.css+24 more/wp-content/plugins/makewebbetter-hubspot-for-woocommerce/admin/js/bootstrap.min.js/wp-content/plugins/makewebbetter-hubspot-for-woocommerce/admin/js/bootstrap-datepicker.js/wp-content/plugins/makewebbetter-hubspot-for-woocommerce/admin/js/common.js/wp-content/plugins/makewebbetter-hubspot-for-woocommerce/admin/js/custom.js/wp-content/plugins/makewebbetter-hubspot-for-woocommerce/admin/js/jquery.datetimepicker.full.min.js/wp-content/plugins/makewebbetter-hubspot-for-woocommerce/admin/js/jquery.js+11 moremakewebbetter-hubspot-for-woocommerce/assets/css/dashboard.css?ver=makewebbetter-hubspot-for-woocommerce/assets/css/frontend.css?ver=makewebbetter-hubspot-for-woocommerce/assets/css/style.css?ver=makewebbetter-hubspot-for-woocommerce/assets/js/dashboard.js?ver=makewebbetter-hubspot-for-woocommerce/assets/js/frontend.js?ver=makewebbetter-hubspot-for-woocommerce/assets/js/script.js?ver=makewebbetter-hubspot-for-woocommerce/assets/js/woo-hubspot-common.js?ver=makewebbetter-hubspot-for-woocommerce/admin/css/style.css?ver=makewebbetter-hubspot-for-woocommerce/admin/js/script.js?ver=HTML / DOM Fingerprints
hubwoo-admin-layouthubwoo-main-bodyhubwoo-section-titlehubwoo-rowhubwoo-colhubwoo-form-grouphubwoo-form-labelhubwoo-form-control+63 more<!-- If this file is called directly, abort. --><!-- Checking if WooCommerce is activeand other woocommerce integration versions. --><!-- The code that runs during plugin activation. -->+9 moredata-hubwoo-client-iddata-hubwoo-secret-iddata-hubwoo-plugin-versionHUBWOO_PRO_CONSTANTSHubwoo_CommonHubwoo_DashboardHubwoo_FrontendHubwoo_Scripts