
Mysterx – Mystery Boxes for WooCommerce Security & Risk Analysis
wordpress.org/plugins/mysterx-mystery-boxes-for-woocommerceWooCommerce addon that implements custom product type "Mystery box" which enables you to offer and sell loot boxes - similar to those found …
Is Mysterx – Mystery Boxes for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Mysterx – Mystery Boxes for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "mysterx-mystery-boxes-for-woocommerce" v1.0.0 exhibits a mixed security posture. While it demonstrates good practices in critical areas like SQL query handling (100% prepared statements) and output escaping (98%), there are significant concerns regarding its attack surface and taint analysis. The presence of one unprotected AJAX handler is a primary risk, as it can be triggered without proper authentication. This is exacerbated by two taint flows identified as having unsanitized paths with high severity, indicating potential vulnerabilities that could be exploited through user-supplied input. The plugin's vulnerability history is clean, with zero known CVEs, which is a positive indicator of its past security. However, the current code analysis reveals potential weaknesses that could lead to future vulnerabilities. Overall, the plugin has strong internal code hygiene for SQL and output, but the unprotected entry point and high-severity taint flows represent immediate security risks that require attention.
Key Concerns
- Unprotected AJAX handler
- High severity unsanitized taint flow (2)
- Bundled outdated library (Freemius v1.0)
Mysterx – Mystery Boxes for WooCommerce Security Vulnerabilities
Mysterx – Mystery Boxes for WooCommerce Release Timeline
Mysterx – Mystery Boxes for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Mysterx – Mystery Boxes for WooCommerce Attack Surface
AJAX Handlers 1
WordPress Hooks 57
Maintenance & Trust
Mysterx – Mystery Boxes for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Mysterx – Mystery Boxes for WooCommerce Alternatives
MailPoet – Newsletters, Email Marketing, and Automation
mailpoet
Send beautiful newsletters from WordPress. Collect subscribers with signup forms, automate your emails for WooCommerce, blog post notifications & more
Pinterest for WooCommerce
pinterest-for-woocommerce
Get your products in front of Pinterest users searching for ideas and things to buy. Connect your WooCommerce store to make your catalog browsable.
Klaviyo
klaviyo
Klaviyo for WooCommerce
Email Marketing for WooCommerce by Omnisend
omnisend-connect
Email Marketing, Newsletter, Email Automation, Forms, Pop Up, SMS, Abandoned Cart made easy for WordPress & WooCommerce by Omnisend
MailerLite – WooCommerce integration
woo-mailerlite
Powerful e-commerce email marketing tools that are easy to use. Grow your store with automated emails, pop-ups, product blocks, sales tracking + more.
Mysterx – Mystery Boxes for WooCommerce Developer Profile
10 plugins · 3K total installs
How We Detect Mysterx – Mystery Boxes for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mysterx-mystery-boxes-for-woocommerce/admin/css/mysterx-admin.css/wp-content/plugins/mysterx-mystery-boxes-for-woocommerce/admin/js/mysterx-admin.js/wp-content/plugins/mysterx-mystery-boxes-for-woocommerce/public/css/mysterx-public.css/wp-content/plugins/mysterx-mystery-boxes-for-woocommerce/public/js/mysterx-public.js/wp-content/plugins/mysterx-mystery-boxes-for-woocommerce/vendor/freemius/freemius-sdk/start.php/wp-content/plugins/mysterx-mystery-boxes-for-woocommerce/admin/js/mysterx-admin.js/wp-content/plugins/mysterx-mystery-boxes-for-woocommerce/public/js/mysterx-public.jsmysterx-mystery-boxes-for-woocommerce/admin/css/mysterx-admin.css?ver=mysterx-mystery-boxes-for-woocommerce/admin/js/mysterx-admin.js?ver=mysterx-mystery-boxes-for-woocommerce/public/css/mysterx-public.css?ver=mysterx-mystery-boxes-for-woocommerce/public/js/mysterx-public.js?ver=HTML / DOM Fingerprints
mysterx-admin-wrapmysterx-product-wrap<!-- Start of Mysterx Mystery Boxes for WooCommerce --><!-- End of Mysterx Mystery Boxes for WooCommerce -->data-mysterx-product-idMYSTERX_ADMINmysterx_public_params/wp-json/mysterx/v1/get_products/wp-json/mysterx/v1/open_box[mysterx_box]