
MyWorks Sync for WooCommerce & Xero Security & Risk Analysis
wordpress.org/plugins/myworks-sync-for-xeroAutomatically sync your customers, orders, inventory and more in real time between your WooCommerce store and Xero - managed directly inside WooCommer …
Is MyWorks Sync for WooCommerce & Xero Safe to Use in 2026?
Generally Safe
Score 100/100MyWorks Sync for WooCommerce & Xero has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "myworks-sync-for-xero" plugin version 1.3.2 exhibits a concerning security posture primarily due to its extensive attack surface exposed through AJAX handlers. With 21 AJAX handlers and none of them protected by authentication checks, any unauthenticated user could potentially trigger these functions, leading to serious security implications. While the plugin shows good practices in its use of prepared statements for SQL queries and output escaping, the lack of authorization on its AJAX endpoints significantly outweighs these strengths. The absence of any recorded vulnerability history is positive, suggesting a potentially diligent development team or good fortune, but it does not negate the immediate risks posed by the current code. The presence of the `unserialize` function is also a point of concern, as it can be a vector for deserialization vulnerabilities if not handled with extreme care, especially when processing user-supplied data.
Key Concerns
- 21 unprotected AJAX handlers
- Use of unserialize function
MyWorks Sync for WooCommerce & Xero Security Vulnerabilities
MyWorks Sync for WooCommerce & Xero Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
MyWorks Sync for WooCommerce & Xero Attack Surface
AJAX Handlers 21
WordPress Hooks 33
Maintenance & Trust
MyWorks Sync for WooCommerce & Xero Maintenance & Trust
Maintenance Signals
Community Trust
MyWorks Sync for WooCommerce & Xero Alternatives
Sync orders with Xero from WooCommerce – Xelation
xelation
Automatically sync your WooCommerce orders with Xero along with payments, contacts & inventory.
Parex Bridge for Quickbooks & Xero
parex-bridge-for-quickbooks-xero
Parex Bridge for QuickBooks & Xero Plugin allows you to quickly integrate WooCommerce Order information with QuickBooks Online or Xero
Data Sync for Xero by Wbsync
data-sync-x-by-wbsync
Automatically sync your data, like orders and inventory, from WooCommerce to Xero.
Vibe BuddyPress WooCommerce
vibe-buddypress-woocommerce
Vibe BuddyPress WooCommerce helps users to Sync the Buddypress Profile Fields with Woocommerce billing and shipping fields.
HarmonyUser Sync – Sync Users & Customers Across Multiple Sites
wowown-harmony-user-sync
Effortlessly synchronize WordPress users and WooCommerce customers across multiple websites securely and reliably.
MyWorks Sync for WooCommerce & Xero Developer Profile
3 plugins · 6K total installs
How We Detect MyWorks Sync for WooCommerce & Xero
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/myworks-sync-for-xero/admin/css/bootstrap.min.css/wp-content/plugins/myworks-sync-for-xero/admin/css/connection-page.css/wp-content/plugins/myworks-sync-for-xero/admin/css/select2.min.css/wp-content/plugins/myworks-sync-for-xero/admin/css/bootstrap-switch.css/wp-content/plugins/myworks-sync-for-xero/admin/css/toggle-switch.css/wp-content/plugins/myworks-sync-for-xero/admin/css/wc-widget-css.css/wp-content/plugins/myworks-sync-for-xero/admin/css/myworks-sync-for-xero-admin.cssmyworks-sync-for-xero/css/wc-widget-css.css?ver=myworks-sync-for-xero/css/myworks-sync-for-xero-admin.css?ver=myworks-sync-for-xero/css/bootstrap.min.css?ver=myworks-sync-for-xero/css/connection-page.css?ver=myworks-sync-for-xero/css/select2.min.css?ver=myworks-sync-for-xero/css/bootstrap-switch.css?ver=myworks-sync-for-xero/css/toggle-switch.css?ver=HTML / DOM Fingerprints
myworks-sync-for-xero-admin<!-- HPOS compatibility declare -->data-plugin-name="myworks-sync-for-xero"data-plugin-version="1.3.2"MWXS_LMWXS_A