
Ni WooCommerce Product Enquiry Security & Risk Analysis
wordpress.org/plugins/ni-woocommerce-product-enquiryStreamline Customer Communication and Drive Sales with "Ni WooCommerce Product Enquiry" Plugin.
Is Ni WooCommerce Product Enquiry Safe to Use in 2026?
Use With Caution
Score 64/100Ni WooCommerce Product Enquiry has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "ni-woocommerce-product-enquiry" plugin v4.1.8 presents a significant security risk due to a combination of concerning static analysis findings and a history of vulnerabilities. While the plugin demonstrates good practice by using prepared statements for SQL queries and avoiding file operations or external HTTP requests, these strengths are overshadowed by critical weaknesses. The analysis reveals a small but unprotected attack surface, with two AJAX handlers lacking any authentication or capability checks. This direct access to functionality without proper authorization is a major concern. Furthermore, the taint analysis indicates two flows with unsanitized paths, suggesting potential vulnerabilities that could be exploited if user input is not properly handled. The plugin's vulnerability history, which includes one currently unpatched medium-severity CVE and a pattern of missing authorization vulnerabilities, strongly suggests that the developers have struggled with securing their code against authorization bypasses. This repeated issue, coupled with the current lack of authorization checks on entry points, indicates a systemic problem that needs immediate attention. The plugin has some good coding habits, but the identified security flaws, especially the unprotected AJAX handlers and the historical CVEs, place it in a precarious security posture.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Unpatched medium severity CVE
- Missing capability checks
- Output escaping issues (52% proper)
Ni WooCommerce Product Enquiry Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Ni WooCommerce Product Enquiry <= 4.1.8 - Missing Authorization
Ni WooCommerce Product Enquiry Release Timeline
Ni WooCommerce Product Enquiry Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Ni WooCommerce Product Enquiry Attack Surface
AJAX Handlers 2
WordPress Hooks 16
Maintenance & Trust
Ni WooCommerce Product Enquiry Maintenance & Trust
Maintenance Signals
Community Trust
Ni WooCommerce Product Enquiry Alternatives
Click to Chat – HoliThemes
click-to-chat-for-whatsapp
WhatsApp Chat🔥. Let's make your Web page visitors contact you through 'WhatsApp', 'WhatsApp Business'. Add matching Widget✅
Social Chat – Click To Chat App Button
wp-whatsapp-chat
WhatsApp Chat🔥 allows you to enhance customer engagement! Integrate "WhatsApp" or "WhatsApp Business" with a single click.
WP Chat App
wp-whatsapp
Integrate WhatsApp experience directly into your WordPress website.
OneClick Chat to Order
oneclick-whatsapp-order
Transform your WooCommerce store with seamless WhatsApp integration. Enable customers to order products instantly via WhatsApp with enhanced features.
Simple Chat Button
simple-chat-button
WhatsApp Chat Button - Display the beautiful WhatsApp Sticky Button on the WordPress frontend.
Ni WooCommerce Product Enquiry Developer Profile
26 plugins · 5K total installs
How We Detect Ni WooCommerce Product Enquiry
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
../admin/js/bootstrap.js../admin/js/popper.min.js../admin/css/bootstrap.min.css../admin/css/niwoope-style.css../js/ni-enquiry.js../js/ni-enquiry-ajax-script.js../admin/js/bootstrap.js../admin/js/popper.min.js../admin/css/bootstrap.min.css../admin/css/niwoope-style.css../js/ni-enquiry.js../js/ni-enquiry-ajax-script.jsHTML / DOM Fingerprints
niwoope-style<!-- Add Enquiry button on woocommerce product detail page -->data-plugin_name="ni-woocommerce-product-enquiry"data-version="4.1.8"ni_enquiry_ajax_object/wp-json/niwoope/v1/enquiry_form