Nimbbl Security & Risk Analysis

wordpress.org/plugins/nimbbl-for-woocommerce

Welcome to the official Nimbbl WooCommerce plugin, support auto-fill address. Get higher conversions with multiple payment gateways, COD, UPI, BNPL an …

20 active installs v5.0.4 PHP 7.0+ WP 5.6+ Updated Feb 19, 2026
ecommerce-payment-gatewaynimbblpayment-gatewaypaymentswoocommerce-payment-gateway
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Nimbbl Safe to Use in 2026?

Generally Safe

Score 100/100

Nimbbl has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "nimbbl-for-woocommerce" plugin v5.0.4 demonstrates some good security practices, such as the absence of dangerous functions and the exclusive use of prepared statements for SQL queries. The code also shows a high percentage of properly escaped output and no recorded vulnerabilities in its history, suggesting a generally well-maintained codebase. However, there are significant areas of concern regarding its attack surface and authorization checks.

The plugin exposes a total of 6 entry points, with a worrying 4 of these being AJAX handlers that lack authentication checks. This means that unauthorized users could potentially trigger these AJAX actions, leading to unintended consequences or exploitation if the actions themselves are not adequately protected. While taint analysis revealed no critical or high-severity flows, the lack of authorization on multiple AJAX endpoints is a substantial risk that could be exploited in conjunction with other vulnerabilities or logic flaws.

Despite the positive indicators like no known CVEs and secure SQL handling, the unprotected AJAX handlers represent a tangible security gap. The absence of capability checks and nonces on these specific entry points elevates the risk. A balanced conclusion is that while the plugin avoids common pitfalls like raw SQL or dangerous functions, its exposed, unauthenticated AJAX endpoints are a significant weakness that requires immediate attention to mitigate potential security breaches.

Key Concerns

  • AJAX handlers without auth checks
  • REST API routes without permission callbacks
  • No capability checks found
Vulnerabilities
None known

Nimbbl Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Nimbbl Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
61 escaped
Nonce Checks
4
Capability Checks
0
File Operations
5
External Requests
0
Bundled Libraries
0

Output Escaping

85% escaped72 total outputs
Attack Surface
4 unprotected

Nimbbl Attack Surface

Entry Points6
Unprotected4

AJAX Handlers 4

authwp_ajax_nimbbl_verify_paymentincludes\wc-nimbbl-payment-gateway.php:74
noprivwp_ajax_nimbbl_verify_paymentincludes\wc-nimbbl-payment-gateway.php:75
authwp_ajax_nimbbl_get_checkout_tokenincludes\wc-nimbbl-payment-gateway.php:76
noprivwp_ajax_nimbbl_get_checkout_tokenincludes\wc-nimbbl-payment-gateway.php:77

REST API Routes 2

POST/wp-json/nimbbl/v1/checkout-tokennimbbl-woocommerce.php:46
POST/wp-json/nimbbl/v1/verify-paymentnimbbl-woocommerce.php:54
WordPress Hooks 20
actionwoocommerce_after_add_to_cart_buttonincludes\wc-nimbbl-payment-gateway.php:51
actiontemplate_redirectincludes\wc-nimbbl-payment-gateway.php:52
actionwoocommerce_proceed_to_checkoutincludes\wc-nimbbl-payment-gateway.php:59
filterwoocommerce_get_checkout_urlincludes\wc-nimbbl-payment-gateway.php:61
filterwoocommerce_store_api_checkout_urlincludes\wc-nimbbl-payment-gateway.php:62
filterwoocommerce_add_to_cart_redirectincludes\wc-nimbbl-payment-gateway.php:63
filterpre_option_woocommerce_cart_redirect_after_addincludes\wc-nimbbl-payment-gateway.php:64
actionwoocommerce_api_nimbbl_process_callbackincludes\wc-nimbbl-payment-gateway.php:72
actionwoocommerce_api_nimbblcallbackincludes\wc-nimbbl-payment-gateway.php:73
actionwoocommerce_order_details_after_order_tableincludes\wc-nimbbl-payment-gateway.php:78
actionwoocommerce_admin_order_data_after_shipping_addressincludes\wc-nimbbl-payment-gateway.php:79
actiontemplate_redirectincludes\wc-nimbbl-payment-gateway.php:80
actionwp_enqueue_scriptsincludes\wc-nimbbl-payment-gateway.php:81
actionwp_enqueue_scriptsincludes\wc-nimbbl-payment-gateway.php:82
actionplugins_loadednimbbl-woocommerce.php:30
filterwoocommerce_payment_gatewaysnimbbl-woocommerce.php:31
actionrest_api_initnimbbl-woocommerce.php:32
actiontemplate_redirectnimbbl-woocommerce.php:33
actionwoocommerce_blocks_loadednimbbl-woocommerce.php:36
actionwoocommerce_blocks_payment_method_type_registrationnimbbl-woocommerce.php:166
Maintenance & Trust

Nimbbl Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedFeb 19, 2026
PHP min version7.0
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Nimbbl Developer Profile

Nimbbl

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Nimbbl

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nimbbl-for-woocommerce/assets/images/nimbbl.png/wp-content/plugins/nimbbl-for-woocommerce/assets/js/nimbbl-checkout-redirect.js/wp-content/plugins/nimbbl-for-woocommerce/assets/css/nimbbl-checkout-redirect.css
Script Paths
/wp-content/plugins/nimbbl-for-woocommerce/includes/blocks/wc-nimbbl-payment-gateway-blocks.php
Version Parameters
nimbbl-for-woocommerce/nimbbl-woocommerce.php

HTML / DOM Fingerprints

Data Attributes
data-nimbbl-payment-token
JS Globals
nimbbl_checkout_redirect_paramsNimbblCheckout
REST Endpoints
/wp-json/nimbbl/v1/checkout-token/wp-json/nimbbl/v1/verify-payment
FAQ

Frequently Asked Questions about Nimbbl