Peki – Bokio Integration for WooCommerce Security & Risk Analysis

wordpress.org/plugins/peki-bokio-integration-for-woocommerce

Connect WooCommerce to Bokio to export orders automatically and keep ledgers, VAT, and documentation in sync.

0 active installs v1.0.2 PHP 7.4+ WP 5.8+ Updated Dec 30, 2025
accountingbokiobookkeepinginvoiceswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Peki – Bokio Integration for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Peki – Bokio Integration for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The 'peki-bokio-integration-for-woocommerce' plugin v1.0.2 exhibits a generally good security posture, with several positive indicators. The complete absence of known CVEs and a strong adherence to prepared statements for SQL queries are significant strengths. Furthermore, the plugin demonstrates a high rate of output escaping (95%) and a substantial number of nonce and capability checks, indicating a thoughtful approach to security. However, there is one notable concern: a REST API route is exposed without permission callbacks, creating an unprotected entry point into the application. While static analysis did not reveal critical taint flows or dangerous functions, this unprotected REST API endpoint warrants attention as it could potentially be exploited if sensitive actions or data are accessible through it without proper authorization checks.

The lack of any recorded vulnerabilities in its history is a very positive sign, suggesting that the developers have either not introduced significant flaws or have a history of promptly addressing them. The overall picture is one of a plugin that largely follows secure coding practices, but the single unprotected REST API route represents a specific, albeit isolated, risk that should be investigated and mitigated. The plugin's strengths in output escaping and structured data handling are commendable, making this single unprotected entry point the primary area of focus for further security hardening.

Key Concerns

  • Unprotected REST API route
Vulnerabilities
None known

Peki – Bokio Integration for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Peki – Bokio Integration for WooCommerce Release Timeline

v1.02
v1.0.1
Code Analysis
Analyzed Apr 16, 2026

Peki – Bokio Integration for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
221 escaped
Nonce Checks
7
Capability Checks
16
File Operations
0
External Requests
6
Bundled Libraries
0

Output Escaping

95% escaped233 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

4 flows
handle_callback (includes/admin/class-admin-connect.php:51)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Peki – Bokio Integration for WooCommerce Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 1

authwp_ajax_pekibokio_refresh_statusincludes/admin/class-admin-connect.php:16

REST API Routes 1

POST/wp-json/bokio/v1/pingbokio.php:140
WordPress Hooks 26
actionplugins_loadedbokio.php:87
filterallowed_redirect_hostsbokio.php:88
actionplugins_loadedbokio.php:103
actionadmin_noticesbokio.php:109
actionrest_api_initbokio.php:139
actionpekibokio_cron_refresh_statusbokio.php:238
filtercron_schedulesbokio.php:259
actionwoocommerce_order_status_completedbokio.php:270
actionwoocommerce_order_refundedbokio.php:294
filterwoocommerce_order_actionsbokio.php:319
actionwoocommerce_order_action_pekibokio_force_exportbokio.php:325
filtermanage_edit-shop_order_columnsbokio.php:416
actionmanage_shop_order_posts_custom_columnbokio.php:431
filterwoocommerce_shop_order_list_table_columnsbokio.php:446
actionwoocommerce_shop_order_list_table_custom_columnbokio.php:461
actionadmin_post_pekibokio_start_connectincludes/admin/class-admin-connect.php:13
actionadmin_post_pekibokio_callbackincludes/admin/class-admin-connect.php:14
actionadmin_post_nopriv_pekibokio_callbackincludes/admin/class-admin-connect.php:15
actionadmin_initincludes/admin/class-admin-menu.php:9
actionadmin_noticesincludes/admin/class-admin-notices.php:22
actionnetwork_admin_noticesincludes/admin/class-admin-notices.php:23
actionadmin_menuincludes/admin/class-admin.php:34
actionadmin_enqueue_scriptsincludes/admin/class-admin.php:35
actionadmin_headincludes/admin/class-admin.php:36
actionadmin_initincludes/admin/class-admin.php:39
actionadmin_post_pekibokio_toggle_auto_upgradeincludes/admin/class-admin.php:42

Scheduled Events 1

pekibokio_cron_refresh_status
Maintenance & Trust

Peki – Bokio Integration for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 30, 2025
PHP min version7.4
Downloads203

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Peki – Bokio Integration for WooCommerce Developer Profile

PEKI AS

4 plugins · 30 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Peki – Bokio Integration for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/peki-bokio-integration-for-woocommerce/assets/css/admin.css/wp-content/plugins/peki-bokio-integration-for-woocommerce/assets/css/admin.css.map/wp-content/plugins/peki-bokio-integration-for-woocommerce/assets/js/admin.js/wp-content/plugins/peki-bokio-integration-for-woocommerce/assets/js/admin.js.map
Script Paths
/wp-content/plugins/peki-bokio-integration-for-woocommerce/assets/js/admin.js
Version Parameters
peki-bokio-integration-for-woocommerce/assets/css/admin.css?ver=peki-bokio-integration-for-woocommerce/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
pekibokio-admin-page
HTML Comments
<!-- Bokio Bilag integration --><!-- ev. testmiljø --><!-- Bokio Bilag integration --><!-- Start main admin (menus, pages, assets, etc.) -->+6 more
Data Attributes
data-pekibokio-version
JS Globals
pekibokio
REST Endpoints
/bokio/v1/ping
FAQ

Frequently Asked Questions about Peki – Bokio Integration for WooCommerce