
Pravel Rent & Sell Addon for WooCommerce Security & Risk Analysis
wordpress.org/plugins/pravel-rent-sell-addon-for-woocommercePravel Rent & Sell Addon for WooCommerce is a flexible, open-source eCommerce solution built on WordPress. Sell & Rent anything, anywhere and …
Is Pravel Rent & Sell Addon for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100Pravel Rent & Sell Addon for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pravel-rent-sell-addon-for-woocommerce" plugin, version 1.0.1, exhibits a concerning security posture primarily due to a large, unprotected attack surface. While the plugin demonstrates good practices in handling SQL queries with prepared statements and avoiding dangerous functions or file operations, the lack of authentication checks on all six identified AJAX handlers is a significant weakness. This makes these entry points highly susceptible to unauthorized access and manipulation.
The static analysis revealed no taint flows, dangerous functions, or issues with SQL queries, which are positive indicators. However, the low percentage of properly escaped output (57%) suggests a potential for cross-site scripting (XSS) vulnerabilities. The absence of nonce checks on AJAX handlers further exacerbates the risk, as it opens the door for CSRF attacks.
The plugin's vulnerability history is clean, with no recorded CVEs. While this is a positive sign, it's important to note that a lack of past vulnerabilities does not guarantee future security. The current version has several critical security weaknesses that need immediate attention, particularly the unprotected AJAX endpoints, which represent a substantial risk despite the absence of historical issues.
Key Concerns
- Unprotected AJAX handlers
- Missing nonce checks on AJAX handlers
- Insufficient output escaping
Pravel Rent & Sell Addon for WooCommerce Security Vulnerabilities
Pravel Rent & Sell Addon for WooCommerce Code Analysis
Bundled Libraries
Output Escaping
Pravel Rent & Sell Addon for WooCommerce Attack Surface
AJAX Handlers 6
WordPress Hooks 44
Maintenance & Trust
Pravel Rent & Sell Addon for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Pravel Rent & Sell Addon for WooCommerce Alternatives
TriPay Payment Gateway
tripay-payment-gateway
TriPay Payment adalah payment gateway indonesia yang menyediakan beragam metode pembayaran seperti virtual account, convenience store, e-wallet, dll
Ovic Pinmap
ovic-pinmap
Need support? [Contact Us](https://kutethemes.com/contact-us/ "Contact Us")
ShipperHQ: Shipping & Checkout Experience Solution
woo-shipperhq
Control the shipping rates and options you show in your WooCommerce cart. Live rates from 30+ carriers, LTL Freight and custom rates.
OPay Payment for WooCommerce
woo-opay-payment
歐付寶金流外掛套件,提供合作特店以及個人會員使用開放原始碼商店系統時,無須自行處理複雜的檢核,直接透過安裝設定外掛套件,便可以較快速的方式介接的金流系統。
Ninja Shop – The Quickest Way to Start Selling
ninja-shop
Ninja Shop is an easy to use eCommerce plugin, the quickest way to start selling your products with WordPress.
Pravel Rent & Sell Addon for WooCommerce Developer Profile
3 plugins · 30 total installs
How We Detect Pravel Rent & Sell Addon for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pravel-rent-sell-addon-for-woocommerce/assets/js/pravel_repeater.js/wp-content/plugins/pravel-rent-sell-addon-for-woocommerce/assets/js/main.js/wp-content/plugins/pravel-rent-sell-addon-for-woocommerce/assets/js/jquery.dataTables.js/wp-content/plugins/pravel-rent-sell-addon-for-woocommerce/assets/css/main_style.css/wp-content/plugins/pravel-rent-sell-addon-for-woocommerce/assets/css/pravel_jquery-ui.css/wp-content/plugins/pravel-rent-sell-addon-for-woocommerce/assets/css/jquery.dataTables.css/wp-content/plugins/pravel-rent-sell-addon-for-woocommerce/assets/css/style_front.css/wp-content/plugins/pravel-rent-sell-addon-for-woocommerce/assets/js/jquery_front.js/wp-content/plugins/pravel-rent-sell-addon-for-woocommerce/assets/js/pravel_repeater.js/wp-content/plugins/pravel-rent-sell-addon-for-woocommerce/assets/js/main.js/wp-content/plugins/pravel-rent-sell-addon-for-woocommerce/assets/js/jquery.dataTables.js/wp-content/plugins/pravel-rent-sell-addon-for-woocommerce/assets/js/jquery_front.jspravel-rent-sell-addon-for-woocommerce/assets/js/pravel_repeater.js?ver=pravel-rent-sell-addon-for-woocommerce/assets/js/main.js?ver=pravel-rent-sell-addon-for-woocommerce/assets/js/jquery.dataTables.js?ver=pravel-rent-sell-addon-for-woocommerce/assets/css/main_style.css?ver=pravel-rent-sell-addon-for-woocommerce/assets/css/pravel_jquery-ui.css?ver=pravel-rent-sell-addon-for-woocommerce/assets/css/jquery.dataTables.css?ver=pravel-rent-sell-addon-for-woocommerce/assets/css/style_front.css?ver=pravel-rent-sell-addon-for-woocommerce/assets/js/jquery_front.js?ver=HTML / DOM Fingerprints
pravel_parent_popuppravel_popup_bgpravel_popup_mainPravel_popup_close_btnpravel_closepravel_popup_leftpravel_popup_rightpravel_buy_logodata-product_idajax_custom<a href=