Storelly ERP – B2B Inventory & Multi-Location POS for WooCommerce Security & Risk Analysis

wordpress.org/plugins/storelly-erp-b2b-inventory-multi-location-pos-for-woocommerce

Connect WooCommerce to Storelly ERP to sync products, inventory, categories, and orders across your business locations.

0 active installs v1.0.1 PHP 7.4+ WP 5.8+ Updated Mar 24, 2026
b2berpinventorystorellywoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Storelly ERP – B2B Inventory & Multi-Location POS for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Storelly ERP – B2B Inventory & Multi-Location POS for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

This plugin exhibits a concerning security posture due to a significant number of unprotected AJAX handlers, which represent a substantial attack surface. While the static analysis indicates good practices in other areas, such as the absence of dangerous functions, the prevalent use of prepared statements for SQL queries, and high output escaping, the unprotected AJAX endpoints overshadow these strengths. The lack of nonce checks and capability checks on a majority of its entry points means that any authenticated user could potentially trigger these AJAX actions, leading to unintended consequences or exploitation if vulnerabilities exist within the handler logic. The absence of known CVEs and a clean vulnerability history is positive, suggesting a generally secure development approach for past issues. However, the identified attack surface without proper authentication is a critical oversight that requires immediate attention. Overall, while the plugin demonstrates good coding practices in many aspects, the unprotected AJAX handlers introduce a significant and unmitigated risk.

Key Concerns

  • Unprotected AJAX handlers
  • Large attack surface without auth
Vulnerabilities
None known

Storelly ERP – B2B Inventory & Multi-Location POS for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Storelly ERP – B2B Inventory & Multi-Location POS for WooCommerce Release Timeline

v1.0.1Current
Code Analysis
Analyzed Apr 16, 2026

Storelly ERP – B2B Inventory & Multi-Location POS for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
127 escaped
Nonce Checks
10
Capability Checks
12
File Operations
2
External Requests
2
Bundled Libraries
0

Output Escaping

99% escaped128 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

4 flows
ajax_save_location (includes/class-setup-wizard.php:95)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
9 unprotected

Storelly ERP – B2B Inventory & Multi-Location POS for WooCommerce Attack Surface

Entry Points9
Unprotected9

AJAX Handlers 9

authwp_ajax_storelly_manual_sync_productsincludes/class-storelly-erp.php:44
authwp_ajax_storelly_manual_sync_ordersincludes/class-storelly-erp.php:45
authwp_ajax_storelly_export_missing_skuincludes/class-storelly-erp.php:46
authwp_ajax_storelly_export_duplicate_skuincludes/class-storelly-erp.php:47
authwp_ajax_storelly_connectincludes/class-storelly-erp.php:53
authwp_ajax_storelly_fetch_locationsincludes/class-storelly-erp.php:54
authwp_ajax_storelly_save_locationincludes/class-storelly-erp.php:55
authwp_ajax_storelly_save_sync_rulesincludes/class-storelly-erp.php:56
authwp_ajax_storelly_first_syncincludes/class-storelly-erp.php:57
WordPress Hooks 14
actionadmin_enqueue_scriptsincludes/class-storelly-erp.php:41
actionadmin_enqueue_scriptsincludes/class-storelly-erp.php:42
actionadmin_menuincludes/class-storelly-erp.php:43
actionadmin_post_storelly_erp_save_settingsincludes/class-storelly-erp.php:48
actionadmin_menuincludes/class-storelly-erp.php:51
actionadmin_initincludes/class-storelly-erp.php:52
actionwoocommerce_new_orderincludes/class-storelly-erp.php:62
actionwoocommerce_update_orderincludes/class-storelly-erp.php:63
actionstorelly_erp_background_syncincludes/class-storelly-erp.php:65
actionstorelly_erp_sync_productsincludes/class-storelly-erp.php:66
actionstorelly_erp_sync_ordersincludes/class-storelly-erp.php:67
filtercron_schedulesincludes/class-storelly-erp.php:69
actionplugins_loadedstorelly-erp.php:32
actionadmin_noticesstorelly-erp.php:35

Scheduled Events 1

storelly_erp_background_sync
Maintenance & Trust

Storelly ERP – B2B Inventory & Multi-Location POS for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 24, 2026
PHP min version7.4
Downloads75

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Storelly ERP – B2B Inventory & Multi-Location POS for WooCommerce Developer Profile

storelly

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Storelly ERP – B2B Inventory & Multi-Location POS for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/storelly-erp-b2b-inventory-multi-location-pos-for-woocommerce/assets/css/storelly-admin.css/wp-content/plugins/storelly-erp-b2b-inventory-multi-location-pos-for-woocommerce/assets/js/storelly-admin.js
Script Paths
/wp-content/plugins/storelly-erp-b2b-inventory-multi-location-pos-for-woocommerce/assets/js/storelly-admin.js
Version Parameters
storelly-erp-b2b-inventory-multi-location-pos-for-woocommerce/assets/css/storelly-admin.css?ver=storelly-erp-b2b-inventory-multi-location-pos-for-woocommerce/assets/js/storelly-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
storelly-erp-setup
Data Attributes
data-storelly-erp-setup
JS Globals
storelly_erp_ajax
FAQ

Frequently Asked Questions about Storelly ERP – B2B Inventory & Multi-Location POS for WooCommerce