
Storelly ERP – B2B Inventory & Multi-Location POS for WooCommerce Security & Risk Analysis
wordpress.org/plugins/storelly-erp-b2b-inventory-multi-location-pos-for-woocommerceConnect WooCommerce to Storelly ERP to sync products, inventory, categories, and orders across your business locations.
Is Storelly ERP – B2B Inventory & Multi-Location POS for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Storelly ERP – B2B Inventory & Multi-Location POS for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
This plugin exhibits a concerning security posture due to a significant number of unprotected AJAX handlers, which represent a substantial attack surface. While the static analysis indicates good practices in other areas, such as the absence of dangerous functions, the prevalent use of prepared statements for SQL queries, and high output escaping, the unprotected AJAX endpoints overshadow these strengths. The lack of nonce checks and capability checks on a majority of its entry points means that any authenticated user could potentially trigger these AJAX actions, leading to unintended consequences or exploitation if vulnerabilities exist within the handler logic. The absence of known CVEs and a clean vulnerability history is positive, suggesting a generally secure development approach for past issues. However, the identified attack surface without proper authentication is a critical oversight that requires immediate attention. Overall, while the plugin demonstrates good coding practices in many aspects, the unprotected AJAX handlers introduce a significant and unmitigated risk.
Key Concerns
- Unprotected AJAX handlers
- Large attack surface without auth
Storelly ERP – B2B Inventory & Multi-Location POS for WooCommerce Security Vulnerabilities
Storelly ERP – B2B Inventory & Multi-Location POS for WooCommerce Release Timeline
Storelly ERP – B2B Inventory & Multi-Location POS for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
Storelly ERP – B2B Inventory & Multi-Location POS for WooCommerce Attack Surface
AJAX Handlers 9
WordPress Hooks 14
Scheduled Events 1
Maintenance & Trust
Storelly ERP – B2B Inventory & Multi-Location POS for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Storelly ERP – B2B Inventory & Multi-Location POS for WooCommerce Alternatives
Perseo Software
perseo-software
Integra el Sistema Contable Perseo (Web y PC) con tu tienda WooCommerce. Sincroniza productos, clientes, inventario y pedidos automáticamente.
Enapps ERP B2B Integration for WooCommerce
enapps-erp-b2b-integration-for-woocommerce
Enapps ERP B2B Integration for WooCommerce Revolutionise B2B ecommerce with real-time Enapps ERP integration.
Keygin Erp Sync
keygin-erp-sync
Automatically sync products and inventory from Contifico to WooCommerce.
Khaos Control Cloud Connector for WooCommerce®
khaos-control-cloud-connector-for-woocommerce
Khaos Control Cloud connector for WooCommerce®, connect your website to Khaos Control Cloud in a few easy steps.
WooCommerce Square
woocommerce-square
Securely accept payments, synchronize sales, and seamlessly manage inventory and product data between WooCommerce and Square POS.
Storelly ERP – B2B Inventory & Multi-Location POS for WooCommerce Developer Profile
2 plugins · 0 total installs
How We Detect Storelly ERP – B2B Inventory & Multi-Location POS for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/storelly-erp-b2b-inventory-multi-location-pos-for-woocommerce/assets/css/storelly-admin.css/wp-content/plugins/storelly-erp-b2b-inventory-multi-location-pos-for-woocommerce/assets/js/storelly-admin.js/wp-content/plugins/storelly-erp-b2b-inventory-multi-location-pos-for-woocommerce/assets/js/storelly-admin.jsstorelly-erp-b2b-inventory-multi-location-pos-for-woocommerce/assets/css/storelly-admin.css?ver=storelly-erp-b2b-inventory-multi-location-pos-for-woocommerce/assets/js/storelly-admin.js?ver=HTML / DOM Fingerprints
storelly-erp-setupdata-storelly-erp-setupstorelly_erp_ajax