Ultraleet Woocommerce Erply Integration Security & Risk Analysis

wordpress.org/plugins/ultraleet-wc-erply-integration

Enables integration between your Woocommerce shop and Erply POS account.

0 active installs v1.0.0 PHP 7.2+ WP 4.9+ Updated Unknown
e-commerceecommerceerplyintegrationwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Ultraleet Woocommerce Erply Integration Safe to Use in 2026?

Generally Safe

Score 100/100

Ultraleet Woocommerce Erply Integration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The ultraleet-wc-erply-integration plugin version 1.0.0 exhibits a mixed security posture. On the positive side, the absence of known vulnerabilities and CVEs, coupled with a low number of external HTTP requests, suggests a relatively clean history. The static analysis also shows a commitment to using prepared statements for the majority of its SQL queries, which is a good practice for preventing SQL injection. However, there are significant concerns regarding output escaping and the lack of proper security checks.

A major weakness identified is the low percentage of properly escaped outputs. With only 19% of 32 outputs being properly escaped, this leaves the plugin highly susceptible to Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed within the WordPress admin or frontend.

Furthermore, the complete absence of nonce checks and capability checks across all identified entry points is alarming. While the attack surface appears small on paper (0 AJAX, 0 REST API, 0 shortcodes), any future expansion or accidental exposure of these points would be entirely unprotected. The single cron event also lacks explicit protection, potentially allowing unauthorized triggering. The vulnerability history being completely clear is a positive sign, but it does not mitigate the current, identifiable risks within the code itself.

Key Concerns

  • Low percentage of properly escaped outputs
  • No nonce checks
  • No capability checks
  • Cron event without auth check
Vulnerabilities
None known

Ultraleet Woocommerce Erply Integration Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Ultraleet Woocommerce Erply Integration Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
10 prepared
Unescaped Output
26
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
6
External Requests
0
Bundled Libraries
0

SQL Query Safety

91% prepared11 total queries

Output Escaping

19% escaped32 total outputs
Attack Surface

Ultraleet Woocommerce Erply Integration Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
filterwcerply_get_language_optionssrc\Components\Settings.php:35
filterwcerply_get_cron_schedule_optionssrc\Components\Settings.php:36
filterwcerply_get_warehouse_optionssrc\Components\Settings.php:37
actionwcerply_save_api_settingssrc\Components\Settings.php:42
actionwcerply_save_schedule_settingssrc\Components\Settings.php:43
filterultraleet_wp_settings_configsrc\Components\Synchronization.php:114
actionultraleet_scheduler_before_runsrc\Components\Synchronization.php:147
actionultraleet_scheduler_after_runsrc\Components\Synchronization.php:148

Scheduled Events 1

wcerply_queue
Maintenance & Trust

Ultraleet Woocommerce Erply Integration Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedUnknown
PHP min version7.2
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Ultraleet Woocommerce Erply Integration Developer Profile

ultraleet

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ultraleet Woocommerce Erply Integration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ultraleet-wc-erply-integration/assets/js/wcerply.js
Script Paths
/wp-content/plugins/ultraleet-wc-erply-integration/assets/js/wcerply.js
Version Parameters
wcerply.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Ultraleet Woocommerce Erply Integration