Wappbiz Security & Risk Analysis

wordpress.org/plugins/wappbiz

Advanced integration with the Wappbiz API for seamless WooCommerce order and cart synchronization.

0 active installs v1.0 PHP 7.2+ WP 5.2+ Updated Unknown
api-integrationcartorderswhatsapp-notificationswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Wappbiz Safe to Use in 2026?

Generally Safe

Score 100/100

Wappbiz has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "wappbiz" v1.0 plugin exhibits a generally strong security posture based on the static analysis. The absence of dangerous functions, raw SQL queries, file operations, and any recorded vulnerability history are significant strengths. The plugin also demonstrates good practices by largely escaping output and utilizing nonce checks. However, there are areas for improvement. The presence of external HTTP requests without any context on their purpose or validation is a concern, as is the complete lack of capability checks on any of its entry points, including the AJAX handlers. While the attack surface is small and all entry points have some form of protection (implied by the "Unprotected: 0" stat), relying solely on nonces without capability checks can still leave the plugin vulnerable to privilege escalation if an attacker can bypass or brute-force the nonces, or if the actions performed by the AJAX handlers are sensitive. The fact that taint analysis found no issues is positive, but it's worth noting that the total flows analyzed were zero, suggesting limited scope or a lack of complex data handling that would trigger taint analysis.

Key Concerns

  • Missing capability checks on entry points
  • External HTTP requests without context/validation
Vulnerabilities
None known

Wappbiz Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Wappbiz Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
23 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
8
Bundled Libraries
0

Output Escaping

88% escaped26 total outputs
Attack Surface

Wappbiz Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

noprivwp_ajax_wappbiz_quantity_updatewappbiz.php:42
authwp_ajax_wappbiz_quantity_updatewappbiz.php:43
WordPress Hooks 10
actioninitwappbiz.php:34
actionadmin_menuwappbiz.php:35
actionadmin_enqueue_scriptswappbiz.php:36
actionwoocommerce_thankyouwappbiz.php:37
actionwoocommerce_order_status_changedwappbiz.php:38
actionwoocommerce_add_to_cartwappbiz.php:39
actionwoocommerce_before_checkout_formwappbiz.php:41
actionwp_enqueue_scriptswappbiz.php:130
actionadmin_noticeswappbiz.php:1025
actionplugins_loadedwappbiz.php:1242
Maintenance & Trust

Wappbiz Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.2
Downloads288

Community Trust

Rating100/100
Number of ratings3
Active installs0
Developer Profile

Wappbiz Developer Profile

wappbiz2024

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Wappbiz

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wappbiz/assets/admin-styles.css/wp-content/plugins/wappbiz/assets/admin-script.js/wp-content/plugins/wappbiz/assets/frontend.js
Script Paths
/wp-content/plugins/wappbiz/assets/admin-script.js/wp-content/plugins/wappbiz/assets/frontend.js
Version Parameters
wappbiz-admin-styles?ver=wappbiz-admin-script?ver=wappbiz-frontend?ver=

HTML / DOM Fingerprints

CSS Classes
wappbiz-admin-pagewappbiz-logowappbiz-nav-tab-active
Data Attributes
data-wappbiz-id
JS Globals
wappbizAjax
FAQ

Frequently Asked Questions about Wappbiz