Powers Triggers for Woocommerce and Trello Security & Risk Analysis

wordpress.org/plugins/wc-trello-powers

Woo & Trello Powers

0 active installs v1.0.2 PHP + WP 4.0.1+ Updated Unknown
trellowoocommercewoocommerce-and-trellowoocommerce-integration-with-trellowoocommerce-order-to-trello
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Powers Triggers for Woocommerce and Trello Safe to Use in 2026?

Generally Safe

Score 100/100

Powers Triggers for Woocommerce and Trello has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "wc-trello-powers" plugin v1.0.2 presents a concerning security posture due to significant gaps in its protection mechanisms, despite some positive aspects. While the plugin demonstrates good practices regarding SQL queries by exclusively using prepared statements and has no recorded vulnerability history, its attack surface is severely exposed. The presence of two AJAX handlers without any authentication or capability checks creates a direct entry point for unauthenticated users to potentially interact with sensitive functionalities.

Furthermore, the static analysis reveals a low rate of proper output escaping (only 33%), increasing the risk of cross-site scripting (XSS) vulnerabilities. The taint analysis highlights flows with unsanitized paths, which, although not classified as critical or high severity in this specific run, indicate potential for unintended data manipulation or access if exploited in conjunction with other weaknesses. The complete absence of nonce checks and capability checks on its entry points, particularly the unprotected AJAX handlers, is a major security oversight.

In conclusion, while the plugin benefits from secure database interaction and a clean vulnerability record, the critical lack of authentication and authorization on its AJAX endpoints, coupled with insufficient output escaping and unsanitized paths, makes it a high-risk target. The unprotected entry points are the most significant immediate threat, demanding urgent attention.

Key Concerns

  • Unprotected AJAX handlers
  • Missing nonce checks
  • Missing capability checks
  • Low percentage of properly escaped output
  • Unsanitized paths in taint analysis
Vulnerabilities
None known

Powers Triggers for Woocommerce and Trello Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Powers Triggers for Woocommerce and Trello Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

33% escaped15 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
wtp_conecta_trello (admin\class-wtp-admin.php:45)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Powers Triggers for Woocommerce and Trello Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_conecta_trelloadmin\class-wtp-admin.php:21
authwp_ajax_load_triggeradmin\class-wtp-admin.php:22
WordPress Hooks 1
actionadmin_menuadmin\class-wtp-admin.php:25
Maintenance & Trust

Powers Triggers for Woocommerce and Trello Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.0
Last updatedUnknown
PHP min version
Downloads879

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Powers Triggers for Woocommerce and Trello Developer Profile

Felipe Peixoto

3 plugins · 10 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Powers Triggers for Woocommerce and Trello

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-trello-powers/admin/js/script.js/wp-content/plugins/wc-trello-powers/admin/css/style.css
Script Paths
/wp-content/plugins/wc-trello-powers/admin/js/script.js

HTML / DOM Fingerprints

CSS Classes
colm3s12m9postboxmetabox-holderhndlemargin-top-bottom15+8 more
Data Attributes
id="form-token"id="key-input"id="token-input"id="painel"id="tabela-acoes"id="btn-adicionar-linha"+2 more
JS Globals
jQuery
REST Endpoints
/wp-json/
FAQ

Frequently Asked Questions about Powers Triggers for Woocommerce and Trello