
Webhook For WCFM Vendors Security & Risk Analysis
wordpress.org/plugins/webhook-for-wcfm-vendorsSend order webhooks to your WCFM vendors.
Is Webhook For WCFM Vendors Safe to Use in 2026?
Generally Safe
Score 92/100Webhook For WCFM Vendors has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "webhook-for-wcfm-vendors" plugin v1.0.1 exhibits a generally good security posture based on the provided static analysis. The plugin has a limited attack surface with only two AJAX handlers, and importantly, all identified entry points are protected with authorization checks. The absence of critical or high-severity taint flows is a strong indicator of secure coding practices regarding data handling. The plugin also demonstrates a commitment to security by implementing nonce checks and capability checks for its AJAX endpoints.
However, there are areas for improvement. While most SQL queries utilize prepared statements, 50% do not, presenting a potential risk if these queries handle user-supplied data. Furthermore, a significant portion of output (33%) is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if the unescaped output contains user-controlled data. The single file operation could also be a concern if not handled with extreme care regarding input validation.
The plugin's vulnerability history is a significant strength, showing zero known CVEs. This suggests a history of developing secure code or a lack of targeted security research against this specific plugin. Coupled with the current static analysis findings, this paints a picture of a relatively safe plugin, but the identified code-level risks, particularly around SQL and output escaping, warrant attention.
Key Concerns
- SQL queries without prepared statements
- Unescaped output detected
- Presence of file operations
Webhook For WCFM Vendors Security Vulnerabilities
Webhook For WCFM Vendors Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Webhook For WCFM Vendors Attack Surface
AJAX Handlers 2
WordPress Hooks 9
Maintenance & Trust
Webhook For WCFM Vendors Maintenance & Trust
Maintenance Signals
Community Trust
Webhook For WCFM Vendors Alternatives
WCFM – WCFM Marketplace integrate Elementor
wc-frontend-manager-elementor
Create your marketplace store page using Elementor with your own design. Easily and Beatifully.
WCFM – Direct PayPal Pay for WooCommerce Multivendor Marketplace
wc-frontend-manager-direct-paypal
Direct pay in vendor's PayPal account from customer account.
Split Pay – Stripe Connect Split Payments & Multi-Vendor Marketplace for WooCommerce
bsd-woo-stripe-connect-split-pay
Split payments made in WooCommerce stores between multiple Stripe Connected Accounts and a Stripe Platform Account.
OttoKit: All-in-One Automation Platform
suretriggers
Experience the power of automation within WordPress: Connect 1,300+ apps, automate manual tasks, and unlock your full potential. Get started now!
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin
uncanny-automator
Uncanny Automator is the easiest and most powerful way to connect your WordPress plugins, sites and apps together with powerful automations.
Webhook For WCFM Vendors Developer Profile
14 plugins · 2K total installs
How We Detect Webhook For WCFM Vendors
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/webhook-for-wcfm-vendors/asset/css/style.css/wp-content/plugins/webhook-for-wcfm-vendors/asset/js/script.js/wp-content/plugins/webhook-for-wcfm-vendors/asset/js/script.jswebhook-for-wcfm-vendors/asset/css/style.css?ver=webhook-for-wcfm-vendors/asset/js/script.js?ver=HTML / DOM Fingerprints
data-webhook_nounceetsWebhookVendor/wp-json/wcfm/v1/webhook/test