
WebisOnline Security & Risk Analysis
wordpress.org/plugins/webisonlineWebisOnline -онлайн консультант для вашего сайта повысит конверсию и увеличит продажи
Is WebisOnline Safe to Use in 2026?
Generally Safe
Score 85/100WebisOnline has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "webisonline" v2.4 plugin exhibits a strong security posture in several key areas. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code demonstrates good practices by exclusively using prepared statements for its SQL queries and having no recorded vulnerability history, indicating a potentially well-maintained codebase. The lack of external HTTP requests and bundled libraries also reduces the risk of relying on vulnerable third-party components.
However, the static analysis reveals a critical concern: 100% of the 14 identified output operations are not properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where unsanitized user input could be injected into the website's output, potentially leading to unauthorized actions or data theft. The absence of nonce checks and capability checks, while not directly leading to a deduction due to the limited attack surface, highlights a potential weakness if new entry points are introduced in future versions without corresponding security checks.
In conclusion, while the plugin has a low attack surface and a clean vulnerability history, the prevalent lack of output escaping is a significant and actionable security risk that overshadows its strengths. Addressing the XSS vulnerability is paramount to securing the plugin.
Key Concerns
- Unescaped output (100% of 14 outputs)
- No nonce checks
- No capability checks
WebisOnline Security Vulnerabilities
WebisOnline Release Timeline
WebisOnline Code Analysis
Output Escaping
WebisOnline Attack Surface
WordPress Hooks 4
Maintenance & Trust
WebisOnline Maintenance & Trust
Maintenance Signals
Community Trust
WebisOnline Alternatives
Online-Consultant, Chat For Your Website
online-consultant
Online-Consultant - Мощный абсолютно бесплатный чат для вашего сайта. Powerful absolutly free online chat for your site.
Shipping for Nova Poshta
nova-poshta-ttn
Доставка на відділення, поштомат та адресу (з автопошуком вулиць). Створення ТТН. Найзручніший плагін.
Ukrposhta
woo-ukrposhta
Створюйте експрес-накладні автоматично, на сторінці замовлення. 10% знижка на відправлення, створені онлайн за допомогою API Ukrposhta.
Prisna YT – Яндекс Переводчик
wp-yandex-translate
Добавьте себе виджет Яндекс переводчик.
Report an error
report-an-error
With this plugin visitors will be able to report typos or mistakes seen on your websites.
WebisOnline Developer Profile
1 plugin · 10 total installs
How We Detect WebisOnline
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/webisonline/webisonline.cssHTML / DOM Fingerprints
WEBISONLINE_LANGWEBISONLINE_URLWEBISONLINE_INTEGRATION_URLWEBISONLINE_LANGUAGES_URLWEBISONLINE_PLUGIN_URLWEBISONLINE_IMG_URL