Whmcs Doali to Elementor Security & Risk Analysis

wordpress.org/plugins/whmcs-doali-elementor

This is a WordPress plugin that allow sync Elementor forms with WHMCS Billing and Doali email marketing

50 active installs v4.2.2 PHP + WP + Updated Oct 7, 2024
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Whmcs Doali to Elementor Safe to Use in 2026?

Generally Safe

Score 92/100

Whmcs Doali to Elementor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "whmcs-doali-elementor" plugin, in version 4.2.2, exhibits a generally strong security posture based on the provided static analysis. The absence of any recorded CVEs, coupled with a lack of critical or high-severity findings in the taint analysis, is a positive indicator. The code demonstrates good practices by utilizing prepared statements for all SQL queries and a high percentage of properly escaped output, which significantly mitigates common web application vulnerabilities like SQL injection and cross-site scripting (XSS). The plugin also avoids common attack vectors by having no exposed AJAX handlers, REST API routes, shortcodes, or cron events without proper checks, and it doesn't appear to use dangerous functions or perform file operations that could be exploited.

However, there are areas that warrant attention. The complete lack of nonce checks and capability checks across all entry points (though the entry point count is zero) is a notable concern. If the attack surface were to increase or be discovered in the future, this would leave the plugin highly vulnerable. Furthermore, the plugin makes 11 external HTTP requests, which, without further inspection of their implementation (e.g., sanitization of URLs, validation of responses), could potentially introduce risks like SSRF (Server-Side Request Forgery) or lead to communication with compromised external services.

In conclusion, the plugin is well-engineered in terms of core security practices like SQL and output handling, and it has a clean vulnerability history. This suggests a developer conscious of security. The primary weaknesses lie in the complete absence of authorization and security checks for any potential future entry points and the inherent risks associated with numerous external HTTP requests, which are not explicitly detailed for their security controls in this analysis. While the current attack surface appears minimal and protected by obscurity, a more robust implementation would include explicit security checks for all interactions.

Key Concerns

  • No nonce checks
  • No capability checks
  • 11 external HTTP requests (potential risk)
  • 92% output escaping (some unescaped output)
Vulnerabilities
None known

Whmcs Doali to Elementor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Whmcs Doali to Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
120 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
11
Bundled Libraries
0

Output Escaping

92% escaped130 total outputs
Attack Surface

Whmcs Doali to Elementor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionelementor_pro/initfunctions.php:8
actionelementor_pro/initfunctions.php:16
actionelementor_pro/initfunctions.php:24
actionelementor_pro/initfunctions.php:32
actionelementor_pro/initfunctions.php:40
actionelementor/frontend/after_register_scriptsplugin.php:93
actioninitwhmcs-doali-to-elementor.php:60
actionplugins_loadedwhmcs-doali-to-elementor.php:63
actionadmin_noticeswhmcs-doali-to-elementor.php:95
actionadmin_noticeswhmcs-doali-to-elementor.php:101
actionadmin_noticeswhmcs-doali-to-elementor.php:107
Maintenance & Trust

Whmcs Doali to Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedOct 7, 2024
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings4
Active installs50
Alternatives

Whmcs Doali to Elementor Alternatives

No alternatives data available yet.

Developer Profile

Whmcs Doali to Elementor Developer Profile

mitcho (Michael Yoshitaka Erlewine)

16 plugins · 6K total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Whmcs Doali to Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Whmcs Doali to Elementor