
WHMCS Domain Checker Security & Risk Analysis
wordpress.org/plugins/whmcs-domain-checkerWordPress plugin that allows you to display the responsive WHMCS Domain Checker in a widget.
Is WHMCS Domain Checker Safe to Use in 2026?
Generally Safe
Score 85/100WHMCS Domain Checker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "whmcs-domain-checker" plugin v1.0.1 presents a mixed security posture. On the positive side, the plugin boasts a very small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events. All identified SQL queries utilize prepared statements, and there are no recorded historical vulnerabilities (CVEs), which suggests a generally well-maintained and secure codebase in these areas. Furthermore, nonce and capability checks are present for its single entry point, and there are no file operations or external HTTP requests that could introduce vulnerabilities. However, a significant concern is the presence of the `create_function` dangerous function, which can lead to arbitrary code execution if not handled with extreme care. Additionally, a low percentage (13%) of output escaping indicates a potential for cross-site scripting (XSS) vulnerabilities across the majority of its output operations. While taint analysis shows no current issues, this could be due to the limited flows analyzed or the nature of the detected `create_function` usage.
In conclusion, while the plugin benefits from a limited attack surface and a clean vulnerability history, the use of `create_function` and the poor output escaping practices represent substantial risks that need immediate attention. The absence of taint flow issues might be misleading if the dangerous function is not being properly sanitized or if the taint analysis was not comprehensive. Therefore, despite its strengths in other areas, the identified code signals warrant a cautious approach and suggest that the plugin is not as secure as its limited attack surface might initially imply.
Key Concerns
- Presence of dangerous function 'create_function'
- Low output escaping percentage (13%)
WHMCS Domain Checker Security Vulnerabilities
WHMCS Domain Checker Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
WHMCS Domain Checker Attack Surface
WordPress Hooks 10
Maintenance & Trust
WHMCS Domain Checker Maintenance & Trust
Maintenance Signals
Community Trust
WHMCS Domain Checker Alternatives
WHMCS Bridge
whmcs-bridge
WHMCS Bridge is a plugin that integrates the powerful WHMCS support and billing software with WordPress.
Innovs WPBakery Visual Composer WHMCS Elements
void-visual-whmcs-element
🚀 This WordPress Plugin seamlessly integrates various WPBakery Page Builder widgets with WHMCS, the leading solution for hosting companies to bill and …
Domain Search for WHMCS
domain-search-for-whmcs
Integrate WHMCS domain search functionality into your WordPress website with a clean, responsive search form.
WHMCS Price
whmcs-price
Dynamic way for extracting product & domain price from WHMCS.
LJM WHMCS Domain Checker
whmcs-domain-checker-widget
A simple plugin for WordPress that allows you to display the Domain Checker for WHMCS in a nice tidy widget.
WHMCS Domain Checker Developer Profile
1 plugin · 60 total installs
How We Detect WHMCS Domain Checker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/whmcs-domain-checker/assets/js/jquery.min.js/wp-content/plugins/whmcs-domain-checker/assets/js/jquery.jplayer.min.js/wp-content/plugins/whmcs-domain-checker/assets/js/jquery.selectbox.js/wp-content/plugins/whmcs-domain-checker/assets/js/moment.min.js/wp-content/plugins/whmcs-domain-checker/assets/js/jquery.inputmask.js/wp-content/plugins/whmcs-domain-checker/assets/js/chart.min.js/wp-content/plugins/whmcs-domain-checker/assets/js/jquery.validate.min.js/wp-content/plugins/whmcs-domain-checker/assets/js/daterangepicker.js+24 more/wp-content/plugins/whmcs-domain-checker/assets/js/main.jsHTML / DOM Fingerprints
whmcs-domain-checker-widgetdata-plugin-slug="whmcs-domain-checker"whmcs_domain_checker_ajax_object