Wholesale Powerhouse Security & Risk Analysis

wordpress.org/plugins/wholesale-powerhouse

Wholesale Powerhouse adds fast wholesale pricing, roles, tiered discounts, and private storefront controls to WooCommerce—no custom tables.

0 active installs v1.0.0 PHP 7.4+ WP 5.8+ Updated Dec 28, 2025
b2bpricingtiered-pricingwholesalewoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Wholesale Powerhouse Safe to Use in 2026?

Generally Safe

Score 100/100

Wholesale Powerhouse has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "wholesale-powerhouse" v1.0.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests are all positive indicators. The plugin demonstrates good practices in output escaping, with 90% of outputs being properly escaped, and a healthy number of nonce and capability checks are implemented, suggesting an effort to protect against common web vulnerabilities.

Despite these strengths, the limited scope of the static analysis, particularly the absence of taint analysis flows, means that deeper vulnerabilities might still exist. The single shortcode is an entry point, and while the analysis indicates no unprotected entry points, a thorough manual review of this shortcode's implementation would be prudent to ensure no overlooked vulnerabilities exist. The lack of any recorded vulnerability history is a positive sign, suggesting a stable and secure codebase up to this version.

Overall, "wholesale-powerhouse" v1.0.0 appears to be a well-developed plugin from a security perspective. Its adherence to secure coding practices in areas like SQL queries and output handling is commendable. However, the completeness of the static analysis is a potential blind spot. The low number of entry points and the absence of known vulnerabilities point towards a low-risk plugin, but further dynamic testing and a review of the shortcode's logic would provide a more comprehensive security assessment.

Vulnerabilities
None known

Wholesale Powerhouse Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Wholesale Powerhouse Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
64 escaped
Nonce Checks
5
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

90% escaped71 total outputs
Attack Surface

Wholesale Powerhouse Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wholpo_registration_form] includes\class-wholpo-registration.php:32
WordPress Hooks 41
filterwoocommerce_product_data_tabsadmin\class-wholpo-admin-product.php:32
actionwoocommerce_product_data_panelsadmin\class-wholpo-admin-product.php:33
actionwoocommerce_process_product_metaadmin\class-wholpo-admin-product.php:36
filtermanage_product_posts_columnsadmin\class-wholpo-admin-product.php:39
actionmanage_product_posts_custom_columnadmin\class-wholpo-admin-product.php:40
filterwoocommerce_settings_tabs_arrayadmin\class-wholpo-admin-settings.php:32
actionwoocommerce_settings_tabs_wholesaleadmin\class-wholpo-admin-settings.php:33
actionwoocommerce_update_options_wholesaleadmin\class-wholpo-admin-settings.php:34
actionshow_user_profileadmin\class-wholpo-admin-user.php:32
actionedit_user_profileadmin\class-wholpo-admin-user.php:33
actionpersonal_options_updateadmin\class-wholpo-admin-user.php:36
actionedit_user_profile_updateadmin\class-wholpo-admin-user.php:37
filtermanage_users_columnsadmin\class-wholpo-admin-user.php:40
filtermanage_users_custom_columnadmin\class-wholpo-admin-user.php:41
actionrestrict_manage_usersadmin\class-wholpo-admin-user.php:44
filterpre_get_usersadmin\class-wholpo-admin-user.php:45
filterbulk_actions-usersadmin\class-wholpo-admin-user.php:48
filterhandle_bulk_actions-usersadmin\class-wholpo-admin-user.php:49
actionwoocommerce_check_cart_itemsincludes\class-wholpo-cart-controls.php:32
filterwoocommerce_coupons_enabledincludes\class-wholpo-cart-controls.php:35
filterwoocommerce_coupon_is_validincludes\class-wholpo-cart-controls.php:36
actionadmin_enqueue_scriptsincludes\class-wholpo-powerhouse.php:102
actionwp_enqueue_scriptsincludes\class-wholpo-powerhouse.php:103
filterwoocommerce_product_get_priceincludes\class-wholpo-pricing.php:39
filterwoocommerce_product_get_regular_priceincludes\class-wholpo-pricing.php:40
filterwoocommerce_product_get_sale_priceincludes\class-wholpo-pricing.php:41
filterwoocommerce_product_variation_get_priceincludes\class-wholpo-pricing.php:44
filterwoocommerce_product_variation_get_regular_priceincludes\class-wholpo-pricing.php:45
filterwoocommerce_product_variation_get_sale_priceincludes\class-wholpo-pricing.php:46
filterwoocommerce_variation_pricesincludes\class-wholpo-pricing.php:49
filterwoocommerce_get_variation_prices_hashincludes\class-wholpo-pricing.php:52
actioninitincludes\class-wholpo-registration.php:35
filterwoocommerce_product_get_priceincludes\class-wholpo-tiered-pricing.php:32
actionwoocommerce_after_add_to_cart_formincludes\class-wholpo-tiered-pricing.php:35
filterwoocommerce_is_purchasableincludes\class-wholpo-visibility.php:32
filterwoocommerce_get_price_htmlincludes\class-wholpo-visibility.php:33
actionpre_get_postsincludes\class-wholpo-visibility.php:36
filterwoocommerce_product_is_visibleincludes\class-wholpo-visibility.php:37
actionadmin_noticeswholesale-powerhouse.php:39
actionplugins_loadedwholesale-powerhouse.php:95
actionbefore_woocommerce_initwholesale-powerhouse.php:100
Maintenance & Trust

Wholesale Powerhouse Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 28, 2025
PHP min version7.4
Downloads110

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Wholesale Powerhouse Developer Profile

Mithu A Quayium

16 plugins · 500 total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Wholesale Powerhouse

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wholesale-powerhouse/assets/css/wh-admin.css/wp-content/plugins/wholesale-powerhouse/assets/js/wh-admin.js/wp-content/plugins/wholesale-powerhouse/assets/css/wh-public.css/wp-content/plugins/wholesale-powerhouse/assets/js/wh-public.js
Script Paths
/wp-content/plugins/wholesale-powerhouse/assets/js/wh-admin.js/wp-content/plugins/wholesale-powerhouse/assets/js/wh-public.js
Version Parameters
ver=1.0.0

HTML / DOM Fingerprints

CSS Classes
wholpo-registration-form
Data Attributes
data-wholpo-role
JS Globals
wholpo_registration_params
Shortcode Output
[wholpo_registration_form]
FAQ

Frequently Asked Questions about Wholesale Powerhouse