WholesaleX – Migration Tool Security & Risk Analysis

wordpress.org/plugins/wholesalex-migration-tool

Move your B2B store's users, groups, dynamic rules, and more from existing Wholesale solutions to the ultimate WooCommerce B2B solution.

20 active installs v1.0.2 PHP 7.4+ WP 6.8+ Updated Mar 4, 2026
b2bkingwholesale-suitewholesalexwoocommerce-b2bwoocommerce-wholesale
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WholesaleX – Migration Tool Safe to Use in 2026?

Generally Safe

Score 100/100

WholesaleX – Migration Tool has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin 'wholesalex-migration-tool' v1.0.2 demonstrates a generally good security posture with several positive indicators. The absence of dangerous functions, SQL injection vulnerabilities, file operations, and external HTTP requests is commendable. All SQL queries utilize prepared statements, and a high percentage of output is properly escaped, significantly reducing the risk of common web vulnerabilities like XSS. The presence of nonce and capability checks for its identified entry points further suggests an effort to implement basic security measures.

However, a key concern arises from the identified attack surface. While the total number of entry points is low (2), one of these, a REST API route, lacks a permission callback. This leaves a direct, unauthenticated entry point into the plugin's functionality, potentially exposing it to unauthorized access or manipulation. The static analysis did not reveal any taint flows or direct vulnerabilities, and the plugin has no recorded vulnerability history, which are positive signs. Despite the single unprotected REST API route, the overall lack of other exploitable code signals and historical issues suggests a relatively secure plugin, but this specific unprotected endpoint needs immediate attention.

In conclusion, the plugin has strong foundations in secure coding practices regarding SQL, output, and external interactions. Its vulnerability history is clean, indicating diligent development or a lack of past exposure. The primary weakness is the unprotected REST API route, which represents a single, but significant, security risk that should be prioritized for remediation.

Key Concerns

  • REST API route without permission callbacks
Vulnerabilities
None known

WholesaleX – Migration Tool Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WholesaleX – Migration Tool Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
17 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

89% escaped19 total outputs
Attack Surface
1 unprotected

WholesaleX – Migration Tool Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 1

authwp_ajax_install_wholesalexincludes\class-wholesalex-migration-notice.php:21

REST API Routes 1

GET/wp-json/wholesalex/v1/migration/includes\class-wholesalex-migration-tool.php:59
WordPress Hooks 8
actionwholesalex_migration_tools_restapi_actionincludes\class-wholesalex-b2bking-migration.php:42
actionadmin_noticesincludes\class-wholesalex-migration-notice.php:22
filterwholesalex_migration_fieldsincludes\class-wholesalex-migration-tool.php:34
actionadmin_initincludes\class-wholesalex-migration-tool.php:39
actionrest_api_initincludes\class-wholesalex-migration-tool.php:256
actionwholesalex_migration_tools_restapi_actionincludes\class-wholesalex-wholesale-suite-migration.php:39
actioninitwholesalex-migration-tool.php:39
actionplugins_loadedwholesalex-migration-tool.php:61
Maintenance & Trust

WholesaleX – Migration Tool Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 4, 2026
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

WholesaleX – Migration Tool Developer Profile

Anik Biswas

3 plugins · 200 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WholesaleX – Migration Tool

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wholesalex-migration-tool/assets/js/whx_migration_tools.js
Script Paths
/wp-content/plugins/wholesalex-migration-tool/assets/js/whx_migration_tools.js
Version Parameters
wholesalex-migration-tool/assets/js/whx_migration_tools.js?ver=

HTML / DOM Fingerprints

Data Attributes
id="wholesalex_migration_tools_root"
JS Globals
wholesalex_migration
REST Endpoints
/wp-json/wholesalex/v1/migration/
FAQ

Frequently Asked Questions about WholesaleX – Migration Tool