
WholesaleX – Migration Tool Security & Risk Analysis
wordpress.org/plugins/wholesalex-migration-toolMove your B2B store's users, groups, dynamic rules, and more from existing Wholesale solutions to the ultimate WooCommerce B2B solution.
Is WholesaleX – Migration Tool Safe to Use in 2026?
Generally Safe
Score 100/100WholesaleX – Migration Tool has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'wholesalex-migration-tool' v1.0.2 demonstrates a generally good security posture with several positive indicators. The absence of dangerous functions, SQL injection vulnerabilities, file operations, and external HTTP requests is commendable. All SQL queries utilize prepared statements, and a high percentage of output is properly escaped, significantly reducing the risk of common web vulnerabilities like XSS. The presence of nonce and capability checks for its identified entry points further suggests an effort to implement basic security measures.
However, a key concern arises from the identified attack surface. While the total number of entry points is low (2), one of these, a REST API route, lacks a permission callback. This leaves a direct, unauthenticated entry point into the plugin's functionality, potentially exposing it to unauthorized access or manipulation. The static analysis did not reveal any taint flows or direct vulnerabilities, and the plugin has no recorded vulnerability history, which are positive signs. Despite the single unprotected REST API route, the overall lack of other exploitable code signals and historical issues suggests a relatively secure plugin, but this specific unprotected endpoint needs immediate attention.
In conclusion, the plugin has strong foundations in secure coding practices regarding SQL, output, and external interactions. Its vulnerability history is clean, indicating diligent development or a lack of past exposure. The primary weakness is the unprotected REST API route, which represents a single, but significant, security risk that should be prioritized for remediation.
Key Concerns
- REST API route without permission callbacks
WholesaleX – Migration Tool Security Vulnerabilities
WholesaleX – Migration Tool Code Analysis
Output Escaping
WholesaleX – Migration Tool Attack Surface
AJAX Handlers 1
REST API Routes 1
WordPress Hooks 8
Maintenance & Trust
WholesaleX – Migration Tool Maintenance & Trust
Maintenance Signals
Community Trust
WholesaleX – Migration Tool Alternatives
B2BKing — Ultimate WooCommerce B2B and Wholesale Solution — Dynamic Pricing, Wholesale Order Form & More
b2bking-wholesale-for-woocommerce
B2BKing is the complete solution for running a Wholesale, B2B or B2B + B2C hybrid store with WooCommerce.
Whols – Wholesale Prices and B2B Store Solution for WooCommerce
whols
WooCommerce Wholesale plugin for WooCommerce wholesale pricing. It is a b2b plugin for WooCommerce. WooCommerce B2B or B2B + B2C hybrid Store Solution
Private Store for WooCommerce B2B & Wholesale by B2BKing
b2bking-private-store-for-woocommerce
Hide prices for logged out users, or even hide the store completely! Perfect solution for Private, B2B, and Wholesale stores.
B2B plugin for Woocommerce
b2b-for-woo
The "B2B plugin for Woocommerce" plugin is designed to help store owners easily manage both wholesale (B2B) and retail (B2C) customers withi …
Wholesale Suite – B2B, Dynamic Pricing & WooCommerce Wholesale Prices
woocommerce-wholesale-prices
WooCommerce wholesale plugin for serving wholesale & B2B customers. Adds wholesale pricing, user roles, dynamic pricing & more.
WholesaleX – Migration Tool Developer Profile
3 plugins · 200 total installs
How We Detect WholesaleX – Migration Tool
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wholesalex-migration-tool/assets/js/whx_migration_tools.js/wp-content/plugins/wholesalex-migration-tool/assets/js/whx_migration_tools.jswholesalex-migration-tool/assets/js/whx_migration_tools.js?ver=HTML / DOM Fingerprints
id="wholesalex_migration_tools_root"wholesalex_migration/wp-json/wholesalex/v1/migration/