Binary MLM For WooCommerce Security & Risk Analysis

wordpress.org/plugins/woo-binary-mlm

Binary MLM plugin for WooCommerce with advanced features to manage users, commissions, and eCommerce growth.

20 active installs v2.1 PHP 8.0+ WP 6.2+ Updated Dec 13, 2025
genealogymlm-pluginnetwork-marketingtags-binary-mlm-for-woocommerce
99
A · Safe
CVEs total2
Unpatched0
Last CVEJan 6, 2025
Download
Safety Verdict

Is Binary MLM For WooCommerce Safe to Use in 2026?

Generally Safe

Score 99/100

Binary MLM For WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Jan 6, 2025Updated 3mo ago
Risk Assessment

The "woo-binary-mlm" v2.1 plugin exhibits a mixed security posture. While it demonstrates good practices in SQL query preparation (98%) and a substantial number of output escaping routines (78% properly escaped), there are significant concerns regarding its attack surface. A large proportion of its AJAX handlers (8 out of 10) lack authentication checks, presenting a clear entry point for unauthorized actions. The presence of 'unserialize' calls in the code, coupled with 7 high-severity taint flows with unsanitized paths, indicates a strong potential for critical vulnerabilities like remote code execution or information disclosure if user-controlled data is passed through these flows.

The vulnerability history, although showing no currently unpatched CVEs, reveals a past pattern of medium-severity Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerabilities. This history, combined with the identified taint flows and unprotected AJAX endpoints, suggests that the plugin may be susceptible to similar or more severe issues if proper sanitization and authentication are not rigorously applied. The lack of bundled libraries is a positive sign, reducing the risk associated with outdated dependencies.

In conclusion, while the plugin has strengths in its database interaction and output handling, the numerous unprotected AJAX endpoints and the high number of critical taint flows are major weaknesses that expose it to significant security risks. The historical trend of vulnerabilities also warrants caution. Addressing the unprotected AJAX handlers and thoroughly sanitizing all data flows, particularly those involving unserialization, should be a priority.

Key Concerns

  • Unprotected AJAX handlers
  • High severity taint flows
  • Dangerous function: unserialize
  • Medium severity CVE history
Vulnerabilities
2

Binary MLM For WooCommerce Security Vulnerabilities

CVEs by Year

2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-12384medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Binary MLM Woocommerce <= 2.0 - Reflected Cross-Site Scripting via 'page'

Jan 6, 2025 Patched in 2.1 (347d)
CVE-2024-12383medium · 6.1Cross-Site Request Forgery (CSRF)

Binary MLM Woocommerce <= 2.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Jan 6, 2025 Patched in 2.1 (347d)
Code Analysis
Analyzed Mar 16, 2026

Binary MLM For WooCommerce Code Analysis

Dangerous Functions
3
Raw SQL Queries
5
208 prepared
Unescaped Output
150
519 escaped
Nonce Checks
11
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$childs = unserialize($pair['childs']); ?>includes\admin\payout\payout-money.php:73
unserialize$users = unserialize($results);includes\common-functions.php:57
unserialize$childs = unserialize($results);includes\common-functions.php:622

SQL Query Safety

98% prepared213 total queries

Output Escaping

78% escaped669 total outputs
Data Flows
12 unsanitized

Data Flow Analysis

25 flows12 with unsanitized paths
display_bmw_member_profile_details_page (includes\admin\member-profile-page.php:27)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
8 unprotected

Binary MLM For WooCommerce Attack Surface

Entry Points14
Unprotected8

AJAX Handlers 10

authwp_ajax_usernameincludes\ajax-function.php:12
noprivwp_ajax_usernameincludes\ajax-function.php:13
authwp_ajax_emailincludes\ajax-function.php:14
noprivwp_ajax_emailincludes\ajax-function.php:15
authwp_ajax_sponsorincludes\ajax-function.php:16
noprivwp_ajax_sponsorincludes\ajax-function.php:17
authwp_ajax_bmw_sponsorincludes\ajax-function.php:18
noprivwp_ajax_bmw_sponsorincludes\ajax-function.php:19
authwp_ajax_savepointsincludes\ajax-function.php:20
authwp_ajax_savemoneyincludes\ajax-function.php:21

Shortcodes 4

[bmw_registration] includes\class-bmw.php:329
[bmw_downlines] includes\class-bmw.php:335
[bmw_network] includes\class-bmw.php:341
[bmw_join_network] includes\class-bmw.php:347
WordPress Hooks 12
actionadmin_enqueue_scriptsincludes\admin\admin.php:6
filtermanage_users_columnsincludes\admin\admin.php:103
actionmanage_users_columnsincludes\admin\admin.php:114
actionmanage_users_custom_columnincludes\admin\admin.php:136
actionwp_enqueue_scriptsincludes\ajax-function.php:10
actionadmin_noticesincludes\class-bmw.php:40
actioninitincludes\class-bmw.php:159
actioninitincludes\class-bmw.php:160
actionadmin_enqueue_scriptsincludes\class-bmw.php:161
actionwp_enqueue_scriptsincludes\class-bmw.php:162
actionwoocommerce_checkout_update_order_metaincludes\class-bmw.php:173
actionadmin_menuincludes\class-bmw.php:196
Maintenance & Trust

Binary MLM For WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 13, 2025
PHP min version8.0
Downloads16K

Community Trust

Rating80/100
Number of ratings4
Active installs20
Developer Profile

Binary MLM For WooCommerce Developer Profile

LETSCMS MLM Software

5 plugins · 80 total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
241 days
View full developer profile
Detection Fingerprints

How We Detect Binary MLM For WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-binary-mlm/assets/js/ajax.js/wp-content/plugins/woo-binary-mlm/assets/js/bonus.js
Script Paths
/wp-content/plugins/woo-binary-mlm/assets/js/ajax.js/wp-content/plugins/woo-binary-mlm/assets/js/bonus.js

HTML / DOM Fingerprints

CSS Classes
nav-tab-active
FAQ

Frequently Asked Questions about Binary MLM For WooCommerce