Integration for WooCommerce and Salesforce Security & Risk Analysis

wordpress.org/plugins/woo-salesforce-plugin-crm-perks

WooCommerce Salesforce Plugin allows you to quickly integrate WooCommerce Orders with Salesforce CRM.

200 active installs v1.7.9 PHP 5.3+ WP 4.7+ Updated Mar 22, 2026
salesforcesalesforce-add-onwoocommerce-integration-with-salesforcewoocommerce-salesforcewoocommerce-salesforce-integration
99
A · Safe
CVEs total2
Unpatched0
Last CVEMay 7, 2025
Safety Verdict

Is Integration for WooCommerce and Salesforce Safe to Use in 2026?

Generally Safe

Score 99/100

Integration for WooCommerce and Salesforce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

2 known CVEsLast CVE: May 7, 2025Updated 1mo ago
Risk Assessment

The plugin "woo-salesforce-plugin-crm-perks" v1.7.8 exhibits a generally strong security posture with a clean static analysis report regarding attack surface and taint flows. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events without proper checks, and the taint analysis shows no unsanitized paths or critical/high severity issues. Furthermore, the plugin demonstrates good coding practices by using prepared statements for a significant majority of its SQL queries and properly escaping outputs. The presence of nonce and capability checks is also a positive indicator of security awareness in development.

However, the vulnerability history presents a notable concern. The plugin has a history of two medium severity CVEs, specifically related to "Open Redirect" and "Cross-site Scripting." While currently unpatched vulnerabilities are reported as zero, the recurrence of these vulnerability types suggests potential weaknesses in input sanitization or redirection handling that could be exploited if not addressed thoroughly. The fact that the last vulnerability was recent (May 2025) further emphasizes the need for vigilance. The presence of file operations and external HTTP requests, while not inherently insecure, are always areas that warrant close scrutiny for potential misuse.

In conclusion, the plugin has solid foundational security practices in place, particularly concerning its attack surface and data handling. The absence of critical findings in static and taint analysis is reassuring. Nevertheless, the historical vulnerability patterns, especially the medium severity issues related to XSS and Open Redirect, indicate areas where more robust defenses might be necessary. Continued monitoring of its security track record and thorough auditing of any updates are recommended.

Key Concerns

  • Medium severity CVEs in history (Open Redirect, XSS)
  • Some SQL queries not using prepared statements
  • Some outputs not properly escaped
  • File operations present
  • External HTTP requests present
Vulnerabilities
2 published

Integration for WooCommerce and Salesforce Security Vulnerabilities

CVEs by Year

1 CVE in 2021
2021
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-47455medium · 6.1URL Redirection to Untrusted Site ('Open Redirect')

Integration for WooCommerce and Salesforce <= 1.7.5 - Open Redirect

May 7, 2025 Patched in 1.7.6 (7d)
WF-cc1e9778-2860-4e3c-a2e4-28f10d585fed-woo-salesforce-plugin-crm-perksmedium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CRM Perks - Various Plugins (Various Versions) - Reflected Cross-Site Scripting

Aug 26, 2021 Patched in 1.5.9 (880d)
Code Analysis
Analyzed Mar 16, 2026

Integration for WooCommerce and Salesforce Code Analysis

Dangerous Functions
0
Raw SQL Queries
6
17 prepared
Unescaped Output
70
335 escaped
Nonce Checks
10
Capability Checks
19
File Operations
2
External Requests
3
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

74% prepared23 total queries

Output Escaping

83% escaped405 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
settings_tab (includes\plugin-pages.php:1629)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Integration for WooCommerce and Salesforce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 34
actionadd_meta_boxesincludes\crmperks-wc.php:8
actionsave_postincludes\plugin-pages.php:28
filterwoocommerce_settings_tabs_arrayincludes\plugin-pages.php:30
actionwoocommerce_update_orderincludes\plugin-pages.php:36
actionadd_meta_boxesincludes\plugin-pages.php:39
actionadd_meta_boxesincludes\plugin-pages.php:40
actionadmin_noticesincludes\plugin-pages.php:42
filterpost_updated_messagesincludes\plugin-pages.php:45
actionadmin_menuincludes\plugin-pages.php:47
filteradmin_menuincludes\plugin-pages.php:49
filterplugin_action_linksincludes\plugin-pages.php:50
actionwp_trash_postincludes\plugin-pages.php:71
actionuntrash_postincludes\plugin-pages.php:72
actionwp_insert_commentincludes\plugin-pages.php:76
actiontrash_commentincludes\plugin-pages.php:77
actionplugins_loadedwoo-salesforce-plugin-crm-perks.php:58
actionadmin_noticeswoo-salesforce-plugin-crm-perks.php:74
actionwoocommerce_order_status_changedwoo-salesforce-plugin-crm-perks.php:97
actionywraq_after_create_orderwoo-salesforce-plugin-crm-perks.php:98
actionwoocommerce_subscription_status_updatedwoo-salesforce-plugin-crm-perks.php:99
actionwoocommerce_checkout_update_order_metawoo-salesforce-plugin-crm-perks.php:100
actionwoocommerce_new_orderwoo-salesforce-plugin-crm-perks.php:101
actionwoocommerce_saved_order_itemswoo-salesforce-plugin-crm-perks.php:103
actionprofile_updatewoo-salesforce-plugin-crm-perks.php:106
actionuser_registerwoo-salesforce-plugin-crm-perks.php:107
actionshutdownwoo-salesforce-plugin-crm-perks.php:108
actionwoocommerce_update_productwoo-salesforce-plugin-crm-perks.php:113
actionwoocommerce_new_productwoo-salesforce-plugin-crm-perks.php:114
actionwoocommerce_save_product_variationwoo-salesforce-plugin-crm-perks.php:115
actioninitwoo-salesforce-plugin-crm-perks.php:126
actionbefore_woocommerce_initwoo-salesforce-plugin-crm-perks.php:142
actionadmin_noticeswp\crmperks-notices.php:17
actionmanage_posts_extra_tablenavwp\crmperks-notices.php:18
filterplugin_row_metawp\crmperks-notices.php:22
Maintenance & Trust

Integration for WooCommerce and Salesforce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 22, 2026
PHP min version5.3
Downloads20K

Community Trust

Rating98/100
Number of ratings45
Active installs200
Developer Profile

Integration for WooCommerce and Salesforce Developer Profile

CRM Perks

32 plugins · 105K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
339 days
View full developer profile
Detection Fingerprints

How We Detect Integration for WooCommerce and Salesforce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-salesforce-plugin-crm-perks/css/crmperks-notice.css/wp-content/plugins/woo-salesforce-plugin-crm-perks/js/crmperks-admin.js/wp-content/plugins/woo-salesforce-plugin-crm-perks/js/crmperks-admin-modal.js
Version Parameters
/woo-salesforce-plugin-crm-perks/css/crmperks-notice.css?ver=/woo-salesforce-plugin-crm-perks/js/crmperks-admin.js?ver=/woo-salesforce-plugin-crm-perks/js/crmperks-admin-modal.js?ver=

HTML / DOM Fingerprints

JS Globals
vxc_salesvxcf_plugin_api
FAQ

Frequently Asked Questions about Integration for WooCommerce and Salesforce