
Integration for WooCommerce and Salesforce Security & Risk Analysis
wordpress.org/plugins/woo-salesforce-plugin-crm-perksWooCommerce Salesforce Plugin allows you to quickly integrate WooCommerce Orders with Salesforce CRM.
Is Integration for WooCommerce and Salesforce Safe to Use in 2026?
Generally Safe
Score 99/100Integration for WooCommerce and Salesforce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin "woo-salesforce-plugin-crm-perks" v1.7.8 exhibits a generally strong security posture with a clean static analysis report regarding attack surface and taint flows. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events without proper checks, and the taint analysis shows no unsanitized paths or critical/high severity issues. Furthermore, the plugin demonstrates good coding practices by using prepared statements for a significant majority of its SQL queries and properly escaping outputs. The presence of nonce and capability checks is also a positive indicator of security awareness in development.
However, the vulnerability history presents a notable concern. The plugin has a history of two medium severity CVEs, specifically related to "Open Redirect" and "Cross-site Scripting." While currently unpatched vulnerabilities are reported as zero, the recurrence of these vulnerability types suggests potential weaknesses in input sanitization or redirection handling that could be exploited if not addressed thoroughly. The fact that the last vulnerability was recent (May 2025) further emphasizes the need for vigilance. The presence of file operations and external HTTP requests, while not inherently insecure, are always areas that warrant close scrutiny for potential misuse.
In conclusion, the plugin has solid foundational security practices in place, particularly concerning its attack surface and data handling. The absence of critical findings in static and taint analysis is reassuring. Nevertheless, the historical vulnerability patterns, especially the medium severity issues related to XSS and Open Redirect, indicate areas where more robust defenses might be necessary. Continued monitoring of its security track record and thorough auditing of any updates are recommended.
Key Concerns
- Medium severity CVEs in history (Open Redirect, XSS)
- Some SQL queries not using prepared statements
- Some outputs not properly escaped
- File operations present
- External HTTP requests present
Integration for WooCommerce and Salesforce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Integration for WooCommerce and Salesforce <= 1.7.5 - Open Redirect
CRM Perks - Various Plugins (Various Versions) - Reflected Cross-Site Scripting
Integration for WooCommerce and Salesforce Release Timeline
Integration for WooCommerce and Salesforce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Integration for WooCommerce and Salesforce Attack Surface
WordPress Hooks 34
Maintenance & Trust
Integration for WooCommerce and Salesforce Maintenance & Trust
Maintenance Signals
Community Trust
Integration for WooCommerce and Salesforce Alternatives
Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms
cf7-salesforce
Send Contact Form 7, WPforms, Elementor, Ninja Forms, Contact Form Entries Plugin and many other contact form submissions to salesforce.
Account Engagement
pardot
Integrate Account Engagement with WordPress: easily track visitors, embed forms and dynamic content in pages and posts, or use the forms or dynamic co …
Connector for Gravity Forms and Salesforce
gf-salesforce-crmperks
Gravity Forms Salesforce Add-on sends Gravity forms entries to salesforce CRM.
Outfunnel: Web Visitor Tracking & CRM Integration
outfunnel
Track which leads visit your website and automatically sync WordPress form submissions to Pipedrive, HubSpot, Copper, or Salesforce.
Object Sync for Salesforce
object-sync-for-salesforce
Object Sync for Salesforce maps and syncs data between Salesforce objects and WordPress objects.
Integration for WooCommerce and Salesforce Developer Profile
32 plugins · 105K total installs
How We Detect Integration for WooCommerce and Salesforce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-salesforce-plugin-crm-perks/css/crmperks-notice.css/wp-content/plugins/woo-salesforce-plugin-crm-perks/js/crmperks-admin.js/wp-content/plugins/woo-salesforce-plugin-crm-perks/js/crmperks-admin-modal.js/woo-salesforce-plugin-crm-perks/css/crmperks-notice.css?ver=/woo-salesforce-plugin-crm-perks/js/crmperks-admin.js?ver=/woo-salesforce-plugin-crm-perks/js/crmperks-admin-modal.js?ver=HTML / DOM Fingerprints
vxc_salesvxcf_plugin_api