Integration for WooCommerce and Zoho CRM, Books, Invoice, Inventory, Bigin Security & Risk Analysis

wordpress.org/plugins/woo-zoho

WooCommerce Zoho Connector allows you to quickly integrate WooCommerce Orders with Zoho CRM, Books, Inventory and Invoice.

2K active installs v1.6.0 PHP 5.3+ WP 4.7+ Updated Jan 14, 2026
woocommerce-zohozohozoho-bookszoho-inventoryzoho-invoice
99
A · Safe
CVEs total2
Unpatched0
Last CVEJul 20, 2023
Safety Verdict

Is Integration for WooCommerce and Zoho CRM, Books, Invoice, Inventory, Bigin Safe to Use in 2026?

Generally Safe

Score 99/100

Integration for WooCommerce and Zoho CRM, Books, Invoice, Inventory, Bigin has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Jul 20, 2023Updated 2mo ago
Risk Assessment

The "woo-zoho" plugin v1.6.0 presents a mixed security posture. The static analysis reveals a commendable absence of direct attack surface points like unprotected AJAX handlers, REST API routes, or shortcodes. The code signals also indicate good practices, with a high percentage of SQL queries using prepared statements and a strong emphasis on output escaping and nonce/capability checks. However, the presence of two file operations and two external HTTP requests, while not explicitly flagged as vulnerable in the static analysis, represent potential avenues for further investigation if not meticulously secured.

The vulnerability history is a significant concern. The plugin has a history of two medium-severity vulnerabilities, specifically "Open Redirect" and "Cross-site Scripting." While there are currently no unpatched CVEs, the recurrence of these vulnerability types suggests potential ongoing weaknesses in input sanitization or output encoding that attackers could exploit. The last reported vulnerability was relatively recent, indicating that the plugin may still be a target or that previous fixes might not have been comprehensive.

In conclusion, "woo-zoho" v1.6.0 demonstrates a solid foundation in core security practices like prepared statements and output escaping. Its lack of direct attack vectors is positive. However, the historical trend of medium-severity vulnerabilities, particularly XSS and open redirects, warrants vigilance. Users should ensure they are using the latest version of the plugin and remain aware of any new security advisories. The limited number of file operations and external requests should be reviewed for robust security controls.

Key Concerns

  • Past Medium Severity Vulnerabilities (XSS, Open Redirect)
  • Two file operations identified
  • Two external HTTP requests identified
Vulnerabilities
2

Integration for WooCommerce and Zoho CRM, Books, Invoice, Inventory, Bigin Security Vulnerabilities

CVEs by Year

1 CVE in 2021
2021
1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2023-38481medium · 4.3URL Redirection to Untrusted Site ('Open Redirect')

Integration for WooCommerce and Zoho CRM <= 1.3.6 - Open Redirect via setup_plugin

Jul 20, 2023 Patched in 1.3.7 (187d)
WF-cc1e9778-2860-4e3c-a2e4-28f10d585fed-woo-zohomedium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CRM Perks - Various Plugins (Various Versions) - Reflected Cross-Site Scripting

Aug 26, 2021 Patched in 1.2.4 (880d)
Code Analysis
Analyzed Mar 16, 2026

Integration for WooCommerce and Zoho CRM, Books, Invoice, Inventory, Bigin Code Analysis

Dangerous Functions
0
Raw SQL Queries
7
15 prepared
Unescaped Output
72
350 escaped
Nonce Checks
10
Capability Checks
19
File Operations
2
External Requests
2
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

68% prepared22 total queries

Output Escaping

83% escaped422 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
settings_tab (includes\plugin-pages.php:1682)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Integration for WooCommerce and Zoho CRM, Books, Invoice, Inventory, Bigin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 33
actionadd_meta_boxesincludes\crmperks-wc.php:10
actionsave_postincludes\plugin-pages.php:29
filterwoocommerce_settings_tabs_arrayincludes\plugin-pages.php:31
actionwoocommerce_order_refundedincludes\plugin-pages.php:35
actionwoocommerce_update_orderincludes\plugin-pages.php:40
actionadd_meta_boxesincludes\plugin-pages.php:43
actionadd_meta_boxesincludes\plugin-pages.php:44
actionadmin_noticesincludes\plugin-pages.php:46
filterpost_updated_messagesincludes\plugin-pages.php:49
actionadmin_menuincludes\plugin-pages.php:51
filteradmin_menuincludes\plugin-pages.php:54
filterplugin_action_linksincludes\plugin-pages.php:55
actionwp_trash_postincludes\plugin-pages.php:75
actionuntrash_postincludes\plugin-pages.php:76
actionwp_insert_commentincludes\plugin-pages.php:80
actiondelete_commentincludes\plugin-pages.php:81
actionplugins_loadedwoo-zoho.php:61
actionadmin_noticeswoo-zoho.php:72
actionwoocommerce_order_status_changedwoo-zoho.php:123
actionywraq_after_create_orderwoo-zoho.php:124
actionwoocommerce_subscription_status_updatedwoo-zoho.php:125
actionwoocommerce_checkout_update_order_metawoo-zoho.php:127
actionwoocommerce_new_orderwoo-zoho.php:128
actionwoocommerce_saved_order_itemswoo-zoho.php:130
actionprofile_updatewoo-zoho.php:133
actionuser_registerwoo-zoho.php:134
actionshutdownwoo-zoho.php:135
actionwoocommerce_update_productwoo-zoho.php:142
actionwoocommerce_new_productwoo-zoho.php:143
actionwoocommerce_save_product_variationwoo-zoho.php:144
actioninitwoo-zoho.php:158
actionbefore_woocommerce_initwoo-zoho.php:170
filterplugin_row_metawp\crmperks-notices.php:18
Maintenance & Trust

Integration for WooCommerce and Zoho CRM, Books, Invoice, Inventory, Bigin Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 14, 2026
PHP min version5.3
Downloads108K

Community Trust

Rating100/100
Number of ratings83
Active installs2K
Developer Profile

Integration for WooCommerce and Zoho CRM, Books, Invoice, Inventory, Bigin Developer Profile

CRM Perks

32 plugins · 105K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
349 days
View full developer profile
Detection Fingerprints

How We Detect Integration for WooCommerce and Zoho CRM, Books, Invoice, Inventory, Bigin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-zoho/assets/css/woo-zoho.css/wp-content/plugins/woo-zoho/assets/js/woo-zoho.js
Script Paths
/wp-content/plugins/woo-zoho/assets/js/woo-zoho.js
Version Parameters
woo-zoho/assets/css/woo-zoho.css?ver=woo-zoho/assets/js/woo-zoho.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- WC -->
JS Globals
woo_zoho_var
FAQ

Frequently Asked Questions about Integration for WooCommerce and Zoho CRM, Books, Invoice, Inventory, Bigin