Integration for HubSpot and WooCommerce Security & Risk Analysis

wordpress.org/plugins/wp-hubspot-woocommerce

HubSpot WooCommerce Plugin allows you to quickly integrate WooCommerce Orders with HubSpot.

100 active installs v1.2.1 PHP 5.3+ WP 3.8+ Updated Dec 15, 2025
hubspothubspot-and-woocommercehubspot-and-woocommerce-integrationhubspot-crm-woocommercehubspot-woocommerce-plugin
100
A · Safe
CVEs total1
Unpatched0
Last CVEAug 26, 2021
Safety Verdict

Is Integration for HubSpot and WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Integration for HubSpot and WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Aug 26, 2021Updated 3mo ago
Risk Assessment

The "wp-hubspot-woocommerce" v1.2.1 plugin exhibits a generally good security posture based on the static analysis. The absence of any unprotected AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the attack surface. The code also demonstrates a strong commitment to security with a high percentage of SQL queries using prepared statements and a significant portion of outputs being properly escaped. Nonce and capability checks are also implemented, further bolstering its defenses.

However, the plugin is not without its concerns. The presence of a past medium severity Cross-Site Scripting (XSS) vulnerability, though currently patched, indicates a potential weakness in input sanitization or output escaping that has historically existed. While the taint analysis shows no unsanitized paths in this version, the past vulnerability history warrants vigilance. The plugin also performs two external HTTP requests and two file operations, which, while not inherently insecure, represent potential vectors for attack if not handled with extreme care and proper validation.

In conclusion, the current version of "wp-hubspot-woocommerce" appears to be reasonably secure with solid foundational security practices. The limited attack surface and strong use of prepared statements and output escaping are positive indicators. Nevertheless, the historical medium-severity XSS vulnerability should not be entirely dismissed, suggesting that ongoing monitoring and code reviews remain important for maintaining a robust security posture.

Key Concerns

  • Past medium severity XSS vulnerability
  • External HTTP requests present
  • File operations present
Vulnerabilities
1

Integration for HubSpot and WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2021
2021
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

WF-cc1e9778-2860-4e3c-a2e4-28f10d585fed-wp-hubspot-woocommercemedium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CRM Perks - Various Plugins (Various Versions) - Reflected Cross-Site Scripting

Aug 26, 2021 Patched in 1.0.5 (880d)
Code Analysis
Analyzed Mar 16, 2026

Integration for HubSpot and WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
7
15 prepared
Unescaped Output
60
338 escaped
Nonce Checks
10
Capability Checks
19
File Operations
2
External Requests
2
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

68% prepared22 total queries

Output Escaping

85% escaped398 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
settings_tab (includes\plugin-pages.php:1626)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Integration for HubSpot and WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 33
actionadd_meta_boxesincludes\crmperks-wc.php:8
actionsave_postincludes\plugin-pages.php:28
filterwoocommerce_settings_tabs_arrayincludes\plugin-pages.php:30
actionwoocommerce_update_orderincludes\plugin-pages.php:36
actionadd_meta_boxesincludes\plugin-pages.php:39
actionadd_meta_boxesincludes\plugin-pages.php:40
actionadmin_noticesincludes\plugin-pages.php:42
filterpost_updated_messagesincludes\plugin-pages.php:45
actionadmin_menuincludes\plugin-pages.php:47
filteradmin_menuincludes\plugin-pages.php:50
filterplugin_action_linksincludes\plugin-pages.php:51
actionwp_trash_postincludes\plugin-pages.php:71
actionuntrash_postincludes\plugin-pages.php:72
actionwp_insert_commentincludes\plugin-pages.php:76
actiontrash_commentincludes\plugin-pages.php:77
actionmanage_posts_extra_tablenavwp\crmperks-notices.php:16
filterplugin_row_metawp\crmperks-notices.php:20
actionplugins_loadedwp-hubspot-woocommerce.php:60
actionadmin_noticeswp-hubspot-woocommerce.php:73
actionwoocommerce_order_status_changedwp-hubspot-woocommerce.php:99
actionywraq_after_create_orderwp-hubspot-woocommerce.php:100
actionwoocommerce_subscription_status_updatedwp-hubspot-woocommerce.php:101
actionwoocommerce_checkout_update_order_metawp-hubspot-woocommerce.php:103
actionwoocommerce_new_orderwp-hubspot-woocommerce.php:105
actionprofile_updatewp-hubspot-woocommerce.php:108
actionuser_registerwp-hubspot-woocommerce.php:109
actionshutdownwp-hubspot-woocommerce.php:110
actionwoocommerce_saved_order_itemswp-hubspot-woocommerce.php:115
actionwoocommerce_update_productwp-hubspot-woocommerce.php:119
actionwoocommerce_new_productwp-hubspot-woocommerce.php:120
actionwoocommerce_save_product_variationwp-hubspot-woocommerce.php:121
actioninitwp-hubspot-woocommerce.php:126
actionbefore_woocommerce_initwp-hubspot-woocommerce.php:137
Maintenance & Trust

Integration for HubSpot and WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 15, 2025
PHP min version5.3
Downloads10K

Community Trust

Rating100/100
Number of ratings4
Active installs100
Developer Profile

Integration for HubSpot and WooCommerce Developer Profile

CRM Perks

32 plugins · 105K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
349 days
View full developer profile
Detection Fingerprints

How We Detect Integration for HubSpot and WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-hubspot-woocommerce/css/admin-style.css/wp-content/plugins/wp-hubspot-woocommerce/css/backend.css/wp-content/plugins/wp-hubspot-woocommerce/js/backend.js/wp-content/plugins/wp-hubspot-woocommerce/js/frontend.js
Version Parameters
wp-hubspot-woocommerce/css/admin-style.css?ver=wp-hubspot-woocommerce/css/backend.css?ver=wp-hubspot-woocommerce/js/backend.js?ver=wp-hubspot-woocommerce/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
wp_hubspot_woocommercewp-hubspot-woocommerce-notice
HTML Comments
<!-- Plugin Name: Integration for HubSpot and WooCommerce --><!-- Description: Integrates WooCommerce with HubSpot allowing new orders to be automatically sent to your HubSpot account. --><!-- Version: 1.2.1 --><!-- Requires at least: 3.8 -->+7 more
Data Attributes
data-crmperks-plugin-id="vxc_hubspot"data-crmperks-plugin-version="1.2.1"
JS Globals
window.vxc_hubspot_pro_config
FAQ

Frequently Asked Questions about Integration for HubSpot and WooCommerce