Integration for WooCommerce and QuickBooks Security & Risk Analysis

wordpress.org/plugins/wp-woocommerce-quickbooks

WooCommerce QuickBooks Plugin allows you to quickly integrate WooCommerce Orders with QuickBooks Online.

1K active installs v1.3.4 PHP 5.3+ WP 4.7+ Updated Dec 15, 2025
connect-woocommerce-to-quickbooksquickbooksquickbooks-online-and-woocommercewoocommerce-quickbookswoocommerce-quickbooks-integration
97
A · Safe
CVEs total3
Unpatched0
Last CVEApr 16, 2025
Safety Verdict

Is Integration for WooCommerce and QuickBooks Safe to Use in 2026?

Generally Safe

Score 97/100

Integration for WooCommerce and QuickBooks has a strong security track record. Known vulnerabilities have been patched promptly.

3 known CVEsLast CVE: Apr 16, 2025Updated 3mo ago
Risk Assessment

The "wp-woocommerce-quickbooks" v1.3.4 plugin exhibits a mixed security posture. On one hand, the static analysis reveals a strong foundation with a complete absence of identified entry points without authentication, no dangerous functions, and a good rate of SQL prepared statements and output escaping. The presence of nonce and capability checks further indicates an effort to implement secure coding practices. However, the vulnerability history is a significant concern. Three medium-severity vulnerabilities, including CSRF, Open Redirect, and XSS, have been documented. While none are currently unpatched, the pattern of past vulnerabilities suggests potential recurring issues in input validation or authorization, despite the static analysis not flagging any critical taint flows or unsanitized paths in this specific version.

Despite the clean slate in this version's static analysis, the historical prevalence of medium-severity vulnerabilities is a red flag. The types of past issues (CSRF, Open Redirect, XSS) are often related to how user input is handled and processed. Although the current analysis shows good escaping and prepared statements, and no immediate critical taint issues, the plugin's past suggests a need for continued vigilance and potentially deeper code review for subtle vulnerabilities. The presence of bundled libraries (Select2) also warrants attention, as outdated versions of bundled libraries can introduce vulnerabilities, though no specific issues are highlighted here. The limited file operations and external HTTP requests are positive indicators, but the overall risk is elevated by the historical vulnerability profile.

Key Concerns

  • Three past medium-severity CVEs found
  • Bundled library (Select2) present
Vulnerabilities
3

Integration for WooCommerce and QuickBooks Security Vulnerabilities

CVEs by Year

1 CVE in 2021
2021
1 CVE in 2023
2023
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2025-39600medium · 4.3Cross-Site Request Forgery (CSRF)

Integration for WooCommerce and QuickBooks <= 1.3.1 - Cross-Site Request Forgery

Apr 16, 2025 Patched in 1.3.2 (6d)
CVE-2023-38478medium · 4.3URL Redirection to Untrusted Site ('Open Redirect')

Integration for WooCommerce and QuickBooks <= 1.2.3 - Open Redirect via setup_plugin

Jul 20, 2023 Patched in 1.2.4 (187d)
WF-cc1e9778-2860-4e3c-a2e4-28f10d585fed-wp-woocommerce-quickbooksmedium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CRM Perks - Various Plugins (Various Versions) - Reflected Cross-Site Scripting

Aug 26, 2021 Patched in 1.1.9 (880d)
Code Analysis
Analyzed Mar 16, 2026

Integration for WooCommerce and QuickBooks Code Analysis

Dangerous Functions
0
Raw SQL Queries
7
13 prepared
Unescaped Output
95
326 escaped
Nonce Checks
10
Capability Checks
19
File Operations
1
External Requests
2
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

65% prepared20 total queries

Output Escaping

77% escaped421 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
settings_tab (includes\plugin-pages.php:1564)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Integration for WooCommerce and QuickBooks Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 29
actionadd_meta_boxesincludes\crmperks-wc.php:8
actionsave_postincludes\plugin-pages.php:28
filterwoocommerce_settings_tabs_arrayincludes\plugin-pages.php:30
actionwoocommerce_update_orderincludes\plugin-pages.php:37
actionwoocommerce_order_refundedincludes\plugin-pages.php:39
actionadd_meta_boxesincludes\plugin-pages.php:42
actionadd_meta_boxesincludes\plugin-pages.php:43
actionadmin_noticesincludes\plugin-pages.php:45
filterpost_updated_messagesincludes\plugin-pages.php:48
actionadmin_menuincludes\plugin-pages.php:50
filteradmin_menuincludes\plugin-pages.php:52
filterplugin_action_linksincludes\plugin-pages.php:53
actionwp_trash_postincludes\plugin-pages.php:74
actionuntrash_postincludes\plugin-pages.php:75
actionwp_insert_commentincludes\plugin-pages.php:79
actiontrash_commentincludes\plugin-pages.php:80
actionadmin_noticeswp\crmperks-notices.php:15
actionmanage_posts_extra_tablenavwp\crmperks-notices.php:16
filterplugin_row_metawp\crmperks-notices.php:20
actionplugins_loadedwp-woocommerce-quickbooks.php:55
actionadmin_noticeswp-woocommerce-quickbooks.php:68
actionwoocommerce_order_status_changedwp-woocommerce-quickbooks.php:92
actionwoocommerce_subscription_status_updatedwp-woocommerce-quickbooks.php:93
actionwoocommerce_checkout_update_order_metawp-woocommerce-quickbooks.php:94
actionwoocommerce_new_orderwp-woocommerce-quickbooks.php:95
actionprofile_updatewp-woocommerce-quickbooks.php:96
actionsave_post_productwp-woocommerce-quickbooks.php:97
actioninitwp-woocommerce-quickbooks.php:106
actionbefore_woocommerce_initwp-woocommerce-quickbooks.php:114
Maintenance & Trust

Integration for WooCommerce and QuickBooks Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 15, 2025
PHP min version5.3
Downloads42K

Community Trust

Rating98/100
Number of ratings15
Active installs1K
Developer Profile

Integration for WooCommerce and QuickBooks Developer Profile

CRM Perks

32 plugins · 105K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
349 days
View full developer profile
Detection Fingerprints

How We Detect Integration for WooCommerce and QuickBooks

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-woocommerce-quickbooks/css/admin.css/wp-content/plugins/wp-woocommerce-quickbooks/css/frontend.css/wp-content/plugins/wp-woocommerce-quickbooks/js/admin.js/wp-content/plugins/wp-woocommerce-quickbooks/js/frontend.js
Script Paths
/wp-content/plugins/wp-woocommerce-quickbooks/js/admin.js/wp-content/plugins/wp-woocommerce-quickbooks/js/frontend.js
Version Parameters
wp-woocommerce-quickbooks/css/admin.css?ver=wp-woocommerce-quickbooks/css/frontend.css?ver=wp-woocommerce-quickbooks/js/admin.js?ver=wp-woocommerce-quickbooks/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
vxc-qbooks-field
HTML Comments
CRM PERKSThis plugin is free for CRM PerksQuickBooks IntegrationThis is a free plugin. For premium features+1 more
Data Attributes
data-crmperks-plugin-namedata-crmperks-plugin-version
JS Globals
vxc_qbooks_adminvxc_qbooks_frontend
FAQ

Frequently Asked Questions about Integration for WooCommerce and QuickBooks