WSB HUB3 Security & Risk Analysis

wordpress.org/plugins/wsb-hub3

HUB3 payment details for Direct bank transfers (Croatian banks only) with barcode for mobile banking.

1K active installs v3.0.2 PHP 7.4+ WP 5.0+ Updated Apr 18, 2025
barcodehub3uplatnicawoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WSB HUB3 Safe to Use in 2026?

Generally Safe

Score 100/100

WSB HUB3 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The wsb-hub3 plugin v3.0.2 demonstrates a generally strong security posture based on the provided static analysis. The absence of critical code signals like dangerous functions, raw SQL queries, and unsanitized taint flows is a significant strength. Furthermore, the plugin utilizes prepared statements for all SQL queries and appears to have a high percentage of properly escaped output, indicating good defensive programming practices.

However, several areas raise concerns. The complete lack of nonce checks and capability checks across all entry points is a critical oversight. While the attack surface is small (two shortcodes) and currently has no unprotected AJAX or REST API routes, this lack of fundamental security mechanisms leaves it vulnerable to CSRF attacks and unauthorized access if the attack surface were to expand or be misused in the future. The presence of file operations and an external HTTP request, while not inherently dangerous, warrants careful monitoring as these can sometimes be vectors for exploitation if not handled securely.

The plugin's vulnerability history is clean, with no recorded CVEs. This is a positive indicator, suggesting the developers have a good track record or have not yet been a target for significant exploits. However, it's crucial to remember that a clean history doesn't guarantee future security, especially given the identified gaps in nonce and capability checks. Overall, the plugin has good fundamentals in data handling but suffers from a lack of essential authentication and authorization checks, which is a significant security risk.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • File operations present
  • External HTTP requests present
Vulnerabilities
None known

WSB HUB3 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WSB HUB3 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
107 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
1
Bundled Libraries
0

Output Escaping

86% escaped124 total outputs
Attack Surface

WSB HUB3 Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[wsb_hub3] includes\class-wsb-hub3-shortcodes.php:28
[wsb_barcode] includes\class-wsb-hub3-shortcodes.php:29
WordPress Hooks 19
actionplugins_loadedincludes\class-wsb-hub3.php:132
actionadmin_enqueue_scriptsincludes\class-wsb-hub3.php:147
actionadmin_enqueue_scriptsincludes\class-wsb-hub3.php:148
filterwoocommerce_settings_tabs_arrayincludes\class-wsb-hub3.php:149
actionwoocommerce_sections_wsb_hub3_admin_tabincludes\class-wsb-hub3.php:150
actionwoocommerce_settings_wsb_hub3_admin_tabincludes\class-wsb-hub3.php:151
actionwoocommerce_settings_save_wsb_hub3_admin_tabincludes\class-wsb-hub3.php:152
actionadmin_noticesincludes\class-wsb-hub3.php:153
actionwp_enqueue_scriptsincludes\class-wsb-hub3.php:169
actionwp_enqueue_scriptsincludes\class-wsb-hub3.php:170
actionwoocommerce_checkout_update_order_metaincludes\class-wsb-hub3.php:171
actionwoocommerce_view_orderincludes\class-wsb-hub3.php:172
actionwoocommerce_thankyouincludes\class-wsb-hub3.php:173
actionwoocommerce_email_after_order_tableincludes\class-wsb-hub3.php:174
actionwoocommerce_update_orderincludes\class-wsb-hub3.php:175
filterwoocommerce_gateway_descriptionincludes\class-wsb-hub3.php:176
filterwoocommerce_bacs_account_fieldsincludes\class-wsb-hub3.php:177
actionadmin_noticeswsb-hub3.php:61
actionbefore_woocommerce_initwsb-hub3.php:67
Maintenance & Trust

WSB HUB3 Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 18, 2025
PHP min version7.4
Downloads11K

Community Trust

Rating100/100
Number of ratings20
Active installs1K
Developer Profile

WSB HUB3 Developer Profile

Branko

3 plugins · 1K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
314 days
View full developer profile
Detection Fingerprints

How We Detect WSB HUB3

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wsb-hub3/admin/css/wsb-hub3-admin.css/wp-content/plugins/wsb-hub3/admin/js/wsb-hub3-admin.js
Script Paths
/wp-content/plugins/wsb-hub3/admin/js/wsb-hub3-admin.js
Version Parameters
wsb-hub3-admin.css?ver=wsb-hub3-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wsb-hub3-options-title
Data Attributes
id="wc_wsb_hub3_admin_tab_section_general_settings_title"
FAQ

Frequently Asked Questions about WSB HUB3