
AgentShop Security & Risk Analysis
wordpress.org/plugins/agentshopTrack LLM-driven traffic and optimize conversions for your WooCommerce store.
Is AgentShop Safe to Use in 2026?
Generally Safe
Score 100/100AgentShop has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The agentshop plugin version 1.0.0 demonstrates a generally strong security posture with several good practices in place. The code analysis reveals a low number of entry points into the plugin, and importantly, the vast majority of these are protected by authentication and capability checks. The plugin also utilizes prepared statements for all its SQL queries, and output escaping is consistently applied, with only a small percentage of outputs not properly escaped. The absence of any known vulnerabilities in its history further contributes to a positive security outlook.
However, there is one significant concern identified: one of the two REST API routes lacks a proper permission callback. This means that potentially any user, even those not authenticated or with limited privileges, could interact with this specific API endpoint, opening up a potential attack vector. While the taint analysis did not reveal any concerning flows, this unprotected REST API route remains a critical weakness that requires immediate attention. The plugin's strengths lie in its diligent use of prepared statements and output escaping, but the unprotected REST API endpoint introduces a notable risk that must be mitigated.
Key Concerns
- Unprotected REST API route
AgentShop Security Vulnerabilities
AgentShop Code Analysis
SQL Query Safety
Output Escaping
AgentShop Attack Surface
AJAX Handlers 4
REST API Routes 2
WordPress Hooks 35
Scheduled Events 1
Maintenance & Trust
AgentShop Maintenance & Trust
Maintenance Signals
Community Trust
AgentShop Alternatives
LLMS Central – AI Bot Tracker
llms-central-ai-bot-tracker
Track AI bots (GPT, Claude, Gemini) visiting your site and manage your llms.txt file. See which AI systems are crawling your content.
Segmentflow Connect
segmentflow-connect
Connect your WordPress website or WooCommerce store to Segmentflow for AI-powered email marketing, customer segmentation, and revenue attribution.
Senvio for WooCommerce
senvio-for-woocommerce
Lightweight tracking plugin connecting WooCommerce to Senvio.ai. First-party tracking, product/order sync. GDPR-compliant.
Klaviyo
klaviyo
Klaviyo for WooCommerce
Pixel Manager for WooCommerce – Conversion Tracking, Google Ads, GA4, TikTok, Dynamic Remarketing
woocommerce-google-adwords-conversion-tracking-tag
Conversion tracking for WooCommerce. Google Ads, GA4, Meta/Facebook Pixel, TikTok & more. Recover 30% more conversions with server-side tracking!
AgentShop Developer Profile
1 plugin · 0 total installs
How We Detect AgentShop
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/agentshop/includes/Blocks/assets/style.css/wp-content/plugins/agentshop/includes/Blocks/assets/script.js/wp-content/plugins/agentshop/assets/css/admin-style.css/wp-content/plugins/agentshop/assets/js/admin-script.js/wp-content/plugins/agentshop/assets/js/pixel.js/wp-content/plugins/agentshop/includes/Blocks/assets/script.js/wp-content/plugins/agentshop/assets/js/admin-script.js/wp-content/plugins/agentshop/assets/js/pixel.jsagentshop/assets/css/admin-style.css?ver=agentshop/assets/js/admin-script.js?ver=agentshop/assets/js/pixel.js?ver=HTML / DOM Fingerprints
agentshop-admin-settingsdata-agentshop-tracking-idagentshop_settings/wp-json/agentshop/v1/verify