AlertaPrecio Security & Risk Analysis

wordpress.org/plugins/alertaprecio

AlertaPrecio lets you add products from any website, monitor prices, and automatically enrich WooCommerce product listings with AI.

0 active installs v1.0.0 PHP 7.4+ WP 6.0+ Updated Jul 4, 2025
enrichmentprice-monitoringscraperseowoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is AlertaPrecio Safe to Use in 2026?

Generally Safe

Score 100/100

AlertaPrecio has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The alertaprecio v1.0.0 plugin demonstrates a generally good security posture, with no known vulnerabilities (CVEs) and a strong adherence to secure coding practices. The code shows a commitment to preventing SQL injection by exclusively using prepared statements and performs a high percentage of output escaping. The presence of nonce checks for all identified entry points is also a positive indicator. However, there is a notable area of concern regarding the REST API route, which lacks a permission callback, creating a potential unauthorized access point. While taint analysis did not reveal any issues, the unprotected REST API route represents a direct and accessible attack vector that could be exploited if a malicious actor can trigger it without proper authorization.

Key Concerns

  • REST API route without permission callback
Vulnerabilities
None known

AlertaPrecio Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

AlertaPrecio Release Timeline

v1.0.0Current
Code Analysis
Analyzed Mar 17, 2026

AlertaPrecio Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
19
80 escaped
Nonce Checks
14
Capability Checks
7
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

81% escaped99 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<alertaprecio> (alertaprecio.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

AlertaPrecio Attack Surface

Entry Points14
Unprotected1

AJAX Handlers 13

authwp_ajax_alertaprecio_add_productalertaprecio.php:270
authwp_ajax_alertaprecio_get_scraped_productsalertaprecio.php:338
authwp_ajax_alertaprecio_toggle_monitoringalertaprecio.php:371
authwp_ajax_alertaprecio_toggle_auto_pricealertaprecio.php:389
authwp_ajax_alertaprecio_assign_markupalertaprecio.php:410
authwp_ajax_alertaprecio_update_markupalertaprecio.php:443
authwp_ajax_alertaprecio_set_price_thresholdalertaprecio.php:457
authwp_ajax_alertaprecio_update_thresholdalertaprecio.php:466
authwp_ajax_alertaprecio_run_cron_nowalertaprecio.php:569
authwp_ajax_alertaprecio_get_price_thresholdalertaprecio.php:630
authwp_ajax_alertaprecio_update_enrichedalertaprecio.php:812
authwp_ajax_alertaprecio_update_product_pricealertaprecio.php:959
authwp_ajax_alertaprecio_logoutalertaprecio.php:1000

REST API Routes 1

GET/wp-json/alertaprecio/v1/google-callbackalertaprecio.php:578
WordPress Hooks 11
actionadmin_enqueue_scriptsalertaprecio.php:130
actionadmin_menualertaprecio.php:181
actioninitalertaprecio.php:480
actionadmin_noticesalertaprecio.php:488
actionalertaprecio_cron_check_pricesalertaprecio.php:502
actionrest_api_initalertaprecio.php:577
filterrest_pre_serve_requestalertaprecio.php:584
actionsave_post_productalertaprecio.php:774
actionmanage_product_posts_custom_columnalertaprecio.php:783
actionalertaprecio_daily_scrapealertaprecio.php:1020
actionwpalertaprecio.php:1036

Scheduled Events 1

alertaprecio_cron_check_prices
Maintenance & Trust

AlertaPrecio Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 4, 2025
PHP min version7.4
Downloads343

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

AlertaPrecio Developer Profile

Jorge Aguilera

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AlertaPrecio

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/alertaprecio/admin/styles.css/wp-content/plugins/alertaprecio/admin/general.js/wp-content/plugins/alertaprecio/assets/style.css/wp-content/plugins/alertaprecio/js/wscraper.js
Script Paths
/wp-content/plugins/alertaprecio/admin/general.js/wp-content/plugins/alertaprecio/js/wscraper.js
Version Parameters
alertaprecio-admin-stylealertaprecio-admin-jswscraper-stylewscraper-js

HTML / DOM Fingerprints

Data Attributes
data-wscraper-id
JS Globals
ALERTAPRECIO
FAQ

Frequently Asked Questions about AlertaPrecio