Amazing Fulfillment Integration for WooCommerce Security & Risk Analysis

wordpress.org/plugins/amazing-fullfilment-integration-for-woocommerce

An easy to use plugin that lets you send WooCommerce Orders to multichannel fulfillment by Amazon

10 active installs v2.1 PHP + WP 4.2+ Updated May 31, 2019
amazonfbafulfillmentmultichannelwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Amazing Fulfillment Integration for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Amazing Fulfillment Integration for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

This plugin exhibits a concerning security posture due to significant vulnerabilities in its entry points. The static analysis reveals a total of 2 AJAX handlers, and alarmingly, both of these lack authentication checks. This creates a wide-open attack surface for malicious actors to exploit. Furthermore, the output escaping is severely lacking, with only 12% of outputs properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities.

The taint analysis, while limited in scope with only 2 flows analyzed, did identify both flows with unsanitized paths. Although these did not escalate to critical or high severity in this specific analysis, the presence of unsanitized paths in conjunction with unprotected AJAX endpoints is a significant red flag. The absence of any nonce checks or capability checks further compounds these issues, providing no built-in protection against common WordPress attack vectors.

Despite the lack of recorded CVEs, this does not automatically imply the plugin is secure. It could indicate a lack of thorough past security audits or that vulnerabilities have simply not been discovered or disclosed yet. The strengths of the plugin lie in its limited use of dangerous functions and a majority of SQL queries utilizing prepared statements. However, these positive aspects are heavily overshadowed by the critical lack of security controls on its primary entry points and the prevalence of unescaped output, making this plugin a high-risk addition to any WordPress site.

Key Concerns

  • Unprotected AJAX handlers
  • Poor output escaping
  • Flows with unsanitized paths
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Amazing Fulfillment Integration for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Amazing Fulfillment Integration for WooCommerce Release Timeline

v2.1Current
v2.0
v1.1.3
v1.1.2
v1.1.1
v1.1.0
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

Amazing Fulfillment Integration for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
20
47 prepared
Unescaped Output
78
11 escaped
Nonce Checks
0
Capability Checks
0
File Operations
12
External Requests
4
Bundled Libraries
0

SQL Query Safety

70% prepared67 total queries

Output Escaping

12% escaped89 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
<LicenseDisplay> (AmzFulfillment\Template\LicenseDisplay.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Amazing Fulfillment Integration for WooCommerce Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_amzFulfillmentFulfillmentsAmzFulfillment\Main.php:47
authwp_ajax_amzFulfillmentLogsAmzFulfillment\Main.php:48
WordPress Hooks 17
actionadmin_menuAmzFulfillment\Main.php:39
actionadmin_enqueue_scriptsAmzFulfillment\Main.php:40
actionadmin_noticesAmzFulfillment\Main.php:41
actionadmin_noticesAmzFulfillment\Main.php:42
filtercron_schedulesAmzFulfillment\Main.php:43
actionwoocommerce_order_status_changedAmzFulfillment\Main.php:45
filterwoocommerce_email_classesAmzFulfillment\Main.php:46
actionwoocommerce_order_actionsAmzFulfillment\WooCommerce\Panel.php:13
actionwoocommerce_order_action_create_amazon_fulfillmentAmzFulfillment\WooCommerce\Panel.php:14
actionwoocommerce_order_action_cancel_amazon_fulfillmentAmzFulfillment\WooCommerce\Panel.php:15
actionadmin_footer-edit.phpAmzFulfillment\WooCommerce\Panel.php:16
actionload-edit.phpAmzFulfillment\WooCommerce\Panel.php:17
actionadd_meta_boxesAmzFulfillment\WooCommerce\Panel.php:18
filtermanage_edit-shop_order_columnsAmzFulfillment\WooCommerce\Panel.php:19
actionmanage_shop_order_posts_custom_columnAmzFulfillment\WooCommerce\Panel.php:20
actionplugins_loadedamzFulfillment.php:51
actionadmin_noticesamzFulfillment.php:124
Maintenance & Trust

Amazing Fulfillment Integration for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedMay 31, 2019
PHP min version
Downloads4K

Community Trust

Rating68/100
Number of ratings5
Active installs10
Developer Profile

Amazing Fulfillment Integration for WooCommerce Developer Profile

denny1989

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Amazing Fulfillment Integration for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/amazing-fullfilment-integration-for-woocommerce/assets/css/amzFulfillment.css/wp-content/plugins/amazing-fullfilment-integration-for-woocommerce/assets/js/amzFulfillment.js/wp-content/plugins/amazing-fullfilment-integration-for-woocommerce/assets/js/amzFulfillmentData.js
Script Paths
/wp-content/plugins/amazing-fullfilment-integration-for-woocommerce/assets/js/amzFulfillment.js/wp-content/plugins/amazing-fullfilment-integration-for-woocommerce/assets/js/amzFulfillmentData.js

HTML / DOM Fingerprints

CSS Classes
amzFulfillment
Data Attributes
data-tabid
JS Globals
amzFulfillmentLogs
FAQ

Frequently Asked Questions about Amazing Fulfillment Integration for WooCommerce