Amazon Product Feeder Security & Risk Analysis

wordpress.org/plugins/amazon-product-feeder

Amazon Product Feeder is a WordPress plugin which will help you to create amazon product pages on your website with your amazon affiliate link.

40 active installs v1.2 PHP + WP 2.8+ Updated Oct 29, 2014
affiliateamazonassociateebaymoney
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Amazon Product Feeder Safe to Use in 2026?

Generally Safe

Score 85/100

Amazon Product Feeder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The amazon-product-feeder plugin version 1.2 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, unescaped output, file operations, and external HTTP requests, coupled with 100% use of prepared statements for SQL and proper output escaping, indicates good development practices. Furthermore, the lack of any recorded vulnerabilities in its history suggests a mature and well-maintained codebase, or at least one that has not been a target or revealed exploitable flaws.

However, a significant concern arises from the complete absence of nonce checks and capability checks across all entry points. While the static analysis reports 0 unprotected entry points, this is likely due to the fact that the single shortcode does not appear to have any explicit authorization mechanisms in place, which is a critical oversight. Taint analysis also reveals no identified flows, which is positive, but doesn't negate the risk posed by the missing authorization checks on the shortcode.

In conclusion, while the plugin demonstrates strong defensive coding in several key areas and has no known vulnerabilities, the complete omission of nonce and capability checks on its sole shortcode presents a notable security weakness. This could potentially lead to unauthorized execution of shortcode functionality if the context allows, even if it doesn't directly involve sensitive data manipulation or privilege escalation based on the provided analysis.

Key Concerns

  • Missing nonce check on shortcode
  • Missing capability check on shortcode
Vulnerabilities
None known

Amazon Product Feeder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Amazon Product Feeder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Amazon Product Feeder Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[apf] amazon-product-feeder.php:122
WordPress Hooks 1
filterplugin_row_metaamazon-product-feeder.php:142
Maintenance & Trust

Amazon Product Feeder Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedOct 29, 2014
PHP min version
Downloads14K

Community Trust

Rating52/100
Number of ratings10
Active installs40
Developer Profile

Amazon Product Feeder Developer Profile

Susanta K Beura

2 plugins · 240 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Amazon Product Feeder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/amazon-product-feeder/css/apf.css/wp-content/plugins/amazon-product-feeder/js/apf.js
Script Paths
/wp-content/plugins/amazon-product-feeder/js/apf.js

HTML / DOM Fingerprints

CSS Classes
rss_excerpttgRssReviewstgProductPriceLine
Data Attributes
itemscopeitemtypeitemprop
JS Globals
SimplePieWP_SimplePie_Sanitize_KSESWP_Feed_CacheWP_SimplePie_Filewp_feed_cache_transient_lifetimewp_feed_options
Shortcode Output
[apf]
FAQ

Frequently Asked Questions about Amazon Product Feeder