Auction Nudge – Your eBay Listings Security & Risk Analysis

wordpress.org/plugins/auction-nudge

Display your active eBay items on your WordPress site using Auction Nudge, an approved eBay Compatible Application.

2K active installs v8.3.0 PHP 5.2+ WP 3.2+ Updated Sep 6, 2025
ebayembedfeedlistingsstore
99
A · Safe
CVEs total1
Unpatched0
Last CVEJan 24, 2025
Safety Verdict

Is Auction Nudge – Your eBay Listings Safe to Use in 2026?

Generally Safe

Score 99/100

Auction Nudge – Your eBay Listings has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 24, 2025Updated 6mo ago
Risk Assessment

The 'auction-nudge' plugin v8.3.0 exhibits a generally positive security posture with a strong emphasis on secure coding practices, particularly regarding SQL queries and output escaping. The static analysis reveals no immediately exploitable attack surface through common entry points like AJAX, REST API, or shortcodes. Furthermore, the absence of dangerous functions and external HTTP requests is commendable. However, there are areas for improvement. The presence of unsanitized paths in taint analysis, even if not resulting in critical or high severity vulnerabilities, indicates a potential for subtle security weaknesses that could be exploited in combination with other factors or in future versions. The plugin's vulnerability history, while currently showing no unpatched issues, includes a past medium-severity Cross-site Scripting (XSS) vulnerability. This suggests a need for continued vigilance in secure coding and regular security audits to prevent recurrence. Overall, the plugin is well-developed from a security perspective, but the taint analysis findings warrant attention.

Key Concerns

  • Unsanitized paths in taint analysis
  • Past medium severity XSS vulnerability
  • Zero nonce checks
Vulnerabilities
1

Auction Nudge – Your eBay Listings Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-24658medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Auction Nudge – Your eBay on Your Site <= 7.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

Jan 24, 2025 Patched in 7.2.1 (5d)
Code Analysis
Analyzed Mar 16, 2026

Auction Nudge – Your eBay Listings Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
43 escaped
Nonce Checks
0
Capability Checks
3
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

90% escaped48 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
an_options_page (inc\admin.php:244)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Auction Nudge – Your eBay Listings Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actioninitblocks\your-ebay-listings.php:62
actionadmin_head-post.phpinc\admin.php:19
actionadmin_head-post-new.phpinc\admin.php:20
actionadmin_initinc\admin.php:31
actionin_plugin_update_message-auction-nudge/auctionnudge.phpinc\admin.php:66
filterplugin_action_links_auction-nudge/auctionnudge.phpinc\admin.php:80
actionadmin_menuinc\admin.php:239
actionadmin_initinc\admin.php:465
actioninitinc\front.php:11
actionwp_headinc\front.php:101
filterquery_varsinc\front.php:116
actiontemplate_redirectinc\front.php:146
Maintenance & Trust

Auction Nudge – Your eBay Listings Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 6, 2025
PHP min version5.2
Downloads103K

Community Trust

Rating96/100
Number of ratings85
Active installs2K
Developer Profile

Auction Nudge – Your eBay Listings Developer Profile

Joe

3 plugins · 4K total installs

94
trust score
Avg Security Score
91/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Auction Nudge – Your eBay Listings

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/auction-nudge/assets/css/admin.css/wp-content/plugins/auction-nudge/assets/js/admin.js/wp-content/plugins/auction-nudge/blocks/build/index.js
Script Paths
/wp-content/plugins/auction-nudge/assets/js/admin.js/wp-content/plugins/auction-nudge/blocks/build/index.js
Version Parameters
auction-nudge/assets/css/admin.css?ver=auction-nudge/assets/js/admin.js?ver=auction-nudge/blocks/build/index.js?ver=

HTML / DOM Fingerprints

CSS Classes
an-shortcode-form-containeran-custom-field-taban-parameter-groupan-parameter-group-an-parameter-group-content
HTML Comments
<!-- END #an-shortcode-form-container -->
Data Attributes
an_actionan_request
JS Globals
an_block_js
Shortcode Output
[auction-nudge][auction-nudge
FAQ

Frequently Asked Questions about Auction Nudge – Your eBay Listings