CedCommerce Integration for Good Market Security & Risk Analysis

wordpress.org/plugins/ced-good-market-integration

CedCommerce Integration for Good Market extension aims to help merchants automate their product, order & inventory management from a single dashboard.

60 active installs v1.0.6 PHP 7.0+ WP 4.0+ Updated Apr 15, 2023
cedcommerce-integration-for-good-marketgood-marketgood-market-integrationgood-market-integration-for-woocommerce
60
C · Use Caution
CVEs total1
Unpatched1
Last CVEDec 26, 2025
Safety Verdict

Is CedCommerce Integration for Good Market Safe to Use in 2026?

Use With Caution

Score 60/100

CedCommerce Integration for Good Market has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Dec 26, 2025Updated 2yr ago
Risk Assessment

The ced-good-market-integration plugin version 1.0.6 exhibits significant security concerns, primarily stemming from a substantial attack surface with all entry points lacking authentication. The static analysis reveals 20 AJAX handlers, none of which have authorization checks, creating a wide opening for potential exploitation. While the plugin shows some positive signs, such as a high percentage of SQL queries using prepared statements and properly escaped output, these strengths are heavily overshadowed by the critical lack of access control on its AJAX endpoints.

The taint analysis did not reveal any critical or high severity unsanitized paths, which is a positive indicator. However, the presence of two flows with unsanitized paths, even if not of critical severity in this analysis, coupled with the unprotected AJAX handlers, suggests that malicious input could still be processed in an unsafe manner. The vulnerability history is particularly alarming, with one known high-severity CVE for PHP Remote File Inclusion, which is currently unpatched. This historical pattern of severe vulnerabilities, especially concerning file inclusion, indicates a recurring weakness in the plugin's code that requires immediate attention.

In conclusion, while the plugin demonstrates some good coding practices in areas like prepared statements and output escaping, the overwhelming number of unprotected AJAX endpoints and the unpatched high-severity RFI vulnerability paint a grim security picture. The plugin's overall security posture is weak due to these critical oversights. Users should exercise extreme caution and consider disabling the plugin until these vulnerabilities are addressed.

Key Concerns

  • Unprotected AJAX handlers
  • Unpatched high severity CVE
  • Unsanitized paths in taint analysis
  • No capability checks
Vulnerabilities
1

CedCommerce Integration for Good Market Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2025-68877high · 8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

CedCommerce Integration for Good Market <= 1.0.6 - Unauthenticated Local File Inclusion

Dec 26, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

CedCommerce Integration for Good Market Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
7 prepared
Unescaped Output
43
343 escaped
Nonce Checks
22
Capability Checks
0
File Operations
4
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

78% prepared9 total queries

Output Escaping

89% escaped386 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

10 flows2 with unsanitized paths
<good_market_profile-edit> (admin\partials\good_market_profile-edit.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
20 unprotected

CedCommerce Integration for Good Market Attack Surface

Entry Points20
Unprotected20

AJAX Handlers 20

authwp_ajax_ced_good_market_process_api_keysincludes\class-good_market_integration.php:148
authwp_ajax_ced_good_market_search_product_nameincludes\class-good_market_integration.php:149
authwp_ajax_ced_good_market_get_product_metakeysincludes\class-good_market_integration.php:150
authwp_ajax_ced_good_market_process_metakeysincludes\class-good_market_integration.php:151
authwp_ajax_ced_good_market_get_orders_manualincludes\class-good_market_integration.php:152
authwp_ajax_ced_good_market_process_bulk_actionincludes\class-good_market_integration.php:153
authwp_ajax_ced_good_market_save_catincludes\class-good_market_integration.php:154
authwp_ajax_ced_good_market_ship_orderincludes\class-good_market_integration.php:155
authwp_ajax_ced_good_market_update_categoriesincludes\class-good_market_integration.php:156
authwp_ajax_ced_good_market_list_per_pageincludes\class-good_market_integration.php:160
authwp_ajax_ced_gm_inventory_schedule_managerincludes\class-good_market_integration.php:161
noprivwp_ajax_ced_gm_inventory_schedule_managerincludes\class-good_market_integration.php:162
authwp_ajax_sync_good_market_productsincludes\class-good_market_integration.php:163
noprivwp_ajax_sync_good_market_productsincludes\class-good_market_integration.php:164
authwp_ajax_sync_good_market_feedsincludes\class-good_market_integration.php:165
noprivwp_ajax_sync_good_market_feedsincludes\class-good_market_integration.php:166
authwp_ajax_ced_good_market_auto_inventory_syncincludes\class-good_market_integration.php:167
noprivwp_ajax_ced_good_market_auto_inventory_syncincludes\class-good_market_integration.php:168
authwp_ajax_ced_good_market_auto_fetch_ordersincludes\class-good_market_integration.php:170
noprivwp_ajax_ced_good_market_auto_fetch_ordersincludes\class-good_market_integration.php:171
WordPress Hooks 13
actionadmin_noticesced_good_market_integration.php:94
actionadmin_noticesced_good_market_integration.php:141
actionadmin_initced_good_market_integration.php:143
actionplugins_loadedincludes\class-good_market_integration.php:131
actionadmin_enqueue_scriptsincludes\class-good_market_integration.php:145
actionadmin_enqueue_scriptsincludes\class-good_market_integration.php:146
actionadmin_menuincludes\class-good_market_integration.php:147
filtercron_schedulesincludes\class-good_market_integration.php:157
filterced_good_market_auto_fetch_ordersincludes\class-good_market_integration.php:158
filterced_good_market_auto_inventory_syncincludes\class-good_market_integration.php:159
filtersync_good_market_feedsincludes\class-good_market_integration.php:169
actionupdated_post_metaincludes\class-good_market_integration.php:172
filterwoocommerce_duplicate_product_exclude_metaincludes\class-good_market_integration.php:173

Scheduled Events 3

ced_good_market_auto_fetch_orders
ced_good_market_auto_inventory_sync
sync_good_market_feeds
Maintenance & Trust

CedCommerce Integration for Good Market Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedApr 15, 2023
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs60
Alternatives

CedCommerce Integration for Good Market Alternatives

No alternatives data available yet.

Developer Profile

CedCommerce Integration for Good Market Developer Profile

cedcommerce

21 plugins · 5K total installs

67
trust score
Avg Security Score
83/100
Avg Patch Time
204 days
View full developer profile
Detection Fingerprints

How We Detect CedCommerce Integration for Good Market

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ced-good-market-integration/admin/css/good_market_integration-admin.css/wp-content/plugins/ced-good-market-integration/admin/js/good_market_integration-admin.js
Script Paths
/wp-content/plugins/ced-good-market-integration/admin/js/good_market_integration-admin.js
Version Parameters
ced-good-market-integration/admin/css/good_market_integration-admin.css?ver=ced-good-market-integration/admin/js/good_market_integration-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
ced-good-makrket-admin-notice
FAQ

Frequently Asked Questions about CedCommerce Integration for Good Market