
CedCommerce Integration for Good Market Security & Risk Analysis
wordpress.org/plugins/ced-good-market-integrationCedCommerce Integration for Good Market extension aims to help merchants automate their product, order & inventory management from a single dashboard.
Is CedCommerce Integration for Good Market Safe to Use in 2026?
Use With Caution
Score 60/100CedCommerce Integration for Good Market has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The ced-good-market-integration plugin version 1.0.6 exhibits significant security concerns, primarily stemming from a substantial attack surface with all entry points lacking authentication. The static analysis reveals 20 AJAX handlers, none of which have authorization checks, creating a wide opening for potential exploitation. While the plugin shows some positive signs, such as a high percentage of SQL queries using prepared statements and properly escaped output, these strengths are heavily overshadowed by the critical lack of access control on its AJAX endpoints.
The taint analysis did not reveal any critical or high severity unsanitized paths, which is a positive indicator. However, the presence of two flows with unsanitized paths, even if not of critical severity in this analysis, coupled with the unprotected AJAX handlers, suggests that malicious input could still be processed in an unsafe manner. The vulnerability history is particularly alarming, with one known high-severity CVE for PHP Remote File Inclusion, which is currently unpatched. This historical pattern of severe vulnerabilities, especially concerning file inclusion, indicates a recurring weakness in the plugin's code that requires immediate attention.
In conclusion, while the plugin demonstrates some good coding practices in areas like prepared statements and output escaping, the overwhelming number of unprotected AJAX endpoints and the unpatched high-severity RFI vulnerability paint a grim security picture. The plugin's overall security posture is weak due to these critical oversights. Users should exercise extreme caution and consider disabling the plugin until these vulnerabilities are addressed.
Key Concerns
- Unprotected AJAX handlers
- Unpatched high severity CVE
- Unsanitized paths in taint analysis
- No capability checks
CedCommerce Integration for Good Market Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
CedCommerce Integration for Good Market <= 1.0.6 - Unauthenticated Local File Inclusion
CedCommerce Integration for Good Market Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
CedCommerce Integration for Good Market Attack Surface
AJAX Handlers 20
WordPress Hooks 13
Scheduled Events 3
Maintenance & Trust
CedCommerce Integration for Good Market Maintenance & Trust
Maintenance Signals
Community Trust
CedCommerce Integration for Good Market Alternatives
No alternatives data available yet.
CedCommerce Integration for Good Market Developer Profile
21 plugins · 5K total installs
How We Detect CedCommerce Integration for Good Market
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ced-good-market-integration/admin/css/good_market_integration-admin.css/wp-content/plugins/ced-good-market-integration/admin/js/good_market_integration-admin.js/wp-content/plugins/ced-good-market-integration/admin/js/good_market_integration-admin.jsced-good-market-integration/admin/css/good_market_integration-admin.css?ver=ced-good-market-integration/admin/js/good_market_integration-admin.js?ver=HTML / DOM Fingerprints
ced-good-makrket-admin-notice