Cherry Picker Security & Risk Analysis

wordpress.org/plugins/cherry-picker

Cherry Picker is a versatile content grabber designed to effortlessly copy content from any eCommerce website and integrate it directly into your WooC …

100 active installs v1.2.4 PHP 7.0+ WP 4.7+ Updated Feb 7, 2024
dropshippingparserscraperwoowoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Cherry Picker Safe to Use in 2026?

Generally Safe

Score 85/100

Cherry Picker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The static analysis of 'cherry-picker' v1.2.4 indicates a strong security posture with no identified vulnerabilities in the provided code signals or taint analysis. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and a high percentage of properly escaped output are positive indicators. Furthermore, the plugin demonstrates good practice by not performing file operations or external HTTP requests, and it has no recorded vulnerability history, suggesting a well-maintained and secure codebase. The lack of exposed attack surface points, such as unprotected AJAX handlers, REST API routes, or shortcodes, further reinforces its secure design.

However, the analysis also highlights some areas for attention. The complete absence of nonce checks and capability checks is a significant concern. While the current attack surface might be zero, any future addition of functionality, especially AJAX handlers or REST API endpoints, without these fundamental security checks would expose the plugin to severe risks like Cross-Site Request Forgery (CSRF) and unauthorized actions. The fact that there are no capability checks means that even if entry points were present, they would likely be accessible to any logged-in user, regardless of their role or permissions. This lack of built-in authorization mechanisms is a notable weakness that needs to be addressed to ensure robust security moving forward.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Cherry Picker Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Cherry Picker Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
19 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

90% escaped21 total outputs
Attack Surface

Cherry Picker Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionplugins_loadedincludes\class-cherry-picker.php:143
actionadmin_enqueue_scriptsincludes\class-cherry-picker.php:159
actionadmin_enqueue_scriptsincludes\class-cherry-picker.php:160
actionadmin_menuincludes\class-cherry-picker.php:161
actionadmin_post_nopriv_handle_cherry_picker_postincludes\class-cherry-picker.php:162
actionadmin_post_handle_cherry_picker_postincludes\class-cherry-picker.php:163
actionadmin_post_nopriv_handle_cherry_picker_product_createincludes\class-cherry-picker.php:164
actionadmin_post_handle_cherry_picker_product_createincludes\class-cherry-picker.php:165
actionadmin_initincludes\class-cherry-picker.php:166
actionwp_enqueue_scriptsincludes\class-cherry-picker.php:173
actionwp_enqueue_scriptsincludes\class-cherry-picker.php:174
actioncp_gateway_viewincludes\class-cherry-picker.php:175
Maintenance & Trust

Cherry Picker Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedFeb 7, 2024
PHP min version7.0
Downloads7K

Community Trust

Rating86/100
Number of ratings3
Active installs100
Developer Profile

Cherry Picker Developer Profile

mosquid

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Cherry Picker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cherry-picker/public/css/cherry-picker-public.css/wp-content/plugins/cherry-picker/public/js/cherry-picker-public.js/wp-content/plugins/cherry-picker/admin/css/cherry-picker-admin.css/wp-content/plugins/cherry-picker/admin/js/cherry-picker-admin.js
Script Paths
/wp-content/plugins/cherry-picker/public/js/bundle.js
Version Parameters
cherry-picker-admin.css?ver=cherry-picker-public.css?ver=cherry-picker-admin.js?ver=cherry-picker-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
cherry-picker-admin-display
Data Attributes
id="cherryPicker-bookmark"draggable=true
JS Globals
window.cherryPickerSubmitUrlwindow.adapterUrl
FAQ

Frequently Asked Questions about Cherry Picker