
Datafeedr API Security & Risk Analysis
wordpress.org/plugins/datafeedr-apiConnect to the Datafeedr API.
Is Datafeedr API Safe to Use in 2026?
Generally Safe
Score 100/100Datafeedr API has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The datafeedr-api plugin version 1.3.25 exhibits a mixed security posture. On the positive side, it has a clean vulnerability history with no known CVEs recorded, which suggests a history of relatively secure development or prompt patching. The plugin also shows a good number of capability checks and a reasonable amount of output escaping, indicating some adherence to WordPress security best practices. However, there are significant areas of concern. The presence of the `unserialize` function is a critical risk, as it can lead to object injection vulnerabilities if not handled with extreme care, especially with user-controlled input. Furthermore, the static analysis reveals one AJAX handler without authentication checks, creating a direct entry point for potential attacks. The fact that 100% of its SQL queries are not using prepared statements is a major red flag, increasing the risk of SQL injection vulnerabilities, especially when combined with other potential weaknesses. While taint analysis did not reveal critical flows, the combination of these factors presents a tangible risk.
Key Concerns
- Unprotected AJAX handler
- SQL queries without prepared statements
- Dangerous function 'unserialize' used
- Low output escaping percentage
Datafeedr API Security Vulnerabilities
Datafeedr API Release Timeline
Datafeedr API Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Datafeedr API Attack Surface
AJAX Handlers 3
WordPress Hooks 59
Maintenance & Trust
Datafeedr API Maintenance & Trust
Maintenance Signals
Community Trust
Datafeedr API Alternatives
Datafeedr Product Sets
datafeedr-product-sets
Build sets of products to import into your website.
Datafeedr WooCommerce Importer
datafeedr-woocommerce-importer
Import products from the Datafeedr API into your WooCommerce store.
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets
wp-all-import
Easily import any file of any size into any plugin, post type, custom field, or taxonomy. Supports WooCommerce, ACF, images, galleries, users, real es …
Import Users from CSV
import-users-from-csv
Import users from a CSV into WordPress
Import WP – Export and Import CSV and XML files to WordPress
jc-importer
Import WP, a simple, fast and powerful XML and CSV import solution, Making it easy to import posts, pages, categories, tags, users and attachments.
Datafeedr API Developer Profile
6 plugins · 23K total installs
How We Detect Datafeedr API
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/datafeedr-api/css/style.css/wp-content/plugins/datafeedr-api/css/searchform.css/wp-content/plugins/datafeedr-api/js/general.js/wp-content/plugins/datafeedr-api/js/searchfilter.js/wp-content/plugins/datafeedr-api/js/merchants.js/wp-content/plugins/datafeedr-api/js/searchform.js/wp-content/plugins/datafeedr-api/js/jquery.reveal.js/wp-content/plugins/datafeedr-api/js/general.js/wp-content/plugins/datafeedr-api/js/searchfilter.js/wp-content/plugins/datafeedr-api/js/merchants.js/wp-content/plugins/datafeedr-api/js/searchform.js/wp-content/plugins/datafeedr-api/js/jquery.reveal.jsdatafeedr-api/css/style.css?ver=datafeedr-api/css/searchform.css?ver=datafeedr-api/js/general.js?ver=datafeedr-api/js/searchfilter.js?ver=datafeedr-api/js/merchants.js?ver=datafeedr-api/js/searchform.js?ver=datafeedr-api/js/jquery.reveal.js?ver=HTML / DOM Fingerprints
dfrapidata-dfr-targetdfrapi_ajax_object