DataFeedWatch Connector for WooCommerce Security & Risk Analysis

wordpress.org/plugins/datafeedwatch-connector-for-woocommerce

Optimize your product feeds to boost online sales. Scale your PPC campaigns to more than 2,000 channels & marketplaces and increase your ROI.

600 active installs v2.0.6 PHP + WP 4.5+ Updated Oct 21, 2024
data-feedfeed-managementgoogle-shoppingproduct-feedwoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is DataFeedWatch Connector for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

DataFeedWatch Connector for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "datafeedwatch-connector-for-woocommerce" plugin v2.0.6 exhibits a mixed security posture. On the positive side, it demonstrates good practices by consistently using prepared statements for all SQL queries and properly escaping a high percentage of its output. The absence of any recorded vulnerabilities, critical taint flows, or bundled libraries also suggests a generally well-maintained codebase.

However, a significant concern lies in its limited attack surface, which is entirely unprotected. With one AJAX handler present and lacking any authentication or capability checks, this entry point is directly accessible to unauthenticated users. This creates a substantial risk, as any functionality exposed through this handler could be abused. While no specific vulnerabilities are detailed in the static analysis, this unprotected AJAX handler represents a clear and actionable security concern that requires immediate attention.

Key Concerns

  • Unprotected AJAX handler
  • No capability checks for entry points
Vulnerabilities
None known

DataFeedWatch Connector for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

DataFeedWatch Connector for WooCommerce Code Analysis

Dangerous Functions
4
Raw SQL Queries
0
24 prepared
Unescaped Output
3
50 escaped
Nonce Checks
1
Capability Checks
0
File Operations
2
External Requests
4
Bundled Libraries
0

Dangerous Functions Found

unserialize$cartPluginsNetwork = unserialize( $cartPluginsNetwork );bridge2cart\bridge.php:805
unserialize$activePlugin = $getActivePlugin( unserialize( $cartPlugins ) );bridge2cart\bridge.php:822
unserialize$activePlugin = $getActivePlugin( unserialize( $cartPlugins ) );bridge2cart\bridge.php:839
unserialize$data = unserialize( $a2cData['metaData'], ['allowed_classes' => ['stdClass']] );bridge2cart\bridge.php:1103

SQL Query Safety

100% prepared24 total queries

Output Escaping

94% escaped53 total outputs
Attack Surface
1 unprotected

DataFeedWatch Connector for WooCommerce Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_DFWCWbridge_actiondatafeedwatch-connector-for-woocommerce.php:62
WordPress Hooks 9
filterwoocommerce_email_enabled_customer_completed_orderbridge2cart\bridge.php:1540
filterwoocommerce_email_enabled_customer_invoicebridge2cart\bridge.php:1541
filterwoocommerce_email_enabled_customer_notebridge2cart\bridge.php:1542
filterwoocommerce_email_enabled_customer_on_hold_orderbridge2cart\bridge.php:1543
filterwoocommerce_email_enabled_customer_processing_orderbridge2cart\bridge.php:1544
filterwoocommerce_email_enabled_customer_refunded_orderbridge2cart\bridge.php:1545
actionadmin_noticesdatafeedwatch-connector-for-woocommerce.php:43
actionrest_api_initdatafeedwatch-connector-for-woocommerce.php:172
actionadmin_menudatafeedwatch-connector-for-woocommerce.php:263
Maintenance & Trust

DataFeedWatch Connector for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedOct 21, 2024
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs600
Developer Profile

DataFeedWatch Connector for WooCommerce Developer Profile

dfwbycart

1 plugin · 600 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DataFeedWatch Connector for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/datafeedwatch-connector-for-woocommerce/css/style.css/wp-content/plugins/datafeedwatch-connector-for-woocommerce/css/dfw-style.css/wp-content/plugins/datafeedwatch-connector-for-woocommerce/js/scripts.js/wp-content/plugins/datafeedwatch-connector-for-woocommerce/js/dfw-scripts.js
Version Parameters
datafeedwatch-connector-for-woocommerce/css/style.css?ver=datafeedwatch-connector-for-woocommerce/css/dfw-style.css?ver=datafeedwatch-connector-for-woocommerce/js/scripts.js?ver=datafeedwatch-connector-for-woocommerce/js/dfw-scripts.js?ver=

HTML / DOM Fingerprints

JS Globals
DFWCWAjax
REST Endpoints
/wp-json/dfwcw-v1/bridge/products
FAQ

Frequently Asked Questions about DataFeedWatch Connector for WooCommerce