DataPocket – Connect product data with your design tools Security & Risk Analysis

wordpress.org/plugins/datapocket

Sync product feeds into your design tools and create on-brand assets with real-time data. DataPocket brings your product data (images, prices, copy) …

300 active installs v1.3.8 PHP 7.0+ WP 4.6+ Updated Sep 15, 2025
adobecanvafigmamarketingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is DataPocket – Connect product data with your design tools Safe to Use in 2026?

Generally Safe

Score 100/100

DataPocket – Connect product data with your design tools has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The "datapocket" v1.3.8 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The plugin demonstrates good practices by ensuring all SQL queries are prepared, and all output is properly escaped, which significantly reduces the risk of common injection and cross-site scripting vulnerabilities. Furthermore, the absence of any recorded vulnerabilities or CVEs in its history suggests a well-maintained and secure codebase. The attack surface is limited to REST API routes, and importantly, all identified entry points have permission callbacks, indicating that access is appropriately controlled.

However, there are a few areas that warrant attention, primarily related to the absence of specific security checks. The analysis shows zero nonce checks and zero capability checks. While the REST API routes have permission callbacks, the lack of explicit nonce checks on AJAX handlers (though there are none reported in this version) and a general absence of capability checks could present a theoretical risk if the plugin's functionality were to evolve or if there were undiscovered logic flaws. The external HTTP requests also represent a potential, albeit low, risk if the target endpoints are compromised or unreliable.

In conclusion, "datapocket" v1.3.8 is a secure plugin with a commendable emphasis on preventing SQL injection and XSS. Its clean vulnerability history is a significant strength. The primary weakness lies in the lack of explicit nonce and capability checks, which, while not immediately exploitable with the current attack surface, represent a missed opportunity for defense-in-depth. The plugin is largely safe, but a proactive approach to adding these checks would further solidify its security.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
  • External HTTP requests present
Vulnerabilities
None known

DataPocket – Connect product data with your design tools Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

DataPocket – Connect product data with your design tools Release Timeline

v1.3.8Current
v1.3.7
v1.3.6
v1.3.5
v1.3.4
v1.3.3
v1.3.2
v1.3.1
v1.2.9
v1.2.8
v1.2.7
v1.2.6
v1.2.5
v1.0.11
Code Analysis
Analyzed Mar 16, 2026

DataPocket – Connect product data with your design tools Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
0
33 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

100% escaped33 total outputs
Attack Surface

DataPocket – Connect product data with your design tools Attack Surface

Entry Points11
Unprotected0

REST API Routes 11

GET/wp-json/datapocket/v1/conncheckincludes\class-datapocket-api.php:32
GET/wp-json/datapocket/v1/createkeysincludes\class-datapocket-api.php:39
GET/wp-json/datapocket/v1/checkkey/(?P<consumer_key>[a-zA-Z0-9-_]+)includes\class-datapocket-api.php:46
POST/wp-json/datapocket/v1/configkeys/(?P<consumer_key>[a-zA-Z0-9-_]+)includes\class-datapocket-api.php:53
GET/wp-json/datapocket/v1/wp-conncheckincludes\class-datapocket-api.php:64
GET/wp-json/datapocket/v1/webhooksincludes\class-datapocket-api.php:71
POST/wp-json/datapocket/v1/webhooksincludes\class-datapocket-api.php:80
POST/wp-json/datapocket/v1/webhooks/(?P<webhook_id>\d+)includes\class-datapocket-api.php:91
DELETE/wp-json/datapocket/v1/webhooks/(?P<webhook_id>\d+)includes\class-datapocket-api.php:102
POST/wp-json/datapocket/v1/application-passwordsincludes\class-datapocket-api.php:112
DELETE/wp-json/datapocket/v1/application-passwords/(?P<uuid>[a-zA-Z0-9-_]+)includes\class-datapocket-api.php:127
WordPress Hooks 14
actionadmin_enqueue_scriptsincludes\admin\class-datapocket-admin-assets.php:20
actionadmin_enqueue_scriptsincludes\admin\class-datapocket-admin-assets.php:21
actionadmin_menuincludes\admin\class-datapocket-admin-menus.php:21
actioninitincludes\admin\class-datapocket-admin.php:20
actionrest_api_initincludes\class-datapocket-api.php:20
actionadmin_initincludes\class-datapocket-install.php:16
actioninitincludes\class-datapocket-post-types.php:20
actionwp_after_insert_postincludes\class-datapocket-post-types.php:21
actiondelete_postincludes\class-datapocket-post-types.php:22
actioncreated_termincludes\class-datapocket-post-types.php:24
actionedited_termincludes\class-datapocket-post-types.php:25
actionpre_delete_termincludes\class-datapocket-post-types.php:26
actionpre_user_queryincludes\class-datapocket-users.php:20
actioninitincludes\class-datapocket.php:96
Maintenance & Trust

DataPocket – Connect product data with your design tools Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedSep 15, 2025
PHP min version7.0
Downloads7K

Community Trust

Rating100/100
Number of ratings2
Active installs300
Developer Profile

DataPocket – Connect product data with your design tools Developer Profile

OVIXIA

1 plugin · 300 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DataPocket – Connect product data with your design tools

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/datapocket/assets/css/bootstrap.min.css/wp-content/plugins/datapocket/assets/css/admin.css
Version Parameters
datapocket/assets/css/admin.css?ver=

HTML / DOM Fingerprints

REST Endpoints
/wp-json/datapocket/v1/conncheck/wp-json/datapocket/v1/createkeys/wp-json/datapocket/v1/checkkey//wp-json/datapocket/v1/configkeys//wp-json/datapocket/v1/wp-conncheck/wp-json/datapocket/v1/webhooks/wp-json/datapocket/v1/webhooks//wp-json/datapocket/v1/application-passwords
FAQ

Frequently Asked Questions about DataPocket – Connect product data with your design tools