Did Prestashop Display – Show Prestashop products in your WordPress Security & Risk Analysis

wordpress.org/plugins/did-prestashop-display

Show products in your Wordpress, using Shortcode. Generate landing pages with direct links to your products, with updated information on prices and di …

50 active installs v1.0.30 PHP 7.0+ WP 4.9.6+ Updated Aug 5, 2020
bannerslinksmarketingprestashopproducts
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEOct 10, 2025
Safety Verdict

Is Did Prestashop Display – Show Prestashop products in your WordPress Safe to Use in 2026?

Use With Caution

Score 63/100

Did Prestashop Display – Show Prestashop products in your WordPress has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Oct 10, 2025Updated 5yr ago
Risk Assessment

The "did-prestashop-display" plugin v1.0.30 presents a mixed security posture. On the positive side, the static analysis reveals a small attack surface with only one entry point (a shortcode) and no identified dangerous functions or raw SQL queries. File operations are also absent, and external HTTP requests are limited to one. However, significant concerns arise from the extremely low percentage of properly escaped output (2%), indicating a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce and capability checks across all entry points further exacerbates this risk, leaving the plugin vulnerable to various attacks, particularly Cross-Site Request Forgery (CSRF) which is a known issue in its history.

The vulnerability history is a critical red flag. The presence of one unpatched medium severity CVE, historically linked to CSRF, combined with the code analysis findings of missing nonces and capability checks, strongly suggests that the plugin has recurring security weaknesses. While the plugin avoids some common pitfalls like raw SQL and dangerous functions, the critical lack of output escaping and authorization checks on its sole entry point makes it a significant risk. Users should be highly cautious and prioritize patching or finding an alternative if possible.

Key Concerns

  • Unpatched CVE (Medium Severity)
  • Very low output escaping percentage
  • Missing nonce checks
  • Missing capability checks
  • Known CSRF vulnerability history
Vulnerabilities
1

Did Prestashop Display – Show Prestashop products in your WordPress Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-62945medium · 4.3Cross-Site Request Forgery (CSRF)

Did Prestashop Display <= 1.0.30 - Cross-Site Request Forgery

Oct 10, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Did Prestashop Display – Show Prestashop products in your WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
251
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

2% escaped257 total outputs
Attack Surface

Did Prestashop Display – Show Prestashop products in your WordPress Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[dp_product] includes\classes\class-didpdmain.php:42
WordPress Hooks 5
actionplugins_loadeddid_prestashop_display.php:35
actionadmin_initincludes\classes\class-didpdadmin.php:13
actionadmin_menuincludes\classes\class-didpdmain.php:41
actionwp_enqueue_scriptsincludes\classes\class-didpdmain.php:45
actionadmin_enqueue_scriptsincludes\classes\class-didpdmain.php:46
Maintenance & Trust

Did Prestashop Display – Show Prestashop products in your WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedAug 5, 2020
PHP min version7.0
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs50
Developer Profile

Did Prestashop Display – Show Prestashop products in your WordPress Developer Profile

Eduard Pinuaga Linares

1 plugin · 50 total installs

68
trust score
Avg Security Score
63/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Did Prestashop Display – Show Prestashop products in your WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/did-prestashop-display/css/didpd_style.css/wp-content/plugins/did-prestashop-display/js/didpd_main.js
Script Paths
/wp-content/plugins/did-prestashop-display/js/didpd_main.js
Version Parameters
did-prestashop-display/css/didpd_style.css?ver=did-prestashop-display/js/didpd_main.js?ver=

HTML / DOM Fingerprints

CSS Classes
didpd-product-displaydidpd-product-namedidpd-product-pricedidpd-product-description
Data Attributes
data-product-iddata-product-type
JS Globals
didpd_main_obj
Shortcode Output
[dp_product
FAQ

Frequently Asked Questions about Did Prestashop Display – Show Prestashop products in your WordPress