Embed and Integrate Etsy Shop Security & Risk Analysis

wordpress.org/plugins/embed-and-integrate-etsy-shop

Bring your Etsy shop to WordPress with Etsy Embed listings and pages, plus Listings Genie AI tools — all through your free Embed360 account.

200 active installs v1.1.1 PHP + WP 6.0+ Updated May 18, 2026
ecommerceembedetsylistingsshop
79
B · Generally Safe
CVEs total1
Unpatched1
Last CVEMay 19, 2025
Safety Verdict

Is Embed and Integrate Etsy Shop Safe to Use in 2026?

Mostly Safe

Score 79/100

Embed and Integrate Etsy Shop is generally safe to use. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: May 19, 2025Updated 3mo ago
Risk Assessment

The plugin "embed-and-integrate-etsy-shop" v1.0.8 exhibits a concerning security posture due to multiple critical weaknesses. While the code analysis shows no dangerous functions, raw SQL queries, or external HTTP requests, it reveals a significant attack surface with two unprotected AJAX handlers. This lack of authorization checks on critical entry points is a major red flag.

The taint analysis further highlights issues, with two flows identified having unsanitized paths, although they are not classified as critical or high severity. The vulnerability history is particularly worrying, indicating one currently unpatched medium severity CVE. The pattern of past vulnerabilities, including a history of missing authorization, strongly suggests a recurring weakness in the plugin's security development lifecycle.

In conclusion, while the plugin has some positive attributes like the use of prepared statements for SQL and mostly proper output escaping, these are overshadowed by the critical risks of unprotected AJAX endpoints and a history of unpatched vulnerabilities, especially concerning missing authorization. The presence of an unpatched CVE and the identified unprotected entry points necessitate immediate attention and remediation.

Key Concerns

  • Unprotected AJAX handlers
  • Unpatched CVE (medium severity)
  • Flows with unsanitized paths
  • No nonce checks on AJAX
  • No capability checks
Vulnerabilities
1 published

Embed and Integrate Etsy Shop Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-48346medium · 5.3Missing Authorization

Embed and Integrate Etsy Shop <= 1.0.4 - Missing Authorization

May 19, 2025Unpatched
Version History

Embed and Integrate Etsy Shop Release Timeline

v1.1.1Current1 CVE
v1.1.01 CVE
v1.0.91 CVE
v1.0.81 CVE
v1.0.71 CVE
v1.0.61 CVE
v1.0.51 CVE
Code Analysis
Analyzed Mar 16, 2026

Embed and Integrate Etsy Shop Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

88% escaped8 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
save_user_token_callback (admin\class-embed-integrate-etsy-shop-admin.php:107)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Embed and Integrate Etsy Shop Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

noprivwp_ajax_save_user_tokenincludes\class-embed-integrate-etsy-shop.php:158
authwp_ajax_save_user_tokenincludes\class-embed-integrate-etsy-shop.php:159
WordPress Hooks 8
actionplugins_loadedincludes\class-embed-integrate-etsy-shop.php:135
actionadmin_enqueue_scriptsincludes\class-embed-integrate-etsy-shop.php:149
actionadmin_enqueue_scriptsincludes\class-embed-integrate-etsy-shop.php:150
actionadmin_menuincludes\class-embed-integrate-etsy-shop.php:152
actionwp_headincludes\class-embed-integrate-etsy-shop.php:155
actionwp_enqueue_scriptsincludes\class-embed-integrate-etsy-shop.php:172
actionwp_enqueue_scriptsincludes\class-embed-integrate-etsy-shop.php:173
actionwp_print_footer_scriptsincludes\class-embed-integrate-etsy-shop.php:175
Maintenance & Trust

Embed and Integrate Etsy Shop Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.5
Last updatedMay 18, 2026
PHP min version
Downloads6K

Community Trust

Rating60/100
Number of ratings2
Active installs200
Developer Profile

Embed and Integrate Etsy Shop Developer Profile

Embed360

1 plugin · 200 total installs

79
trust score
Avg Security Score
79/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Embed and Integrate Etsy Shop

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/embed-and-integrate-etsy-shop/css/embed-integrate-etsy-shop-public.css/wp-content/plugins/embed-and-integrate-etsy-shop/js/embed-integrate-etsy-shop-public.js
Script Paths
/wp-content/plugins/embed-and-integrate-etsy-shop/js/embed-integrate-etsy-shop-public.js
Version Parameters
embed-integrate-etsy-shop/css/embed-integrate-etsy-shop-public.css?ver=embed-integrate-etsy-shop/js/embed-integrate-etsy-shop-public.js?ver=

HTML / DOM Fingerprints

JS Globals
window.ajaxurl
FAQ

Frequently Asked Questions about Embed and Integrate Etsy Shop