
ePim API importer Security & Risk Analysis
wordpress.org/plugins/epim-api-importerThis plugin requires you to have an account at https://epim.online for ePim and an activated ePim api. More info on ePim here: https://www.e-pim.co.
Is ePim API importer Safe to Use in 2026?
Generally Safe
Score 85/100ePim API importer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The epim-api-importer plugin exhibits a significantly concerning security posture due to a vast attack surface with no authentication checks on its AJAX handlers. While the code displays good practices in SQL query sanitization and a lack of known vulnerabilities, the absence of security measures on its entry points is a critical oversight. The static analysis reveals all 43 AJAX handlers are unprotected, presenting a wide avenue for potential exploitation. Taint analysis, though showing no critical or high severity flows, analyzed a limited number of flows and found 100% of them with unsanitized paths, which is a worrying indicator given the unauthenticated nature of the AJAX handlers.
The vulnerability history shows a clean slate, which is positive but could also be attributed to the plugin's limited adoption or a lack of extensive security auditing. The presence of nonce checks and capability checks on a limited subset of functions suggests some awareness of security principles, but their application is not comprehensive enough to mitigate the risks posed by the unprotected AJAX endpoints. Overall, the plugin's strengths lie in its SQL handling and lack of historical vulnerabilities, but these are severely overshadowed by the high risk introduced by its exposed AJAX interface.
Key Concerns
- 43 AJAX handlers without auth checks
- 22 flows with unsanitized paths (taint analysis)
- 49% output escaping is not properly escaped
- 4 nonce checks for 43 entry points
- 7 capability checks for 43 entry points
ePim API importer Security Vulnerabilities
ePim API importer Release Timeline
ePim API importer Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ePim API importer Attack Surface
AJAX Handlers 43
WordPress Hooks 61
Scheduled Events 13
Maintenance & Trust
ePim API importer Maintenance & Trust
Maintenance Signals
Community Trust
ePim API importer Alternatives
Course Box
course-box
A WordPress plugin that integrates with WooCommerce to import products from an external API with advanced features like pagination, search, and import …
Integration for Artbiz
integration-artbiz
Integration for Artbiz plugin seamlessly links Artbiz software with your Woocommerce store.
Product Import for Triumph Underwear
product-import-for-triumph-underwear
Effortlessly import products from the Triumph Underwear API into your WooCommerce store.
REST API Products Importer for WooCommerce
rest-api-products-importer-for-woocommerce
Import products from any external WordPress/WooCommerce site's REST API directly into your store.
spss12 Importer from Prom.ua to WooCoommerce
spss12-import-prom-woo
Import products from Prom.ua xml feed directly into your woocommerce store.
ePim API importer Developer Profile
1 plugin · 10 total installs
How We Detect ePim API importer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/epim-api-importer/assets/css/jquery-ui-1-8-2.css/wp-content/plugins/epim-api-importer/assets/scripts/processQueue.js/wp-content/plugins/epim-api-importer/assets/scripts/admin.js/wp-content/plugins/epim-api-importer/assets/scripts/processQueue.js/wp-content/plugins/epim-api-importer/assets/scripts/admin.jsepim-api-importer/assets/scripts/processQueue.js?ver=epim-api-importer/assets/scripts/admin.js?ver=HTML / DOM Fingerprints
epim_ajax_object/wp-json/epim-api-importer/v1/products/wp-json/epim-api-importer/v1/categories/wp-json/epim-api-importer/v1/settings