
ePim API importer Security & Risk Analysis
wordpress.org/plugins/epim-api-importerThis plugin requires you to have an account at https://epim.online for ePim and an activated ePim api. More info on ePim here: https://www.e-pim.co.
Is ePim API importer Safe to Use in 2026?
Generally Safe
Score 92/100ePim API importer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The epim-api-importer plugin exhibits a significantly concerning security posture due to a vast attack surface with no authentication checks on its AJAX handlers. While the code displays good practices in SQL query sanitization and a lack of known vulnerabilities, the absence of security measures on its entry points is a critical oversight. The static analysis reveals all 43 AJAX handlers are unprotected, presenting a wide avenue for potential exploitation. Taint analysis, though showing no critical or high severity flows, analyzed a limited number of flows and found 100% of them with unsanitized paths, which is a worrying indicator given the unauthenticated nature of the AJAX handlers.
The vulnerability history shows a clean slate, which is positive but could also be attributed to the plugin's limited adoption or a lack of extensive security auditing. The presence of nonce checks and capability checks on a limited subset of functions suggests some awareness of security principles, but their application is not comprehensive enough to mitigate the risks posed by the unprotected AJAX endpoints. Overall, the plugin's strengths lie in its SQL handling and lack of historical vulnerabilities, but these are severely overshadowed by the high risk introduced by its exposed AJAX interface.
Key Concerns
- 43 AJAX handlers without auth checks
- 22 flows with unsanitized paths (taint analysis)
- 49% output escaping is not properly escaped
- 4 nonce checks for 43 entry points
- 7 capability checks for 43 entry points
ePim API importer Security Vulnerabilities
ePim API importer Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ePim API importer Attack Surface
AJAX Handlers 43
WordPress Hooks 61
Scheduled Events 13
Maintenance & Trust
ePim API importer Maintenance & Trust
Maintenance Signals
Community Trust
ePim API importer Alternatives
Course Box
course-box
A WordPress plugin that integrates with WooCommerce to import products from an external API with advanced features like pagination, search, and import …
Integration for Artbiz
integration-artbiz
Integration for Artbiz plugin seamlessly links Artbiz software with your Woocommerce store.
Vamp Fashion
vamp-fashion
Effortlessly import products from the Vamp Fashion API into your WooCommerce store.
WooCommerce Legacy REST API
woocommerce-legacy-rest-api
The WooCommerce Legacy REST API, which is now part of WooCommerce itself but will be removed in WooCommerce 9.0.
Product Import Export for WooCommerce – Import Export Product CSV Suite
product-import-export-for-woo
Easily import/export WooCommerce products (simple, grouped, external/affiliate) via CSV. Transfer product data, including images, reviews, categories, …
ePim API importer Developer Profile
1 plugin · 10 total installs
How We Detect ePim API importer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/epim-api-importer/assets/css/jquery-ui-1-8-2.css/wp-content/plugins/epim-api-importer/assets/scripts/processQueue.js/wp-content/plugins/epim-api-importer/assets/scripts/admin.js/wp-content/plugins/epim-api-importer/assets/scripts/processQueue.js/wp-content/plugins/epim-api-importer/assets/scripts/admin.jsepim-api-importer/assets/scripts/processQueue.js?ver=epim-api-importer/assets/scripts/admin.js?ver=HTML / DOM Fingerprints
epim_ajax_object/wp-json/epim-api-importer/v1/products/wp-json/epim-api-importer/v1/categories/wp-json/epim-api-importer/v1/settings