
EPROLO-Dropshipping Security & Risk Analysis
wordpress.org/plugins/eprolo-dropshippingEPROLO dropshipping allows to import products from Aliexpress or EPROLO to wordpress, woocommerce in one click.
Is EPROLO-Dropshipping Safe to Use in 2026?
Generally Safe
Score 98/100EPROLO-Dropshipping has a strong security track record. Known vulnerabilities have been patched promptly.
The 'eprolo-dropshipping' plugin v2.4.2 presents a mixed security posture. While it demonstrates good practices in output escaping, with 98% of outputs properly escaped, and has no currently unpatched known vulnerabilities, several significant concerns are evident.
The static analysis reveals an attack surface with 7 AJAX handlers, 3 of which lack authentication checks. Furthermore, 1 REST API route is exposed without proper permission callbacks. This exposes the plugin to potential unauthorized actions. The taint analysis shows 6 flows with unsanitized paths, although they are not categorized as critical or high severity, this still indicates potential for injecting malicious data that is not properly handled.
The vulnerability history, while showing no currently unpatched CVEs, indicates a pattern of past issues, specifically two medium-severity vulnerabilities. Notably, 'Missing Authorization' was a common vulnerability type. This historical trend, coupled with the current findings of unprotected entry points, suggests a recurring weakness in authorization controls within the plugin. While the lack of critical vulnerabilities and high-quality output escaping are positive signs, the unprotected entry points and historical authorization issues warrant careful consideration.
Key Concerns
- AJAX handlers without auth checks
- REST API routes without permission callbacks
- SQL queries without prepared statements
- Unsanitized taint flows
- Previous medium severity CVEs
EPROLO-Dropshipping Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
EPROLO Dropshipping <= 2.3.1 - Missing Authorization to Authenticated (Subscriber+) Tracking Data Modification
EPROLO Dropshipping <= 1.7.1 - Missing Authorization
EPROLO-Dropshipping Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
EPROLO-Dropshipping Attack Surface
AJAX Handlers 7
REST API Routes 1
WordPress Hooks 12
Maintenance & Trust
EPROLO-Dropshipping Maintenance & Trust
Maintenance Signals
Community Trust
EPROLO-Dropshipping Alternatives
Spreadconnect
wc-spod
Ready to add merch to your website? Spreadconnect is a Print on Demand Dropshipping plug-in for WooCommerce that’s trusted by over 100,000 creators an …
Selfnamed: Cosmetics on demand
selfnamed-cosmetics-on-demand
Create and sell organic & vegan skincare products trough print-on-demand dropshipping.
Hoplix Integration for WooCommerce
hoplix-print-on-demand-platform
Grow your store with the top print-on-demand dropshipping plugin
Popcustoms – Print on demand & dropshipping, Free Personalizer
popcustoms-integration-for-woocommerce
Print on demand products & embroidery provider, fulfillment & global dropshipping, customize shoes, T-shirt, hats, hoodie, jacket, blanket and more.
Yakkyofy
yakkyofy
Yakkyofy completely automates your woocommerce dropshipping store so you can focus on what matters most: marketing. You run ads, we power your store.
EPROLO-Dropshipping Developer Profile
2 plugins · 1K total installs
How We Detect EPROLO-Dropshipping
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/eprolo-dropshipping/js/startup.js/wp-content/plugins/eprolo-dropshipping/js/bootstrap.min.js/wp-content/plugins/eprolo-dropshipping/js/startup.js/wp-content/plugins/eprolo-dropshipping/js/bootstrap.min.jseprolo-dropshipping/js/startup.js?ver=eprolo-dropshipping/js/bootstrap.min.js?ver=HTML / DOM Fingerprints
data-eprolo-connectedEproloSettings/wp-json/eprolo/v1/settings/wp-json/eprolo/v1/products/wp-json/eprolo/v1/orders[eprolo_products][eprolo_orders]