
iThemes Exchange – Product Importer Security & Risk Analysis
wordpress.org/plugins/exchange-addon-product-importerImport new Products into your iThemes Exchange store from simple formatted files (e.g. CSV, TXT, etc.).
Is iThemes Exchange – Product Importer Safe to Use in 2026?
Generally Safe
Score 85/100iThemes Exchange – Product Importer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "exchange-addon-product-importer" v1.2 plugin exhibits a concerning security posture due to several critical findings in its static analysis. While the use of prepared statements for all SQL queries is a significant strength, the plugin lacks essential security controls on its entry points. Specifically, both identified AJAX handlers are unprotected, meaning any unauthenticated user could potentially trigger these actions, leading to unexpected behavior or even exploitation if the actions themselves are vulnerable. The absence of nonce checks and capability checks on these handlers further exacerbates this risk, as it leaves them open to cross-site request forgery (CSRF) and privilege escalation attacks.
The taint analysis, while showing no critical or high severity flows, did reveal flows with unsanitized paths. Combined with the unprotected AJAX handlers, this indicates a potential risk of directory traversal or local file inclusion vulnerabilities, especially if these unsanitized paths are used in file operations. The low percentage of properly escaped output is also a significant concern, suggesting a high likelihood of cross-site scripting (XSS) vulnerabilities.
Given the lack of any recorded vulnerability history, the plugin might appear safe. However, this absence could also indicate that the plugin hasn't been thoroughly audited or targeted by attackers yet. The identified weaknesses, particularly the unprotected AJAX endpoints and poor output escaping, present substantial security risks that need immediate attention, overriding the positive aspects like prepared SQL statements and the lack of known CVEs.
Key Concerns
- Unprotected AJAX handlers
- Missing nonce checks on AJAX
- Missing capability checks
- Low output escaping percentage
- Unsanitized paths in taint flows
iThemes Exchange – Product Importer Security Vulnerabilities
iThemes Exchange – Product Importer Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
iThemes Exchange – Product Importer Attack Surface
AJAX Handlers 2
WordPress Hooks 11
Maintenance & Trust
iThemes Exchange – Product Importer Maintenance & Trust
Maintenance Signals
Community Trust
iThemes Exchange – Product Importer Alternatives
iThemes Exchange – Add Product SKU
exchange-addon-add-product-sku
This addon for iThemes Exchange adds SKU support to all Product Types.
iThemes Exchange – Store Exporter
exchange-addon-exporter
Export store details out of iThemes Exchange into simple formatted files (e.g. CSV, XML, TXT, etc.).
Ecwid by Lightspeed Ecommerce Shopping Cart
ecwid-shopping-cart
Powerful, easy to use ecommerce shopping cart for WordPress. Sell on Facebook and Instagram. iPhone & Android apps. Superb support.
Welcart e-Commerce
usc-e-shop
Welcart is a free e-commerce plugin for Wordpress with top market share in Japan.
Shopping Cart & eCommerce Store
wp-easycart
A FREE WordPress eCommerce & WordPress Shopping Cart plugin that can sell products, subscriptions, downloads, services, donations, and much more o …
iThemes Exchange – Product Importer Developer Profile
7 plugins · 160 total installs
How We Detect iThemes Exchange – Product Importer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/exchange-addon-product-importer/templates/admin/import.css/wp-content/plugins/exchange-addon-product-importer/templates/admin/import.js/wp-content/plugins/exchange-addon-product-importer/js/toggleblock.js/wp-content/plugins/exchange-addon-product-importer/templates/admin/import.js/wp-content/plugins/exchange-addon-product-importer/js/toggleblock.jsexchange-addon-product-importer/templates/admin/import.css?ver=exchange-addon-product-importer/templates/admin/import.js?ver=exchange-addon-product-importer/js/toggleblock.js?ver=HTML / DOM Fingerprints
nav-tab-activedata-import-error