
ExportFeed – Woo Additional Product Fields Security & Risk Analysis
wordpress.org/plugins/exportfeed-woo-additional-product-fieldsExportFeed: Woo Additional Fields Plugin to Add Brand, MPN, UPC, EAN & Shipping Rates
Is ExportFeed – Woo Additional Product Fields Safe to Use in 2026?
Generally Safe
Score 85/100ExportFeed – Woo Additional Product Fields has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'exportfeed-woo-additional-product-fields' v1.0.2 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is a positive sign. Furthermore, the lack of recorded CVEs suggests a history of responsible development and maintenance. The limited attack surface, consisting of a single shortcode with no explicit authentication or capability checks, is a notable area for improvement.
While the code analysis shows no critical taint flows and a reasonable percentage of output escaping, the lack of explicit nonce and capability checks on the identified shortcode is a potential concern. This could allow for unintended execution or manipulation if the shortcode's functionality is sensitive. The absence of any recorded vulnerabilities in its history is a strong positive indicator, but it doesn't negate the need for robust security practices for all entry points.
In conclusion, the plugin demonstrates strong fundamental security practices, particularly regarding data handling and preventing common vulnerabilities. However, the security of the shortcode entry point needs to be reinforced with appropriate authentication and capability checks to fully mitigate potential risks. This would significantly strengthen its overall security profile.
Key Concerns
- Shortcode without capability checks
- Shortcode without nonce checks
- 11 total outputs, 73% properly escaped
ExportFeed – Woo Additional Product Fields Security Vulnerabilities
ExportFeed – Woo Additional Product Fields Code Analysis
Output Escaping
ExportFeed – Woo Additional Product Fields Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
ExportFeed – Woo Additional Product Fields Maintenance & Trust
Maintenance Signals
Community Trust
ExportFeed – Woo Additional Product Fields Alternatives
No alternatives data available yet.
ExportFeed – Woo Additional Product Fields Developer Profile
3 plugins · 1K total installs
How We Detect ExportFeed – Woo Additional Product Fields
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
options_groupshow_if_simpleshow_if_externalform-row-firstform-row-laststepmin[WAPF_additional_fields