
Social Shop for WooCommerce Security & Risk Analysis
wordpress.org/plugins/facebook-shop-by-storeyacomThis plugin will import your Woocommerce store to Facebook in a couple of minutes, with no development or design skills required.
Is Social Shop for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100Social Shop for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'facebook-shop-by-storeyacom' v2.6 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The plugin demonstrates good practices by having a limited attack surface with no apparent entry points that bypass authentication. Furthermore, it adheres to secure coding principles by exclusively using prepared statements for SQL queries and including nonce and capability checks. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its secure design.
However, a significant concern arises from the low percentage (12%) of properly escaped output. This indicates a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not sufficiently sanitized before being rendered in the browser. While the taint analysis showed no unsanitized flows, this is likely due to the limited scope of the analysis or the absence of complex data flows. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator. Despite this, the output escaping issue presents a notable weakness that requires attention.
In conclusion, the plugin benefits from a small attack surface and adherence to secure practices for database interaction and authentication. The primary weakness lies in insufficient output escaping, which could lead to XSS vulnerabilities. The lack of historical vulnerabilities is reassuring, but the identified code signal deficiency needs to be addressed to improve the overall security.
Key Concerns
- Insufficient output escaping
Social Shop for WooCommerce Security Vulnerabilities
Social Shop for WooCommerce Code Analysis
Output Escaping
Social Shop for WooCommerce Attack Surface
WordPress Hooks 10
Maintenance & Trust
Social Shop for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Social Shop for WooCommerce Alternatives
Robokassa for WooCommerce
robokassa-for-woocommerce
Allows you to use Robokassa payment gateway with the WooCommerce plugin.
Shipping Additional Days for WooCommerce
woo-shipping-additional-days
Allows you to set additional days to your delivery date into Products and Shipping Classes.
Robokassa Payment Gateway (Saphali)
robokassa-payment-gateway-saphali
Allows you to use Robokassa payment gateway with the WooCommerce plugin.
Webmoney – payment gateway for WooCommerce
wc-webmoney
Allows you to use the Webmoney with WooCommerce as a payment gateway plugin.
SMSPILOT.RU WooCommerce
smspilot-ru-woocommerce
SMS уведомления о заказах WooCommerce через шлюз SMSPILOT.RU
Social Shop for WooCommerce Developer Profile
5 plugins · 1K total installs
How We Detect Social Shop for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/facebook-shop-by-storeyacom/js/facebook-shop-by-storeyacom-admin.js/wp-content/plugins/facebook-shop-by-storeyacom/js/facebook-shop-by-storeyacom-frontend.js/wp-content/plugins/facebook-shop-by-storeyacom/css/facebook-shop-by-storeyacom-admin.css/wp-content/plugins/facebook-shop-by-storeyacom/css/facebook-shop-by-storeyacom-frontend.css/wp-content/plugins/facebook-shop-by-storeyacom/js/facebook-shop-by-storeyacom-admin.js/wp-content/plugins/facebook-shop-by-storeyacom/js/facebook-shop-by-storeyacom-frontend.jsHTML / DOM Fingerprints
woocommerce_storeya_field_selector_groupwoocommerce_storeya_field_selectordata-woocommerce_storeya_disable_feedwoocommerce_storeya