Fast eBay Listings Security & Risk Analysis

wordpress.org/plugins/fast-ebay-listings

eBay WordPress Plugin to display live eBay products from your store or across eBay. Add affiliate eBay Partner Network links to earn money.

400 active installs v2.12.17 PHP 7.4+ WP 5.0+ Updated Feb 20, 2026
affiliate-marketingebayebay-partner-networkfeedbackintegrate
99
A · Safe
CVEs total1
Unpatched0
Last CVEApr 16, 2025
Safety Verdict

Is Fast eBay Listings Safe to Use in 2026?

Generally Safe

Score 99/100

Fast eBay Listings has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 16, 2025Updated 1mo ago
Risk Assessment

The "fast-ebay-listings" plugin v2.12.17 demonstrates a generally good security posture with strong practices in key areas. The complete absence of critical or high severity taint flows, coupled with 100% of SQL queries using prepared statements, indicates a solid defense against common injection attacks. Furthermore, the high percentage of properly escaped output (97%) and the presence of nonce and capability checks on some entry points are positive signs. However, a significant concern arises from the large attack surface, with 11 AJAX handlers and a concerning 8 of these lacking authentication checks. This presents a substantial risk of unauthorized actions if attackers can bypass or exploit these unprotected endpoints.

The vulnerability history shows one past medium-severity vulnerability related to Open Redirect, which is concerning given the plugin's age and past issues. Although there are no currently unpatched vulnerabilities, the historical presence of such flaws suggests a need for continued vigilance. The plugin also performs external HTTP requests, which, while not inherently risky, could be a vector if not handled with extreme care in conjunction with other potential weaknesses. Overall, the plugin has strengths in core secure coding practices but a major weakness in its exposed AJAX endpoints that requires immediate attention.

Key Concerns

  • 8 unprotected AJAX handlers
  • 1 past medium vulnerability (Open Redirect)
  • 2 file operations detected
  • 1 external HTTP request detected
Vulnerabilities
1

Fast eBay Listings Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-39597medium · 6.1URL Redirection to Untrusted Site ('Open Redirect')

Fast eBay Listings <= 2.12.15 - Open Redirect

Apr 16, 2025 Patched in 2.12.16 (7d)
Code Analysis
Analyzed Mar 16, 2026

Fast eBay Listings Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
413 escaped
Nonce Checks
2
Capability Checks
6
File Operations
2
External Requests
1
Bundled Libraries
0

Output Escaping

97% escaped427 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
fu_ebay_handle_admin_notice_dismissal (utilities.php:237)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
8 unprotected

Fast eBay Listings Attack Surface

Entry Points11
Unprotected8

AJAX Handlers 11

authwp_ajax_fu_ebay_load_getitemapicall_browse_getitem.php:143
noprivwp_ajax_fu_ebay_load_getitemapicall_browse_getitem.php:144
authwp_ajax_fu_ebay_load_searchapicall_browse_search.php:541
noprivwp_ajax_fu_ebay_load_searchapicall_browse_search.php:542
authwp_ajax_fu_ebay_load_feedbackapicall_feedback.php:336
noprivwp_ajax_fu_ebay_load_feedbackapicall_feedback.php:337
authwp_ajax_fu_ebay_load_rssapicall_rss.php:226
noprivwp_ajax_fu_ebay_load_rssapicall_rss.php:227
authwp_ajax_fu_ebay_load_categoriescats\cat_chooser.php:66
noprivwp_ajax_fu_ebay_load_categoriescats\cat_chooser.php:67
authwp_ajax_dismissed_notice_handlerutilities.php:251
WordPress Hooks 36
actionadmin_menuadmin.php:15
actionadmin_initadmin.php:25
actionshow_user_profileadmin.php:939
actionedit_user_profileadmin.php:940
actionpersonal_options_updateadmin.php:959
actionedit_user_profile_updateadmin.php:960
actionadmin_noticesapicall_subinfo.php:147
actioninitblocks\feedback\feedback.php:69
actioninitblocks\item\item.php:51
actioninitblocks\rssfeed\rssfeed.php:55
actioninitblocks\search\search.php:85
actionadmin_footercats\cat_chooser.php:39
actioninitconstants.php:464
actioninitfast-ebay-listings.php:69
actionadmin_headincludes\shortcodes.inc.php:39
filtermce_external_pluginsincludes\shortcodes.inc.php:64
filtermce_buttonsincludes\shortcodes.inc.php:65
actionadmin_headincludes\shortcodes.inc.php:109
actionadmin_enqueue_scriptsincludes\shortcodes.inc.php:110
filtermce_external_pluginsincludes\shortcodes.inc.php:127
filtermce_buttonsincludes\shortcodes.inc.php:128
filterthe_contentpresentation.php:143
filtermce_external_languagesshortcodes.php:6
actionwp_print_stylesutilities.php:43
actionadmin_headutilities.php:52
actionwp_enqueue_scriptsutilities.php:89
actionadmin_enqueue_scriptsutilities.php:132
actionupgrader_process_completeutilities.php:181
actionadmin_noticesutilities.php:196
actionadmin_noticesutilities.php:218
actionadmin_noticesutilities.php:276
actioninitutilities.php:313
actioninitutilities.php:354
actionadmin_print_scripts-widgets.phpwidget_search.php:17
actionwidgets_initwidget_search.php:269
actionwidgets_initwidget_search_dynamic.php:225
Maintenance & Trust

Fast eBay Listings Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 20, 2026
PHP min version7.4
Downloads24K

Community Trust

Rating90/100
Number of ratings18
Active installs400
Developer Profile

Fast eBay Listings Developer Profile

WarfarePlugins

11 plugins · 22K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
408 days
View full developer profile
Detection Fingerprints

How We Detect Fast eBay Listings

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fast-ebay-listings/styles.css/wp-content/plugins/fast-ebay-listings/includes/styles.inc.css/wp-content/plugins/fast-ebay-listings/admin_styles.css/wp-content/plugins/fast-ebay-listings/cats/cat_styles.css/wp-content/plugins/fast-ebay-listings/includes/script.inc.js/wp-content/plugins/fast-ebay-listings/smartlinks.js/wp-content/plugins/fast-ebay-listings/mce/mce-button-core.js
Script Paths
mce/mce-button-core.js
Version Parameters
fast-ebay-listings/styles.css?v=fast-ebay-listings/includes/styles.inc.css?v=fast-ebay-listings/admin_styles.css?v=fast-ebay-listings/cats/cat_styles.css?v=fast-ebay-listings/includes/script.inc.js?v=fast-ebay-listings/smartlinks.js?v=fast-ebay-listings/mce/mce-button-core.js?v=

HTML / DOM Fingerprints

CSS Classes
fu_ebay_titlefu_ebay_desc
JS Globals
fuEbayScriptShortcode
Shortcode Output
[fu_ebay_listing[fu_ebay_feedback[fu_ebay_rssfeed[fu_ebay_search
FAQ

Frequently Asked Questions about Fast eBay Listings