
Feed KuantoKusta for WooCommerce – Free Security & Risk Analysis
wordpress.org/plugins/feed-kuantokusta-for-woocommerceThis plugin allows you to generate a WooCommerce product feed to submit to Kuanto Kusta, a Portuguese price comparison website and marketplace.
Is Feed KuantoKusta for WooCommerce – Free Safe to Use in 2026?
Generally Safe
Score 100/100Feed KuantoKusta for WooCommerce – Free has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "feed-kuantokusta-for-woocommerce" plugin version 5.2 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL query handling, exclusively using prepared statements, and has a high percentage of properly escaped outputs. Furthermore, there is no recorded vulnerability history, suggesting a relatively stable and secure codebase in the past.
However, significant concerns arise from the static analysis. The plugin has a single AJAX entry point, which crucially lacks any authentication or capability checks. This represents a direct and unprotected pathway for attackers. The taint analysis further highlights this risk, revealing two flows with unsanitized paths classified as high severity. This indicates that data processed through these flows could potentially be exploited, although the lack of specific vulnerability types in the history prevents a more precise assessment of the exploitability. The absence of nonce checks on the AJAX handler is a critical oversight that exacerbates the risk posed by the unprotected entry point.
In conclusion, while the plugin avoids common pitfalls like raw SQL and outdated libraries, the unprotected AJAX handler and the identified high-severity unsanitized taint flows present a notable security risk. The lack of vulnerability history is a positive sign, but it does not mitigate the immediate threats identified in the code analysis. Users should exercise caution and consider the potential for unauthorized actions or data compromise through the exposed AJAX endpoint.
Key Concerns
- Unprotected AJAX handler
- High severity unsanitized taint flows (x2)
- Missing nonce check on AJAX handler
Feed KuantoKusta for WooCommerce – Free Security Vulnerabilities
Feed KuantoKusta for WooCommerce – Free Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Feed KuantoKusta for WooCommerce – Free Attack Surface
AJAX Handlers 1
WordPress Hooks 15
Maintenance & Trust
Feed KuantoKusta for WooCommerce – Free Maintenance & Trust
Maintenance Signals
Community Trust
Feed KuantoKusta for WooCommerce – Free Alternatives
Product Feeder
product-feeder
Connect to the marketplace(s) of your choice to increase sales, synchronize orders & returns, rule-based product selection, and much more! Try it …
Skroutz & Bestprice XML feed for WooCommerce
woo-xml-feed-for-skroutzgr-bestpricegr
Create Skroutz and Bestprice XML feeds for Woocommerce
XML Feed for Skroutz & BestPrice for WooCommerce
xml-feed-for-skroutz-for-woocommerce
This plugin helps you create an XML feed for Skroutz and BestPrice marketplaces.
ShoppingFeeder
shoppingfeeder
Seamlessly allows you to integrate your WooCommerce store with ShoppingFeeder and send to Google Shopping and Facebook Ads.
Sello ChannelConnector
sello-channelconnector
Easily send your products to multiple Nordic and European marketplaces like CDON, Fyndiq, Tradera, Wupti and Coolshop.
Feed KuantoKusta for WooCommerce – Free Developer Profile
21 plugins · 27K total installs
How We Detect Feed KuantoKusta for WooCommerce – Free
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/feed-kuantokusta-for-woocommerce/webdados-invoicexpress-nag/webdados-invoicexpress-nag.php/wp-content/plugins/feed-kuantokusta-for-woocommerce/images/kk.svg/wp-content/plugins/feed-kuantokusta-for-woocommerce/images/webdados.svgfeed-kuantokusta-for-woocommerceHTML / DOM Fingerprints
kk_section_titlekk_settings_sectionkk_wrapkk_rightbarstar-ratingstarstar-full WooCommerce CRUD ready (except products exclusion via the _kuantokusta_hide meta) - Can be fixed with the wc_get_products meta argument (slow? need to measure query speed) Initialize the plugin. Our own order class and the main classes. Add settings links - This is here because inside the main class we cannot call the correct plugin_basename( __FILE__ ) Load the main class. +6 morekk_section_titlekk_settings_sectionkk_wrapkk_rightbarkk_webdados_invoicexpress_nagkuantokusta_hide_settings_right_bar+3 moreWC_Feed_KuantoKusta