Feed KuantoKusta for WooCommerce – Free Security & Risk Analysis

wordpress.org/plugins/feed-kuantokusta-for-woocommerce

This plugin allows you to generate a WooCommerce product feed to submit to Kuanto Kusta, a Portuguese price comparison website and marketplace.

100 active installs v5.2 PHP 7.2+ WP 6.2+ Updated Mar 17, 2026
comparisone-commercefeedmarketplaceportugal
97
A · Safe
CVEs total1
Unpatched0
Last CVEApr 22, 2026
Safety Verdict

Is Feed KuantoKusta for WooCommerce – Free Safe to Use in 2026?

Generally Safe

Score 97/100

Feed KuantoKusta for WooCommerce – Free has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Apr 22, 2026Updated 2mo ago
Risk Assessment

The "feed-kuantokusta-for-woocommerce" plugin version 5.2 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL query handling, exclusively using prepared statements, and has a high percentage of properly escaped outputs. Furthermore, there is no recorded vulnerability history, suggesting a relatively stable and secure codebase in the past.

However, significant concerns arise from the static analysis. The plugin has a single AJAX entry point, which crucially lacks any authentication or capability checks. This represents a direct and unprotected pathway for attackers. The taint analysis further highlights this risk, revealing two flows with unsanitized paths classified as high severity. This indicates that data processed through these flows could potentially be exploited, although the lack of specific vulnerability types in the history prevents a more precise assessment of the exploitability. The absence of nonce checks on the AJAX handler is a critical oversight that exacerbates the risk posed by the unprotected entry point.

In conclusion, while the plugin avoids common pitfalls like raw SQL and outdated libraries, the unprotected AJAX handler and the identified high-severity unsanitized taint flows present a notable security risk. The lack of vulnerability history is a positive sign, but it does not mitigate the immediate threats identified in the code analysis. Users should exercise caution and consider the potential for unauthorized actions or data compromise through the exposed AJAX endpoint.

Key Concerns

  • Unprotected AJAX handler
  • High severity unsanitized taint flows (x2)
  • Missing nonce check on AJAX handler
Vulnerabilities
1 published

Feed KuantoKusta for WooCommerce – Free Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2026-39441high · 7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Feed KuantoKusta for WooCommerce – Free <= 5.3 - Unauthenticated SQL Injection

Apr 22, 2026 Patched in 5.3.1 (9d)
Version History

Feed KuantoKusta for WooCommerce – Free Release Timeline

v5.31 CVE
v5.2Current1 CVE
v5.11 CVE
v5.01 CVE
v4.11 CVE
v4.01 CVE
v3.41 CVE
v3.31 CVE
v3.21 CVE
v3.11 CVE
v3.01 CVE
v2.81 CVE
v2.71 CVE
v2.61 CVE
v2.51 CVE
v2.41 CVE
v2.31 CVE
v2.21 CVE
v2.11 CVE
v2.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Feed KuantoKusta for WooCommerce – Free Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
6
130 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

96% escaped136 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
render_products_feed (includes\class-wc-feed-kuantokusta.php:586)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Feed KuantoKusta for WooCommerce – Free Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_dismiss_webdados_invoicexpress_nagwebdados-invoicexpress-nag\webdados-invoicexpress-nag.php:77
WordPress Hooks 15
actionadmin_noticesfeed-kuantokusta-for-woocommerce.php:39
actioninitfeed-kuantokusta-for-woocommerce.php:42
actionadmin_initfeed-kuantokusta-for-woocommerce.php:56
actionbefore_woocommerce_initfeed-kuantokusta-for-woocommerce.php:115
filterinitincludes\class-wc-feed-kuantokusta.php:68
filterwoocommerce_settings_tabs_arrayincludes\class-wc-feed-kuantokusta.php:70
actionwoocommerce_settings_tabs_kuantokustaincludes\class-wc-feed-kuantokusta.php:71
actionwoocommerce_update_options_kuantokustaincludes\class-wc-feed-kuantokusta.php:72
actionkuantokusta_documentation_before_fieldsincludes\class-wc-feed-kuantokusta.php:74
filterwoocommerce_product_data_tabsincludes\class-wc-feed-kuantokusta.php:76
actionwoocommerce_product_data_panelsincludes\class-wc-feed-kuantokusta.php:77
actionwoocommerce_process_product_metaincludes\class-wc-feed-kuantokusta.php:78
actionadmin_noticesincludes\class-wc-feed-kuantokusta.php:82
actioninitincludes\class-wc-feed-kuantokusta.php:87
actionadmin_noticeswebdados-invoicexpress-nag\webdados-invoicexpress-nag.php:61
Maintenance & Trust

Feed KuantoKusta for WooCommerce – Free Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedMar 17, 2026
PHP min version7.2
Downloads11K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Feed KuantoKusta for WooCommerce – Free Developer Profile

Marco Almeida | Webdados

14 plugins · 15K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
191 days
View full developer profile
Detection Fingerprints

How We Detect Feed KuantoKusta for WooCommerce – Free

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/feed-kuantokusta-for-woocommerce/webdados-invoicexpress-nag/webdados-invoicexpress-nag.php/wp-content/plugins/feed-kuantokusta-for-woocommerce/images/kk.svg/wp-content/plugins/feed-kuantokusta-for-woocommerce/images/webdados.svg
Version Parameters
feed-kuantokusta-for-woocommerce

HTML / DOM Fingerprints

CSS Classes
kk_section_titlekk_settings_sectionkk_wrapkk_rightbarstar-ratingstarstar-full
HTML Comments
WooCommerce CRUD ready (except products exclusion via the _kuantokusta_hide meta) - Can be fixed with the wc_get_products meta argument (slow? need to measure query speed) Initialize the plugin. Our own order class and the main classes. Add settings links - This is here because inside the main class we cannot call the correct plugin_basename( __FILE__ ) Load the main class. +6 more
Data Attributes
kk_section_titlekk_settings_sectionkk_wrapkk_rightbarkk_webdados_invoicexpress_nagkuantokusta_hide_settings_right_bar+3 more
JS Globals
WC_Feed_KuantoKusta
FAQ

Frequently Asked Questions about Feed KuantoKusta for WooCommerce – Free