
FindShop Security & Risk Analysis
wordpress.org/plugins/findshopCustomer review collection tool for woo-commerce
Is FindShop Safe to Use in 2026?
Generally Safe
Score 85/100FindShop has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'findshop' v1.0.0 plugin presents a mixed security posture. On the positive side, it avoids dangerous functions, utilizes prepared statements for all SQL queries, and has no recorded vulnerability history, suggesting a lack of past exploitation and a potential for generally safe code. However, significant concerns arise from its attack surface. The plugin exposes two AJAX handlers, and crucially, neither of them has any authentication checks. This creates a direct and easy path for unauthenticated users to interact with potentially sensitive plugin functionality. Furthermore, only 65% of output is properly escaped, which, while not a critical flaw on its own, combined with the unauthenticated AJAX endpoints, could lead to cross-site scripting (XSS) vulnerabilities if malicious data is injected and then rendered without proper sanitization. The absence of nonce checks on AJAX handlers exacerbates this risk, as it becomes simpler to forge requests.
The vulnerability history being empty is a positive indicator, but it doesn't negate the immediate risks identified in the static analysis. The presence of an external HTTP request without further context is a minor concern, but the lack of authentication on critical entry points is the most pressing issue. Without proper authorization and validation, attackers could potentially abuse these AJAX endpoints to perform unintended actions or extract information. The plugin needs to implement robust authentication and authorization mechanisms for its AJAX handlers to significantly improve its security.
Key Concerns
- AJAX handlers without authentication checks
- Missing nonce checks on AJAX
- Unescaped output (35%)
FindShop Security Vulnerabilities
FindShop Release Timeline
FindShop Code Analysis
Output Escaping
FindShop Attack Surface
AJAX Handlers 2
WordPress Hooks 12
Maintenance & Trust
FindShop Maintenance & Trust
Maintenance Signals
Community Trust
FindShop Alternatives
Site Reviews
site-reviews
Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …
Better Business Reviews – Trustpilot WordPress Plugin
better-business-reviews
Better Business Reviews allows you to display your business reviews from a Trustpilot profile.
Buzzolt Reviews & Testimonials
buzzolt-reviews-testimonials
Easily collect, manage, and display testimonials and reviews on your WordPress site.
Breview – Order reviews for WooCommerce
breview
Collect reviews from order page after completion and display them on product pages on your WooCommerce store.
Business Reviews
business-reviews
Run unlimited free business review reports showing reviews across all major sites, your aggregate rating, public sentiment about your company and much …
FindShop Developer Profile
1 plugin · 0 total installs
How We Detect FindShop
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/findshop/assets/js/woo-findshop.co.jswoo-findshop.co.js?ver=HTML / DOM Fingerprints
<!-- WooCommerce FindShop require WooCommerce version Woo_findshop_admin