Goodtill Stock Sync Security & Risk Analysis

wordpress.org/plugins/goodtill-stock-sync

Sync your Goodtill POS products and stock quantities with WooCommerce.

60 active installs v1.4.2 PHP 7.0+ WP 4.8+ Updated May 15, 2025
ecommerceeposinventoryposwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Goodtill Stock Sync Safe to Use in 2026?

Generally Safe

Score 100/100

Goodtill Stock Sync has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The "goodtill-stock-sync" v1.4.2 plugin exhibits a generally good security posture due to the absence of known vulnerabilities and a limited attack surface. The static analysis reveals no direct entry points like unprotected AJAX handlers, REST API routes, or shortcodes. Furthermore, the code demonstrates a commitment to secure SQL practices by using prepared statements for all its queries. The presence of nonce checks and file operations suggests some level of security awareness in the development. However, a significant concern arises from the output escaping, with only 46% of outputs being properly escaped. This leaves a substantial portion of the plugin's output potentially vulnerable to cross-site scripting (XSS) attacks if the data being output is not inherently safe. The lack of any recorded vulnerabilities in its history is a positive indicator, suggesting a stable and relatively secure code base over time. Despite the unescaped output, the overall impression is of a plugin that follows many best practices, but requires attention to its output sanitization to mitigate potential XSS risks.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Goodtill Stock Sync Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Goodtill Stock Sync Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
39
33 escaped
Nonce Checks
2
Capability Checks
0
File Operations
5
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

46% escaped72 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
actionExport (includes\admin.php:568)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Goodtill Stock Sync Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 23
actionadmin_enqueue_scriptsgtc-stock-sync.php:60
actionadmin_enqueue_scriptsgtc-stock-sync.php:80
actionadmin_menuincludes\admin.php:24
actionadmin_post_gtcsync_importincludes\admin.php:35
actionadmin_post_gtcsync_exportincludes\admin.php:40
actionadmin_headincludes\admin.php:57
filterwoocommerce_product_is_in_stockincludes\core.php:22
actionwoocommerce_order_status_pendingincludes\core.php:25
actionwoocommerce_order_status_processingincludes\core.php:26
actionwoocommerce_order_status_on-holdincludes\core.php:27
actionwoocommerce_order_status_completedincludes\core.php:28
actionwoocommerce_order_status_cancelledincludes\core.php:29
actionwoocommerce_order_status_failedincludes\core.php:30
actionwoocommerce_restock_refunded_itemincludes\core.php:32
filterwoocommerce_product_data_tabsincludes\core.php:35
actionwoocommerce_product_data_panelsincludes\core.php:36
actionwp_loadedincludes\cron.php:14
filtercron_schedulesincludes\cron.php:30
actionadmin_initincludes\export.php:12
actionadmin_initincludes\import.php:20
actionadmin_menuincludes\settings.php:11
actionadmin_initincludes\settings.php:21
actionadmin_initincludes\update.php:9
Maintenance & Trust

Goodtill Stock Sync Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 15, 2025
PHP min version7.0
Downloads4K

Community Trust

Rating20/100
Number of ratings1
Active installs60
Developer Profile

Goodtill Stock Sync Developer Profile

Goodtill Developer Team

1 plugin · 60 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Goodtill Stock Sync

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Goodtill Stock Sync