
ICDSoft Reseller Store Security & Risk Analysis
wordpress.org/plugins/icdsoft-reseller-storeStart reselling web hosting services, domains and SSL Certificates on your website. Create your own web hosting company.
Is ICDSoft Reseller Store Safe to Use in 2026?
Generally Safe
Score 99/100ICDSoft Reseller Store has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "icdsoft-reseller-store" plugin v2.6.2 exhibits a mixed security posture. While it demonstrates good practices in areas like prepared SQL statements and output escaping, significant concerns arise from its attack surface and a concerning lack of capability checks. The presence of a REST API route without proper permission callbacks represents a direct entry point that could be exploited without authentication, posing a notable risk. The taint analysis, while not showing critical or high severity flows, did reveal all analyzed flows had unsanitized paths, which is a general indicator of potential weaknesses in input handling, even if not currently leading to severe exploits.
The vulnerability history, particularly a past medium-severity Cross-site Scripting (XSS) vulnerability, suggests that the plugin has had issues with input sanitization for output. While the plugin is currently unpatched for this vulnerability, the fact that it occurred in the past coupled with the taint analysis findings warrants careful attention. Despite strong adherence to SQL and output escaping, the unprotected REST API endpoint is a primary vulnerability. The plugin's strengths lie in its diligent use of prepared statements and output escaping, but these are overshadowed by the direct unauthenticated access point and the general caution advised by the taint analysis. Therefore, while not critically flawed, significant attention is required to address the unprotected REST API.
Key Concerns
- Unprotected REST API endpoint
- All analyzed taint flows have unsanitized paths
- Past medium XSS vulnerability
ICDSoft Reseller Store Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
ICDSoft Reseller Store <= 2.4.5 - Reflected Cross-Site Scripting
ICDSoft Reseller Store Release Timeline
ICDSoft Reseller Store Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
ICDSoft Reseller Store Attack Surface
REST API Routes 1
WordPress Hooks 22
Maintenance & Trust
ICDSoft Reseller Store Maintenance & Trust
Maintenance Signals
Community Trust
ICDSoft Reseller Store Alternatives
WooCommerce
woocommerce
Everything you need to launch an online store in days and keep it growing for years. From your first sale to millions in revenue, Woo is with you.
Download Manager
download-manager
This File Management & Digital Store plugin will help you to control file downloads & sell digital products from your WP site.
Download Monitor
download-monitor
Powerful Download Manager Plugin for WordPress
SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments
surecart
Make ecommerce easy with a simple-to-use, all-in-one platform that anyone can set up in just a few minutes!
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy
easy-digital-downloads
The #1 eCommerce plugin to sell digital products & subscriptions. Accept payments with Stripe & PayPal. Sell ebooks, software & more.
ICDSoft Reseller Store Developer Profile
2 plugins · 1K total installs
How We Detect ICDSoft Reseller Store
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/icdsoft-reseller-store/assets/css/style.css/wp-content/plugins/icdsoft-reseller-store/assets/js/main.js/wp-content/plugins/icdsoft-reseller-store/assets/js/main.jsicdsoft-reseller-store/assets/css/style.css?ver=icdsoft-reseller-store/assets/js/main.js?ver=HTML / DOM Fingerprints
icdsoft-reseller-storedata-icdsoft-reseller-store-optionICDSoftResellerStoreAjax/wp-json/icdsoft-reseller-store/v1/process_order/wp-json/icdsoft-reseller-store/v1/domain_check[icdsoft_hosting_order][icdsoft_domain_check][icdsoft_thankyou][icdsoft_terms]