ICDSoft Reseller Store Security & Risk Analysis

wordpress.org/plugins/icdsoft-reseller-store

Start reselling web hosting services, domains and SSL Certificates on your website. Create your own web hosting company.

60 active installs v2.6.2 PHP 7.4+ WP 6.3+ Updated Jan 22, 2026
domainecommercehostingresellerstore
99
A · Safe
CVEs total1
Unpatched0
Last CVEDec 11, 2024
Safety Verdict

Is ICDSoft Reseller Store Safe to Use in 2026?

Generally Safe

Score 99/100

ICDSoft Reseller Store has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Dec 11, 2024Updated 3mo ago
Risk Assessment

The "icdsoft-reseller-store" plugin v2.6.2 exhibits a mixed security posture. While it demonstrates good practices in areas like prepared SQL statements and output escaping, significant concerns arise from its attack surface and a concerning lack of capability checks. The presence of a REST API route without proper permission callbacks represents a direct entry point that could be exploited without authentication, posing a notable risk. The taint analysis, while not showing critical or high severity flows, did reveal all analyzed flows had unsanitized paths, which is a general indicator of potential weaknesses in input handling, even if not currently leading to severe exploits.

The vulnerability history, particularly a past medium-severity Cross-site Scripting (XSS) vulnerability, suggests that the plugin has had issues with input sanitization for output. While the plugin is currently unpatched for this vulnerability, the fact that it occurred in the past coupled with the taint analysis findings warrants careful attention. Despite strong adherence to SQL and output escaping, the unprotected REST API endpoint is a primary vulnerability. The plugin's strengths lie in its diligent use of prepared statements and output escaping, but these are overshadowed by the direct unauthenticated access point and the general caution advised by the taint analysis. Therefore, while not critically flawed, significant attention is required to address the unprotected REST API.

Key Concerns

  • Unprotected REST API endpoint
  • All analyzed taint flows have unsanitized paths
  • Past medium XSS vulnerability
Vulnerabilities
1 published

ICDSoft Reseller Store Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-54320medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

ICDSoft Reseller Store <= 2.4.5 - Reflected Cross-Site Scripting

Dec 11, 2024 Patched in 2.5.0 (9d)
Version History

ICDSoft Reseller Store Release Timeline

v2.6.2Current
v2.6.1
v2.6.0
v2.5.6
v2.5.5
v2.5.4
v2.5.3
v2.5.2
v2.5.1
v2.5.0
v2.4.51 CVE
v2.4.41 CVE
v2.4.31 CVE
v2.4.21 CVE
v2.4.11 CVE
v2.4.01 CVE
v2.3.91 CVE
v2.3.81 CVE
v2.3.71 CVE
v2.3.61 CVE
Code Analysis
Analyzed Mar 16, 2026

ICDSoft Reseller Store Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
8 prepared
Unescaped Output
24
1892 escaped
Nonce Checks
8
Capability Checks
0
File Operations
8
External Requests
5
Bundled Libraries
1

Bundled Libraries

Stripe PHP

SQL Query Safety

89% prepared9 total queries

Output Escaping

99% escaped1916 total outputs
Data Flows · Security
12 unsanitized

Data Flow Analysis

12 flows12 with unsanitized paths
welcome_page_content (includes\admin\class-icd-hosting-admin-settings.php:99)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

ICDSoft Reseller Store Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

GET/wp-json/icd-hosting/v1/catalogincludes\class-icd-hosting-rest.php:8
WordPress Hooks 22
actioniniticd-hosting.php:106
actioniniticd-hosting.php:107
filterget_pagesicd-hosting.php:110
filterpre_get_postsicd-hosting.php:113
actionadmin_noticesincludes\admin\class-icd-hosting-admin-notices.php:120
actionadmin_noticesincludes\admin\class-icd-hosting-admin-notices.php:122
actionadmin_menuincludes\admin\class-icd-hosting-admin-settings.php:70
actionadmin_menuincludes\admin\class-icd-hosting-admin-settings.php:71
actionadmin_initincludes\admin\class-icd-hosting-admin-settings.php:72
actionadmin_menuincludes\admin\class-icd-hosting-admin-settings.php:73
actionadmin_headincludes\admin\class-icd-hosting-admin-settings.php:74
actionadmin_menuincludes\admin\class-icd-hosting-admin-setup-wizard.php:22
actionadmin_initincludes\admin\class-icd-hosting-admin-setup-wizard.php:23
actionadmin_enqueue_scriptsincludes\admin\class-icd-hosting-admin-setup-wizard.php:24
actioninitincludes\admin\class-icd-hosting-admin.php:18
actionadmin_initincludes\admin\class-icd-hosting-admin.php:19
actionwp_enqueue_scriptsincludes\class-icd-hosting-frontend-scripts.php:19
actioninitincludes\class-icd-hosting-install.php:14
filterget_pagesincludes\class-icd-hosting-install.php:108
filterquery_varsincludes\class-icd-hosting-query.php:22
actioninitincludes\class-icd-hosting-query.php:24
actionrest_api_initincludes\class-icd-hosting-rest.php:7
Maintenance & Trust

ICDSoft Reseller Store Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 22, 2026
PHP min version7.4
Downloads10K

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

ICDSoft Reseller Store Developer Profile

icdsoft

2 plugins · 1K total installs

99
trust score
Avg Security Score
98/100
Avg Patch Time
5 days
View full developer profile
Detection Fingerprints

How We Detect ICDSoft Reseller Store

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/icdsoft-reseller-store/assets/css/style.css/wp-content/plugins/icdsoft-reseller-store/assets/js/main.js
Script Paths
/wp-content/plugins/icdsoft-reseller-store/assets/js/main.js
Version Parameters
icdsoft-reseller-store/assets/css/style.css?ver=icdsoft-reseller-store/assets/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
icdsoft-reseller-store
Data Attributes
data-icdsoft-reseller-store-option
JS Globals
ICDSoftResellerStoreAjax
REST Endpoints
/wp-json/icdsoft-reseller-store/v1/process_order/wp-json/icdsoft-reseller-store/v1/domain_check
Shortcode Output
[icdsoft_hosting_order][icdsoft_domain_check][icdsoft_thankyou][icdsoft_terms]
FAQ

Frequently Asked Questions about ICDSoft Reseller Store