IT Guild Amazon Feed Security & Risk Analysis

wordpress.org/plugins/itg-amazon-feed

Create your own amazon product feed quick and easy.

0 active installs v1.0 PHP 5.4+ WP 4.5+ Updated Feb 25, 2019
amazonfeedproducs-feed
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is IT Guild Amazon Feed Safe to Use in 2026?

Generally Safe

Score 85/100

IT Guild Amazon Feed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "itg-amazon-feed" v1.0 plugin exhibits a generally strong security posture based on the provided static analysis. The complete absence of identified vulnerabilities in its history and the lack of critical findings in taint analysis are positive indicators. The code also demonstrates good practices by utilizing prepared statements for all SQL queries and including nonce and capability checks, suggesting an awareness of common WordPress security pitfalls. Furthermore, the limited attack surface with zero identified entry points without authentication is a significant strength.

However, a notable concern arises from the low percentage of properly escaped output (17%). This suggests that a substantial portion of the plugin's output is not being properly sanitized, leaving it vulnerable to Cross-Site Scripting (XSS) attacks. While no specific XSS vulnerabilities were flagged in the taint analysis, the potential exists and should be addressed. The absence of external HTTP requests and file operations, along with no bundled libraries, further simplifies the security landscape but doesn't mitigate the output escaping issue.

In conclusion, the "itg-amazon-feed" v1.0 plugin has a good foundation in terms of preventing common injection and unauthorized access vulnerabilities. Its clean vulnerability history is reassuring. The primary area requiring immediate attention is the insufficient output escaping, which poses a significant risk of XSS vulnerabilities that could be exploited if user-supplied data is displayed without proper sanitization.

Key Concerns

  • Low output escaping percentage
Vulnerabilities
None known

IT Guild Amazon Feed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

IT Guild Amazon Feed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
55
11 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

17% escaped66 total outputs
Attack Surface

IT Guild Amazon Feed Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actioninititg-amazon-feed.php:49
actioninititg-amazon-feed.php:72
filtertemplate_includeitg-amazon-feed.php:94
actionadd_meta_boxes_amznfeeditg-amazon-feed.php:112
actionsave_post_amznfeeditg-amazon-feed.php:259
actionfeed_category_edit_form_fieldsitg-amazon-feed.php:365
actionedited_feed_categoryitg-amazon-feed.php:387
filtertheme_page_templatesitg-amazon-feed.php:394
filterpage_templateitg-amazon-feed.php:413
Maintenance & Trust

IT Guild Amazon Feed Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedFeb 25, 2019
PHP min version5.4
Downloads979

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

IT Guild Amazon Feed Developer Profile

IT Guild

2 plugins · 20 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect IT Guild Amazon Feed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
amzn_product_urlamzn_product_headlineamzn_product_summaryamzn_product_rankamzn_product_awardamzn_product_rating+4 more
FAQ

Frequently Asked Questions about IT Guild Amazon Feed