Kosmos eSync Dashboard Connector Security & Risk Analysis

wordpress.org/plugins/kosmos-esync-dashboard-connector

Connect point of sale, ERP and ecommerce applications. Sync inventory, transfer orders and manage product data in one place with the eSync Dashboard.

80 active installs v1.0.3 PHP + WP 4.0+ Updated Sep 16, 2024
erpintegrationpoint-of-saleposwoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Kosmos eSync Dashboard Connector Safe to Use in 2026?

Generally Safe

Score 92/100

Kosmos eSync Dashboard Connector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The kosmos-esync-dashboard-connector plugin version 1.0.3 exhibits a seemingly strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits the potential attack surface. The code also demonstrates good practices in its handling of SQL queries, utilizing prepared statements exclusively, and avoids dangerous functions and file operations. Furthermore, there's a recorded capability check, indicating some level of access control is implemented.

However, a notable concern arises from the output escaping, where only 31% of outputs are properly escaped. This indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. While taint analysis shows no current unsanitized flows, this is likely due to the limited attack surface identified. The absence of any recorded vulnerabilities in its history is positive, but it doesn't negate the risks posed by the poor output escaping. The plugin's strengths lie in its limited attack surface and secure SQL handling, but the low rate of output escaping is a significant weakness that requires immediate attention.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Kosmos eSync Dashboard Connector Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Kosmos eSync Dashboard Connector Release Timeline

v4.9
Code Analysis
Analyzed Mar 16, 2026

Kosmos eSync Dashboard Connector Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
27
12 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

31% escaped39 total outputs
Attack Surface

Kosmos eSync Dashboard Connector Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionplugins_loadedincludes\class-ked-connector.php:149
actionadmin_enqueue_scriptsincludes\class-ked-connector.php:164
actionadmin_enqueue_scriptsincludes\class-ked-connector.php:165
actionwp_enqueue_scriptsincludes\class-ked-connector.php:180
actionwp_enqueue_scriptsincludes\class-ked-connector.php:181
actionadmin_initincludes\wp-settings-framework.php:64
actionadmin_noticesincludes\wp-settings-framework.php:65
actionadmin_enqueue_scriptsincludes\wp-settings-framework.php:66
actionadmin_initked-connector.php:60
actionadmin_noticesked-connector.php:63
actionadmin_menuked-connector.php:93
actionadmin_bar_menuked-connector.php:99
actionadmin_initked-connector.php:122
Maintenance & Trust

Kosmos eSync Dashboard Connector Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedSep 16, 2024
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings3
Active installs80
Developer Profile

Kosmos eSync Dashboard Connector Developer Profile

kosmoscentral

1 plugin · 80 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Kosmos eSync Dashboard Connector

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kosmos-esync-dashboard-connector/public/images/kosmos_icon_small.png/wp-content/plugins/kosmos-esync-dashboard-connector/public/images/kosmos_logo.png/wp-content/plugins/kosmos-esync-dashboard-connector/public/css/ked-connector-public.css/wp-content/plugins/kosmos-esync-dashboard-connector/public/js/ked-connector-public.js
Script Paths
/wp-content/plugins/kosmos-esync-dashboard-connector/public/js/ked-connector-public.js
Version Parameters
kosmos-esync-dashboard-connector/public/css/ked-connector-public.css?ver=kosmos-esync-dashboard-connector/public/js/ked-connector-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
kosmos-plugin-logokedc-tabsemphasize
Data Attributes
data-kosmos-esync-dashboard-connector-version
Shortcode Output
<img class='kosmos-plugin-logo' src='' alt='Kosmos eSync Dashboard Connector' title='Kosmos eSync Dashboard Connector'/> <h1>Kosmos eSync Dashboard Connector</h1><ul class='kedc-tabs'><li><a id='kedcintro' href='#kedcintroduction'>Introduction</a></li><li><a href='https://www.kosmosesync.com' target='_blank'>Dashboard</a></li><li><a href='https://help.kosmosesync.com/' target='_blank'>Help Docs</a></li><li><a href='https://www.youtube.com/user/KosmosCentralTV/playlists' target='_blank'>Video Tutorials</a></li><li><a href='https://supportcenter.kosmoscentral.com/support/tickets/new' target='_blank'>Request Support</a></li><li class='emphasize'><a href='https://www.kosmoscentral.com/esync-cloud-pricing' target='_blank'>14 Day Free Trial</a></li></ul><hr /><div id='kedcintroduction'><p>Kosmos eSync Dashboard Connector allows you to access the Kosmos eSync Dashboard from inside WordPress. Existing eSync users can run Tasks to sync inventory and orders between applications and manage integration settings.</p><p>Kosmos eSync integrates data between leading point of sale, ERP, marketplace and ecommerce applications.</p><h3>Current integrations include:</h3><ul><li>- WooCommerce</li><li>- Revel Systems Point of Sale</li><li>- Lightspeed Retail Point of Sale</li><li>- Vend Point of Sale</li><li>- Acumatica ERP</li><li>- Integrate Amazon and eBay using marketplace tools</li><li>- Clover Point of Sale</li> <li>- View a complete list of integrations <a href='https://www.kosmoscentral.com/connections' target='_blank'>here</a></li></ul><h3>Features of Kosmos eSync Dashboard Connector:</h3><ul><li>- Quick link to Kosmos eSync Dashboard is added to the top menu of your WordPress admin area</li><li>- Quick link to help documentation</li><li>- Access to video tutorials</li><li>- Access to support center</li><li>- Requires the WooCommerce plugin to be installed</li></ul><h3>Frequently asked questions:</h3><p><strong>What is Kosmos eSync?</strong><br />An integration platform to streamline order and inventory management for businesses that sell both online and through brick and mortar stores.</p><p><strong>How do I make an eSync account?</strong><br />Visit us at <a href='https://www.kosmoscentral.com/esync-cloud-pricing' target='_blank'>kosmoscentral.com</a>, and select the free trial button to register a new account.</p><p><strong>I need help configuring my settings</strong><br />See our <a href='https://help.kosmosesync.com/' target='_blank'>help documentation</a>, or visit the <a href='https://supportcenter.kosmoscentral.com/support/tickets/new' target='_blank'>support center</a> to request assistance.</p></div>
FAQ

Frequently Asked Questions about Kosmos eSync Dashboard Connector