Connect Products with Shopify Security & Risk Analysis

wordpress.org/plugins/mainichi-shopify-products-connect

You can connect Shopify to retrieve all the products in your store and automatically register them in a custom WordPress post.

50 active installs v1.1.8 PHP 7.2+ WP 5.0+ Updated Jan 23, 2026
connectproductshopify
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Connect Products with Shopify Safe to Use in 2026?

Generally Safe

Score 100/100

Connect Products with Shopify has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The "mainichi-shopify-products-connect" v1.1.8 plugin exhibits a generally good security posture, with no known critical vulnerabilities or historically recorded CVEs. The static analysis shows a reasonable approach to security, with no dangerous functions, all SQL queries using prepared statements, and no critical or high-severity taint flows identified. The absence of raw SQL queries is a significant strength. However, there are areas for improvement. The plugin utilizes external HTTP requests and file operations, which can sometimes introduce attack vectors if not handled with extreme care. A concerning finding is the lack of capability checks on any entry points, despite the presence of non-user-facing AJAX handlers. While there are nonce checks, the absence of capability checks means that any authenticated user could potentially trigger these AJAX actions, regardless of their intended permissions. The output escaping, while at 72%, is not perfect, leaving a small window for potential cross-site scripting (XSS) vulnerabilities if sensitive data is outputted without proper sanitization. The plugin's overall security is decent due to the lack of known severe vulnerabilities and good SQL practices, but the absence of capability checks on entry points and less-than-perfect output escaping are notable weaknesses that elevate its risk profile.

Key Concerns

  • No capability checks on entry points
  • Output escaping at 72%
  • Presence of file operations
  • Presence of external HTTP requests
Vulnerabilities
None known

Connect Products with Shopify Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Connect Products with Shopify Release Timeline

v1.1.8Current
v1.1.7
v1.1.6
v1.1.5
v1.1.4
v1.1.3
v1.1.2
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Connect Products with Shopify Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
150
391 escaped
Nonce Checks
3
Capability Checks
0
File Operations
9
External Requests
7
Bundled Libraries
0

Output Escaping

72% escaped541 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<shopify_settings> (shopify_settings.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Connect Products with Shopify Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 4

authwp_ajax_shopifyConnectfunctions/cps_connect.php:320
noprivwp_ajax_shopifyConnectfunctions/cps_connect.php:321
authwp_ajax_shopifyDeletefunctions/cps_other.php:163
noprivwp_ajax_shopifyDeletefunctions/cps_other.php:164

Shortcodes 2

[shopifyBuyButton] functions/cps_buy-button.php:664
[shopifyProductsList] functions/cps_products-list.php:210
WordPress Hooks 8
actioninitfunctions/cps_create.php:57
filtermanage_product_posts_columnsfunctions/cps_create.php:132
actionmanage_product_posts_custom_columnfunctions/cps_create.php:133
actionadmin_menufunctions/cps_create.php:144
actionadmin_print_stylesfunctions/cps_other.php:50
actionwp_enqueue_scriptsfunctions/cps_other.php:223
actionadmin_enqueue_scriptsfunctions/cps_other.php:230
filterplugin_action_linksmainichi-shopify-products-connect.php:48
Maintenance & Trust

Connect Products with Shopify Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.5
Last updatedJan 23, 2026
PHP min version7.2
Downloads3K

Community Trust

Rating20/100
Number of ratings1
Active installs50
Developer Profile

Connect Products with Shopify Developer Profile

mainichiweb

3 plugins · 2K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
10 days
View full developer profile
Detection Fingerprints

How We Detect Connect Products with Shopify

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mainichi-shopify-products-connect/css/style_shopify-font.php/wp-content/plugins/mainichi-shopify-products-connect/css/style_shopify-buy-button.php/wp-content/plugins/mainichi-shopify-products-connect/css/style_shopify-inline.php
Script Paths
/wp-content/plugins/mainichi-shopify-products-connect/functions/cps_create.php/wp-content/plugins/mainichi-shopify-products-connect/functions/cps_connect.php/wp-content/plugins/mainichi-shopify-products-connect/functions/cps_buy-button.php/wp-content/plugins/mainichi-shopify-products-connect/functions/cps_products-list.php/wp-content/plugins/mainichi-shopify-products-connect/functions/cps_translate.php/wp-content/plugins/mainichi-shopify-products-connect/functions/cps_svg.php+1 more

HTML / DOM Fingerprints

HTML Comments
<!-- Template Name: その他 -->
Data Attributes
name="shopify_product"
JS Globals
CONNECT_PRODUCTS_WITH_SHOPIFY__PLUGIN_URL
FAQ

Frequently Asked Questions about Connect Products with Shopify