
MarketEngine Security & Risk Analysis
wordpress.org/plugins/marketengineA free WordPress plugin that allows you to build a multi vendor marketplace platform for any niche.
Is MarketEngine Safe to Use in 2026?
Generally Safe
Score 85/100MarketEngine has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The MarketEngine v1.1 plugin exhibits a mixed security posture. While it shows strengths in its use of prepared statements for SQL queries and a healthy number of nonce checks, significant concerns arise from its attack surface and taint analysis.
The plugin has a considerable attack surface with 19 AJAX handlers, a substantial 10 of which lack authentication checks. This directly exposes these endpoints to unauthorized access and potential exploitation. Furthermore, the taint analysis revealed 2 high-severity flows with unsanitized paths, indicating potential for cross-site scripting (XSS) or other injection vulnerabilities if user-supplied data is not properly handled before being used in sensitive operations.
The plugin's vulnerability history is remarkably clean, with no recorded CVEs. This suggests a history of responsible development or perhaps a lack of public scrutiny. However, this clean history should not overshadow the immediate risks identified in the static analysis, particularly the unprotected AJAX handlers and high-severity taint flows. The presence of the `unserialize` function, while not directly flagged as a vulnerability in the static analysis, is a known risk for deserialization vulnerabilities if not handled with extreme care, especially when dealing with untrusted input.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows (unsanitized paths)
- Dangerous function (unserialize)
- Low output escaping percentage
MarketEngine Security Vulnerabilities
MarketEngine Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
MarketEngine Attack Surface
AJAX Handlers 19
Shortcodes 11
WordPress Hooks 122
Scheduled Events 1
Maintenance & Trust
MarketEngine Maintenance & Trust
Maintenance Signals
Community Trust
MarketEngine Alternatives
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy
dokan-lite
Transform your WooCommerce site into a multivendor marketplace with Dokan – an AI powered & advanced WooCommerce marketplace solution
WCFM Marketplace – Multivendor Marketplace for WooCommerce
wc-multivendor-marketplace
The most featured and powerful multi vendor plugin for WordPress, setup fantastic woocommerce marketplace store in minutes.
WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors
wc-vendors
The original WooCommerce multi-vendor plugin. Easily create a WooCommerce marketplace with multi-seller, product vendor stores & vendor commissions.
Affiliate Super Assistent
amazonsimpleadmin
The flexible plugin for WordPress affiliates working with Amazon. Create your own templates, embed products by use of [asa]ASIN[/asa] shortcodes
AffiliateWP – Allowed Products
affiliatewp-allowed-products
Allows only specific products to generate commission in AffiliateWP.
MarketEngine Developer Profile
1 plugin · 10 total installs
How We Detect MarketEngine
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/marketengine/assets/css/marketengine-frontend.css/wp-content/plugins/marketengine/assets/js/marketengine-frontend.js/wp-content/plugins/marketengine/assets/css/flatpickr.min.css/wp-content/plugins/marketengine/assets/js/flatpickr.min.js/wp-content/plugins/marketengine/assets/js/marketengine-frontend.jsmarketengine/assets/css/marketengine-frontend.css?ver=marketengine/assets/js/marketengine-frontend.js?ver=HTML / DOM Fingerprints
marketengine-containermarketengine-content-wrappermarketengine-form-fielddata-marketengineme_globalsMarketEngineme_payment_gateways/wp-json/marketengine/v1/listings/wp-json/marketengine/v1/users[marketengine_auth][marketengine_listing][marketengine_transaction]