Meliconnect Security & Risk Analysis

wordpress.org/plugins/meliconnect

Seamless WooCommerce and Mercado Libre integration with real-time sync of products, stock, and prices.

50 active installs v1.6.2 PHP 8.0+ WP 5.8+ Updated Feb 26, 2026
integrationmarketplacemercadolibresyncwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Meliconnect Safe to Use in 2026?

Generally Safe

Score 100/100

Meliconnect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The meliconnect plugin v1.6.2 exhibits a significant security concern due to its entirely unprotected attack surface. With 36 identified entry points, all of which are accessible without authentication or authorization checks, an attacker could potentially interact with and exploit these handlers directly. While the static analysis reveals good practices in other areas, such as a high percentage of prepared SQL statements and properly escaped output, the lack of access control on nearly all its interaction points overshadows these strengths. The plugin also utilizes 37 nonce checks and 26 capability checks, which are positive signs for security, but these appear to be inconsistently applied or absent from the identified AJAX and REST API endpoints.

The vulnerability history of meliconnect is notably clean, with no recorded CVEs. This absence of known vulnerabilities and past incidents might suggest a well-maintained codebase or limited historical scrutiny. However, the lack of past issues does not negate the immediate risks presented by the current code analysis. The total absence of critical or high-severity taint flows is a positive indicator, suggesting that data manipulation within the plugin is likely handled with care. Nevertheless, the substantial unprotected attack surface remains the primary area of concern.

In conclusion, while meliconnect demonstrates good practices in areas like SQL query preparation and output escaping, and has a clean vulnerability history, the critical flaw of having its entire attack surface exposed without authentication or permission checks poses a significant risk. This oversight could allow for unauthorized actions or denial-of-service attacks. The plugin's strengths in data handling are negated by this fundamental security deficiency.

Key Concerns

  • Unprotected AJAX handlers
  • Unprotected REST API routes
  • Large attack surface without auth
Vulnerabilities
None known

Meliconnect Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Meliconnect Code Analysis

Dangerous Functions
0
Raw SQL Queries
20
100 prepared
Unescaped Output
33
530 escaped
Nonce Checks
37
Capability Checks
26
File Operations
0
External Requests
9
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

83% prepared120 total queries

Output Escaping

94% escaped563 total outputs
Data Flows
All sanitized

Data Flow Analysis

6 flows
handleSaveGeneralSettings (includes\Core\Controllers\SettingController.php:93)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
36 unprotected

Meliconnect Attack Surface

Entry Points36
Unprotected36

AJAX Handlers 33

authwp_ajax_meliconnect_settings_get_general_htmlincludes\Core\AjaxManager.php:21
authwp_ajax_meliconnect_settings_get_export_htmlincludes\Core\AjaxManager.php:22
authwp_ajax_meliconnect_settings_get_import_htmlincludes\Core\AjaxManager.php:23
authwp_ajax_meliconnect_settings_get_sync_htmlincludes\Core\AjaxManager.php:24
authwp_ajax_meliconnect_save_general_settingsincludes\Core\AjaxManager.php:26
authwp_ajax_meliconnect_save_export_settingsincludes\Core\AjaxManager.php:27
authwp_ajax_meliconnect_save_import_settingsincludes\Core\AjaxManager.php:28
authwp_ajax_meliconnect_save_sync_settingsincludes\Core\AjaxManager.php:29
authwp_ajax_meliconnect_get_meli_user_listingsincludes\Core\AjaxManager.php:32
authwp_ajax_meliconnect_reset_user_listingsincludes\Core\AjaxManager.php:33
authwp_ajax_meliconnect_init_import_processincludes\Core\AjaxManager.php:34
authwp_ajax_meliconnect_cancel_custom_importincludes\Core\AjaxManager.php:35
authwp_ajax_meliconnect_cancel_finished_processesincludes\Core\AjaxManager.php:36
authwp_ajax_meliconnect_bulk_import_actionincludes\Core\AjaxManager.php:37
authwp_ajax_meliconnect_desvinculate_woo_productincludes\Core\AjaxManager.php:38
authwp_ajax_meliconnect_match_listings_with_productsincludes\Core\AjaxManager.php:39
authwp_ajax_meliconnect_clear_matchesincludes\Core\AjaxManager.php:40
authwp_ajax_meliconnect_get_match_available_productsincludes\Core\AjaxManager.php:41
authwp_ajax_meliconnect_apply_matchincludes\Core\AjaxManager.php:42
authwp_ajax_meliconnect_clear_selected_products_matchincludes\Core\AjaxManager.php:43
authwp_ajax_meliconnect_bulk_export_actionincludes\Core\AjaxManager.php:46
authwp_ajax_meliconnect_cancel_custom_exportincludes\Core\AjaxManager.php:47
authwp_ajax_meliconnect_desvinculate_listingincludes\Core\AjaxManager.php:48
authwp_ajax_meliconnect_clean_custom_export_processincludes\Core\AjaxManager.php:49
authwp_ajax_meliconnect_fill_products_stepincludes\Core\AjaxManager.php:51
authwp_ajax_meliconnect_load_meli_categoriesincludes\Core\AjaxManager.php:54
authwp_ajax_meliconnect_update_meli_categoryincludes\Core\AjaxManager.php:55
authwp_ajax_meliconnect_import_single_listingincludes\Core\AjaxManager.php:56
authwp_ajax_meliconnect_export_single_listingincludes\Core\AjaxManager.php:57
authwp_ajax_meliconnect_unlink_single_listingincludes\Core\AjaxManager.php:58
authwp_ajax_meliconnect_save_template_dataincludes\Core\AjaxManager.php:59
authwp_ajax_meliconnect_get_process_progressincludes\Core\AjaxManager.php:62
authwp_ajax_meliconnect_dismiss_messageincludes\Core\AjaxManager.php:65

REST API Routes 3

POST/wp-json/meliconnect/v1/update_domainincludes\Core\ApiManager.php:27
GET/wp-json/meliconnect/v1/statusincludes\Core\ApiManager.php:37
POST/wp-json/meliconnect/v1/sync/productincludes\Core\ApiManager.php:47
WordPress Hooks 31
actionrest_api_initincludes\Core\ApiManager.php:20
actioninitincludes\Core\CronManager.php:55
actioninitincludes\Core\CronManager.php:56
filtercron_schedulesincludes\Core\CronManager.php:64
actionadmin_noticesincludes\Core\Initialize.php:36
actionplugins_loadedincludes\Core\Initialize.php:45
actionadmin_noticesincludes\Core\Initialize.php:55
actioninitincludes\Core\Initialize.php:56
actionplugins_loadedincludes\Core\Initialize.php:180
actionadmin_menuincludes\Core\Initialize.php:187
actionadmin_enqueue_scriptsincludes\Core\Initialize.php:189
actionadmin_enqueue_scriptsincludes\Core\Initialize.php:191
actionadd_meta_boxesincludes\Core\Services\ProductEdit.php:47
actionadd_meta_boxesincludes\Core\Services\ProductEdit.php:48
actionwoocommerce_product_options_pricingincludes\Core\Services\ProductEdit.php:49
actionwoocommerce_product_options_inventory_product_dataincludes\Core\Services\ProductEdit.php:50
filterwoocommerce_product_data_tabsincludes\Core\Services\ProductEdit.php:51
actionwoocommerce_product_data_panelsincludes\Core\Services\ProductEdit.php:52
actionwoocommerce_product_data_panelsincludes\Core\Services\ProductEdit.php:53
actionwoocommerce_product_options_attributesincludes\Core\Services\ProductEdit.php:55
actionwoocommerce_after_product_attribute_settingsincludes\Core\Services\ProductEdit.php:57
actionwoocommerce_process_product_metaincludes\Core\Services\ProductEdit.php:59
actionwoocommerce_admin_process_variation_objectincludes\Core\Services\ProductEdit.php:61
actionwoocommerce_variation_optionsincludes\Core\Services\ProductEdit.php:63
actionadmin_menuincludes\Modules\Exporter\Exporter.php:16
actionadmin_enqueue_scriptsincludes\Modules\Exporter\Exporter.php:17
actionadmin_enqueue_scriptsincludes\Modules\Exporter\Exporter.php:18
actionadmin_menuincludes\Modules\Importer\Importer.php:15
actionadmin_enqueue_scriptsincludes\Modules\Importer\Importer.php:16
actionadmin_enqueue_scriptsincludes\Modules\Importer\Importer.php:17
actionupgrader_process_completemeliconnect.php:100
Maintenance & Trust

Meliconnect Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 26, 2026
PHP min version8.0
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs50
Developer Profile

Meliconnect Developer Profile

Mercadolibre Connect

1 plugin · 50 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Meliconnect

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/meliconnect/assets/css/main.css/wp-content/plugins/meliconnect/assets/css/vendor.css/wp-content/plugins/meliconnect/assets/js/app.js/wp-content/plugins/meliconnect/assets/js/chunk-vendors.js
Script Paths
/wp-content/plugins/meliconnect/assets/js/app.js/wp-content/plugins/meliconnect/assets/js/chunk-vendors.js
Version Parameters
meliconnect/assets/css/main.css?ver=meliconnect/assets/css/vendor.css?ver=meliconnect/assets/js/app.js?ver=meliconnect/assets/js/chunk-vendors.js?ver=

HTML / DOM Fingerprints

CSS Classes
meliconnect-notificationmeliconnect-is-link
Data Attributes
data-meliconnect
JS Globals
meliconnect_params
FAQ

Frequently Asked Questions about Meliconnect