Mercado Lite — Multi-Vendor Marketplace for WooCommerce Security & Risk Analysis

wordpress.org/plugins/mercado

Mercado turns your WooCommerce store into a fully-fledged multi-vendor marketplace with easy vendor management, customizable commissions, & seamle …

10 active installs v2.3.0 PHP 5.6.2+ WP 3.0.1+ Updated Jan 31, 2026
multivendor-marketplacewoocommerce-marketplacewoocommerce-multivendorwordpress-marketplacewordpress-multivendor
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Mercado Lite — Multi-Vendor Marketplace for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Mercado Lite — Multi-Vendor Marketplace for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "mercado" plugin v2.3.0 demonstrates a generally strong security posture based on the provided static analysis. The plugin utilizes prepared statements for all its SQL queries and has a high rate of proper output escaping, significantly mitigating common vulnerabilities like SQL injection and Cross-Site Scripting (XSS). The presence of numerous nonce and capability checks further indicates an effort to secure entry points. The lack of critical or high-severity taint flows, along with a clean vulnerability history, suggests responsible development practices and diligent patching of any past issues.

However, a few areas warrant attention. While the attack surface of direct entry points like AJAX handlers and REST API routes appears to be protected, the plugin does expose functionality through three shortcodes. Although the static analysis reports zero unprotected entry points, the security of these shortcodes relies entirely on the internal capability checks. Any misconfiguration or oversight in these checks could potentially lead to vulnerabilities. Additionally, the plugin makes three external HTTP requests, which, while not inherently a vulnerability, could become a vector if the external service is compromised or if the plugin handles the responses insecurely. The bundled libraries, DataTables and Select2, should also be monitored for known vulnerabilities in their specific versions, though no outdated library issues were explicitly flagged in this analysis.

Key Concerns

  • Shortcodes could be potential attack vectors
  • External HTTP requests could be a risk
Vulnerabilities
None known

Mercado Lite — Multi-Vendor Marketplace for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Mercado Lite — Multi-Vendor Marketplace for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
235 prepared
Unescaped Output
47
782 escaped
Nonce Checks
82
Capability Checks
14
File Operations
0
External Requests
3
Bundled Libraries
2

Bundled Libraries

DataTablesSelect2

SQL Query Safety

100% prepared236 total queries

Output Escaping

94% escaped829 total outputs
Data Flows
All sanitized

Data Flow Analysis

25 flows
<rtwmer-mercado-order-functionality> (admin\partials\admin-includes\rtwmer-mercado-order-functionality.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Mercado Lite — Multi-Vendor Marketplace for WooCommerce Attack Surface

Entry Points3
Unprotected0

Shortcodes 3

[Vendor_Dashboard] includes\rtwmer-class-mercado.php:257
[Vendor_Store] includes\rtwmer-class-mercado.php:259
[rtwmer_extra_product_option] public\rtwmer-class-mercado-public.php:61
WordPress Hooks 3
actionadmin_noticesrtwmer-mercado.php:99
actionadmin_initrtwmer-mercado.php:101
actionbefore_woocommerce_initrtwmer-mercado.php:144
Maintenance & Trust

Mercado Lite — Multi-Vendor Marketplace for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 31, 2026
PHP min version5.6.2
Downloads8K

Community Trust

Rating100/100
Number of ratings5
Active installs10
Developer Profile

Mercado Lite — Multi-Vendor Marketplace for WooCommerce Developer Profile

RedefiningTheWeb

6 plugins · 2K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
180 days
View full developer profile
Detection Fingerprints

How We Detect Mercado Lite — Multi-Vendor Marketplace for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mercado/assets/css/mercado-backend.css/wp-content/plugins/mercado/assets/js/mercado-backend.js/wp-content/plugins/mercado/assets/common-js/mercado-common.js/wp-content/plugins/mercado/assets/bundle/mercado-bundle.js/wp-content/plugins/mercado/assets/css/mercado-frontend.css/wp-content/plugins/mercado/assets/js/mercado-frontend.js
Script Paths
/wp-content/plugins/mercado/assets/common-js/mercado-common.js/wp-content/plugins/mercado/assets/bundle/mercado-bundle.js
Version Parameters
mercado-backend.css?ver=mercado-backend.js?ver=mercado-common.js?ver=mercado-bundle.js?ver=mercado-frontend.css?ver=mercado-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
rtwmer_admin_areartwmer-backend-wrapperrtwmer-pro-upgrade-wrapperrtwmer_frontend_areartwmer-frontend-wrapper
HTML Comments
<!-- Mercado Lite Lite Multi-Vendor Marketplace for WooCommerce --><!-- Plugin Constant --><!-- BEGIN Mercado Lite Plugin --><!-- END Mercado Lite Plugin -->+2 more
Data Attributes
data-rtwmer-admin-urldata-rtwmer-plugin-urldata-rtwmer-home-urldata-rtwmer-plugin-dirdata-rtwmer-frontend-url
JS Globals
rtwmer_backend_paramsrtwmer_frontend_params
REST Endpoints
/wp-json/rtwmer-mercado/v1
FAQ

Frequently Asked Questions about Mercado Lite — Multi-Vendor Marketplace for WooCommerce