
Mercantor Security & Risk Analysis
wordpress.org/plugins/mercantorSeamlessly sync your WooCommerce products to Google Merchant Center with real-time updates, multilingual support, and automatic error handling.
Is Mercantor Safe to Use in 2026?
Generally Safe
Score 100/100Mercantor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'mercantor' plugin v1.2.0 presents a mixed security posture. While it demonstrates strong practices in code sanitation, with a very high percentage of SQL queries using prepared statements and a near-perfect rate of output escaping, significant concerns arise from its attack surface. All 13 identified REST API routes lack permission callbacks, meaning they are accessible and potentially executable by any user, regardless of their role or logged-in status. This creates a substantial risk of unauthorized actions or data exposure through these unprotected endpoints.
The absence of known vulnerabilities in its history is a positive indicator, suggesting that developers may be proactive or that the plugin has not been a target. However, this cannot overshadow the immediate risks posed by the exposed REST API. The plugin also has a single cron event, which, while not explicitly stated as unprotected, warrants scrutiny to ensure it doesn't become an additional attack vector if not properly secured. The presence of nonce checks and capability checks, though limited in number, suggests an awareness of security principles, but their implementation is not comprehensive enough to mitigate the risks of the open REST API.
In conclusion, 'mercantor' v1.2.0 exhibits excellent code hygiene regarding SQL and output handling. However, the plugin's security is severely compromised by a large, unprotected attack surface primarily consisting of REST API endpoints. The lack of authentication and authorization on these points is the most critical finding and represents a significant security weakness that attackers could exploit. Despite a clean vulnerability history, the inherent design flaw in exposing these endpoints makes the plugin a high-risk component until these are properly secured.
Key Concerns
- REST API routes without permission callbacks
- Total entry points without protection
- Limited nonce checks
- Limited capability checks
Mercantor Security Vulnerabilities
Mercantor Release Timeline
Mercantor Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Mercantor Attack Surface
REST API Routes 13
WordPress Hooks 18
Scheduled Events 1
Maintenance & Trust
Mercantor Maintenance & Trust
Maintenance Signals
Community Trust
Mercantor Alternatives
WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping
wp-product-feed-manager
The WooCommerce product feed plugin built for Google. Create a Google Merchant feed in 5 minutes—no coding, no errors. Start selling on Google Shoppin …
WebToffee WooCommerce Product Feeds – Google Shopping, Pinterest, TikTok Ads, & More
webtoffee-product-feed
Create WooCommerce product feeds containing unlimited number of products. Supports Google Product feed, Facebook catalog feed, Instagram, Bing & m …
ELEX WooCommerce Google Shopping (Google Product Feed)
elex-woocommerce-google-product-feed-plugin-basic
The ELEX WooCommerce Google Shopping (Google Product Feed) plugin is a free WooCommerce plugin that serves in feeding your WooCommerce products to Goo …
GTIN Product Feed for Google Shopping
gtin-product-feed-for-google-shopping
Generate Google Shopping product feeds for WooCommerce. Add GTIN, Brand, MPN fields. Google Merchant Center compliant XML feeds. Free & lightweight.
Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce
woo-product-feed-pro
Most popular WooCommerce product feed plugin supporting Google shopping feed, meta/facebook feed, bing product feed & more.
Mercantor Developer Profile
2 plugins · 0 total installs
How We Detect Mercantor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mercantor/assets/css/mercantor.css/wp-content/plugins/mercantor/assets/js/mercantor.js/wp-content/plugins/mercantor/assets/js/mercantor.jsmercantor/assets/css/mercantor.css?ver=mercantor/assets/js/mercantor.js?ver=HTML / DOM Fingerprints
mercantor-setup-noticedata-mercantor-product-iddata-mercantor-sync-statusMercantor/wp-json/mercantor/v1/sync/wp-json/mercantor/v1/products/wp-json/mercantor/v1/settings