
Google Merchant Product Feed Security & Risk Analysis
wordpress.org/plugins/merchant-xml-feed-generatorEasily and quickly create XML Feeds for use on the Google Merchant Centre from your WooCommerce Store
Is Google Merchant Product Feed Safe to Use in 2026?
Generally Safe
Score 85/100Google Merchant Product Feed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'merchant-xml-feed-generator' v1.1.4 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any known CVEs and the complete reliance on prepared statements for SQL queries are significant strengths. Furthermore, the plugin demonstrates good practices by incorporating nonce checks and capability checks, and it has a minimal attack surface with no publicly exposed AJAX handlers, REST API routes, or shortcodes without proper authentication.
However, a notable concern is the presence of the `unserialize` function, which is inherently dangerous if used with untrusted input. While no specific taint flows were identified as critical or high severity, the potential for such a vulnerability exists. The output escaping is also only moderately effective at 58%, indicating a risk of cross-site scripting (XSS) vulnerabilities in certain scenarios.
In conclusion, while the plugin has a clean vulnerability history and avoids many common pitfalls, the identified use of `unserialize` and the suboptimal output escaping warrant attention. The plugin's strengths lie in its controlled attack surface and adherence to basic security checks, but the potential for deserialization and XSS vulnerabilities should be mitigated.
Key Concerns
- Use of dangerous unserialize function
- Moderately escaped output (58%)
Google Merchant Product Feed Security Vulnerabilities
Google Merchant Product Feed Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Data Flow Analysis
Google Merchant Product Feed Attack Surface
WordPress Hooks 14
Maintenance & Trust
Google Merchant Product Feed Maintenance & Trust
Maintenance Signals
Community Trust
Google Merchant Product Feed Alternatives
WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping
wp-product-feed-manager
Easily create high-quality product feeds for Google Shopping and Google Merchant Center in your WooCommerce store. Increase sales on Google now!
WebToffee WooCommerce Product Feeds – Google Shopping, Pinterest, TikTok Ads, & More
webtoffee-product-feed
Create WooCommerce product feeds containing unlimited number of products. Supports Google Product feed, Facebook catalog feed, Instagram, Bing & m …
ELEX WooCommerce Google Shopping (Google Product Feed)
elex-woocommerce-google-product-feed-plugin-basic
The ELEX WooCommerce Google Shopping (Google Product Feed) plugin is a free WooCommerce plugin that serves in feeding your WooCommerce products to Goo …
AW Feed Manager For WooCommerce Product
my-feed
Generate error-free woocommerce product feed plugin for Google Shopping, Google Merchant.
SJRubel Product Feed Generator
sjrubel-product-feed-generator
Short Description: WooCommerce plugin to generate Google Merchant compatible XML product feeds with filtering and field mapping support.
Google Merchant Product Feed Developer Profile
1 plugin · 10 total installs
How We Detect Google Merchant Product Feed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/merchant-xml-feed-generator/css/gmpf_styles.css/wp-content/plugins/merchant-xml-feed-generator/js/gmpf_scripts.js/wp-content/plugins/merchant-xml-feed-generator/datatables/datatables.min.css/wp-content/plugins/merchant-xml-feed-generator/datatables/datatables.min.js/wp-content/plugins/merchant-xml-feed-generator/tooltipster/css/tooltipster.css/wp-content/plugins/merchant-xml-feed-generator/tooltipster/css/themes/tooltipster-light.css/wp-content/plugins/merchant-xml-feed-generator/tooltipster/js/jquery.tooltipster.min.js/wp-content/plugins/merchant-xml-feed-generator/js/gmpf_scripts.jsgmpf_styles.css?ver=1.0.0gmpf_scripts.jsdatatables.min.css?ver=1.0.0datatables.min.jstooltipster.css?ver=1.0.0tooltipster-light.css?ver=1.0.0jquery.tooltipster.min.jsHTML / DOM Fingerprints
gmpf_blockgmpf_shop_linkgmpf_descriptiongmpf_default_google_categorygmpf_filtertypegmpf_productsgmpf_shipping_method+1 more