
Mergado Pack Security & Risk Analysis
wordpress.org/plugins/mergado-marketing-packConnect your online store to the e-commerce world and get even more from hundreds shopping channels
Is Mergado Pack Safe to Use in 2026?
Use With Caution
Score 56/100Mergado Pack has 2 unpatched vulnerabilities. Evaluate alternatives or apply available mitigations.
The "mergado-marketing-pack" plugin v4.2.1 exhibits a concerning security posture, primarily due to a large number of unprotected AJAX handlers. While the plugin shows good practices in using prepared statements for SQL queries and has a relatively low number of file operations and external HTTP requests, the absence of authentication checks on all identified entry points is a significant weakness. This directly exposes a large attack surface, making the plugin susceptible to unauthorized actions if other security measures are bypassed or absent.
The static analysis highlights a critical lack of security controls, with all 14 detected AJAX handlers lacking authentication. The taint analysis, while not revealing critical or high severity unsanitized flows, still shows 10 flows with unsanitized paths, which could potentially lead to unexpected behavior or vulnerabilities if combined with other weaknesses. The complete absence of nonce checks on these handlers is a glaring omission, especially given the plugin's history of Cross-Site Request Forgery (CSRF) vulnerabilities.
The vulnerability history, with two currently unpatched medium severity CVEs, reinforces the ongoing security risks associated with this plugin. The fact that these are medium severity and unpatched indicates a persistent need for attention. The recurrence of CSRF as a common vulnerability type further emphasizes the lack of proper input validation and authorization checks. While the plugin demonstrates some positive coding practices, the high number of unprotected entry points and the history of unpatched vulnerabilities present a substantial risk.
Key Concerns
- Unprotected AJAX handlers
- No nonce checks on AJAX handlers
- Unpatched CVEs (2 medium)
- Low output escaping percentage
- Unsanitized paths in taint flows
Mergado Pack Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Mergado Pack <= 4.2.0 - Cross-Site Request Forgery
Mergado Pack <= 4.1.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Mergado Pack Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Mergado Pack Attack Surface
AJAX Handlers 14
WordPress Hooks 87
Scheduled Events 1
Maintenance & Trust
Mergado Pack Maintenance & Trust
Maintenance Signals
Community Trust
Mergado Pack Alternatives
XML for Google Merchant Center
xml-for-google-merchant-center
Creates a XML feed that allows merchants to easily display their products across Google’s network.
Product XML Feed Manager for WooCommerce – Google Shopping, Social Sites, Skroutz & More
product-xml-feeds-for-woocommerce
Create your own XML feeds to export them, utilize tens of preconfigured shortcodes for you on your WooCommerce store as per marketplace needs
Pinterest for WooCommerce
pinterest-for-woocommerce
Get your products in front of Pinterest users searching for ideas and things to buy. Connect your WooCommerce store to make your catalog browsable.
WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel
wp-all-export
Easily export data from any post type, custom field, or taxonomy to a CSV, XML, or Excel file of any custom format. Supports WooCommerce products, ord …
WP Ultimate CSV Importer – Import CSV, XML & Excel into WordPress
wp-ultimate-csv-importer
Effortlessly import, export, and migrate your WordPress data with WP Ultimate CSV Importer. This all-in-one solution supports CSV, XML, and Excel file …
Mergado Pack Developer Profile
1 plugin · 800 total installs
How We Detect Mergado Pack
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mergado-marketing-pack/admin/css/mergado-marketing-pack.css/wp-content/plugins/mergado-marketing-pack/admin/css/mergado-marketing-pack.js/wp-content/plugins/mergado-marketing-pack/assets/css/mergado-marketing-pack.css/wp-content/plugins/mergado-marketing-pack/assets/js/mergado-marketing-pack.js/wp-content/plugins/mergado-marketing-pack/admin/js/mergado-marketing-pack.jsmergado-marketing-pack/admin/css/mergado-marketing-pack.css?ver=mergado-marketing-pack/admin/js/mergado-marketing-pack.js?ver=mergado-marketing-pack/assets/css/mergado-marketing-pack.css?ver=mergado-marketing-pack/assets/js/mergado-marketing-pack.js?ver=HTML / DOM Fingerprints
mergado-marketing-pack-menumergado-marketing-pack-menu-wrappermmp-wrapperdata-mergado-product-iddata-mergado-customer-idmergadoMarketingPackAdmin/wp-json/mergado-marketing-pack/v1/settings/wp-json/mergado-marketing-pack/v1/token