Multi-Platform Stock Sync (MPSS) Security & Risk Analysis

wordpress.org/plugins/multi-platform-stock-sync

Seamlessly synchronize your inventory across WooCommerce and multiple e-commerce platforms.

0 active installs v1.0.2 PHP 7.0+ WP 5.0+ Updated Nov 3, 2024
e-commerceinventorymulti-platformstock-managementwoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Multi-Platform Stock Sync (MPSS) Safe to Use in 2026?

Generally Safe

Score 92/100

Multi-Platform Stock Sync (MPSS) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The static analysis of the "multi-platform-stock-sync" plugin v1.0.2 indicates a generally strong security posture. The absence of dangerous functions, properly escaped output, and the use of prepared statements for all SQL queries are positive signs. Importantly, there are no identified taint flows, which suggests that user-supplied data is not being improperly handled within the code.

However, a notable concern arises from the complete lack of nonce checks. While the plugin appears to have capability checks for its entry points, nonce checks are a critical defense against Cross-Site Request Forgery (CSRF) attacks. Their absence represents a significant potential vulnerability, as authenticated users could be tricked into executing unintended actions.

The plugin's vulnerability history is clear, with no recorded CVEs. This, combined with the positive static analysis findings (excluding the nonce issue), suggests that the developers have a good understanding of secure coding practices. Nevertheless, the lack of nonce checks is a direct gap that needs immediate attention to ensure the plugin's security.

Key Concerns

  • Missing nonce checks
Vulnerabilities
None known

Multi-Platform Stock Sync (MPSS) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Multi-Platform Stock Sync (MPSS) Release Timeline

v1.0.2Current
Code Analysis
Analyzed Apr 16, 2026

Multi-Platform Stock Sync (MPSS) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

100% escaped2 total outputs
Attack Surface

Multi-Platform Stock Sync (MPSS) Attack Surface

Entry Points4
Unprotected0

REST API Routes 4

GETPOST/wp-json/mpss/v1/platforms-settingsadmin/class-multi-platform-stock-sync-options.php:27
GETPOST/wp-json/mpss/v1/cronjob-settingsadmin/class-multi-platform-stock-sync-options.php:38
GET/wp-json/mpss/v1/logsadmin/class-multi-platform-stock-sync-options.php:49
GETPOST/wp-json/mpss/v1/log-settingsadmin/class-multi-platform-stock-sync-options.php:62
WordPress Hooks 12
actionplugins_loadedincludes/class-multi-platform-stock-sync.php:89
actionplugins_loadedincludes/class-multi-platform-stock-sync.php:181
actionadmin_enqueue_scriptsincludes/class-multi-platform-stock-sync.php:194
actionadmin_enqueue_scriptsincludes/class-multi-platform-stock-sync.php:195
actionadmin_menuincludes/class-multi-platform-stock-sync.php:196
actionrest_api_initincludes/class-multi-platform-stock-sync.php:210
actioninitincludes/class-multi-platform-stock-sync.php:224
actioncron_schedulesincludes/class-multi-platform-stock-sync.php:225
actionmpss_cron_hookincludes/class-multi-platform-stock-sync.php:226
actionmpss_cronjob_errorincludes/class-multi-platform-stock-sync.php:240
actionmpss_cronjob_startincludes/class-multi-platform-stock-sync.php:241
actionmpss_cronjob_endincludes/class-multi-platform-stock-sync.php:242

Scheduled Events 1

mpss_cron_hook
Maintenance & Trust

Multi-Platform Stock Sync (MPSS) Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedNov 3, 2024
PHP min version7.0
Downloads403

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Multi-Platform Stock Sync (MPSS) Developer Profile

Feras Jobeir

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Multi-Platform Stock Sync (MPSS)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/multi-platform-stock-sync/build/admin.css/wp-content/plugins/multi-platform-stock-sync/build/index.tsx.js
Script Paths
/wp-content/plugins/multi-platform-stock-sync/build/index.tsx.js
Version Parameters
multi-platform-stock-sync/build/admin.css?ver=multi-platform-stock-sync/build/index.tsx.js?ver=

HTML / DOM Fingerprints

CSS Classes
mpss-settings-page
JS Globals
mpss
REST Endpoints
/wp-json/mpss/v1/platforms-settings/wp-json/mpss/v1/cronjob-settings
FAQ

Frequently Asked Questions about Multi-Platform Stock Sync (MPSS)