Muzaara Content API Microsoft/Bing Data Feed Security & Risk Analysis

wordpress.org/plugins/muzaara-micosoft-bing-product-data-feed

Microsoft Ads Data Feed - Integrates your WooCommerce Products into Microsoft Merchant Center using the content API or XML data feeds.

10 active installs v2.0 PHP 7.3+ WP 4.9+ Updated Mar 1, 2024
bing-adsbing-data-feedmicrosoft-adsmicrosoft-shoppingwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Muzaara Content API Microsoft/Bing Data Feed Safe to Use in 2026?

Generally Safe

Score 85/100

Muzaara Content API Microsoft/Bing Data Feed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "muzaara-microsoft-bing-product-data-feed" v2.0 plugin exhibits a mixed security posture. While it demonstrates strong practices in output escaping, with all 51 outputs properly escaped, and has no recorded historical vulnerabilities, there are significant concerns regarding its attack surface. A notable six of the sixteen AJAX handlers lack authentication checks, presenting a direct pathway for unauthenticated attackers to potentially interact with sensitive functionalities. Furthermore, the presence of a single SQL query that does not utilize prepared statements, while not a critical flaw in isolation, indicates a potential for SQL injection vulnerabilities if input is not rigorously validated and sanitized elsewhere.

The absence of taint analysis results and the lack of known CVEs are positive indicators. However, the identified unprotected AJAX endpoints represent a substantial security risk that could be exploited without any user authentication. The plugin also lacks nonce checks on its AJAX handlers, which is a critical security measure to prevent Cross-Site Request Execution (CSRF) attacks. The 7 file operations, while not specified as dangerous, could also become a vector if not handled with extreme care, especially in conjunction with the unprotected AJAX endpoints.

In conclusion, the plugin's strengths lie in its output sanitization and clean vulnerability history. However, the significant number of unprotected AJAX handlers and the absence of nonce checks on these handlers are major weaknesses. The single un-prepared SQL query is another area of concern that requires attention. Addressing these entry points with proper authentication and nonce validation is crucial to improving the plugin's overall security.

Key Concerns

  • Unprotected AJAX handlers
  • Raw SQL query without prepared statements
  • Missing nonce checks on AJAX
Vulnerabilities
None known

Muzaara Content API Microsoft/Bing Data Feed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Muzaara Content API Microsoft/Bing Data Feed Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
0
51 escaped
Nonce Checks
0
Capability Checks
12
File Operations
7
External Requests
5
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

100% escaped51 total outputs
Attack Surface
6 unprotected

Muzaara Content API Microsoft/Bing Data Feed Attack Surface

Entry Points16
Unprotected6

AJAX Handlers 16

authwp_ajax_muzaara_woopf_bing_checkAuthclass\Ajax.php:25
authwp_ajax_muzaara_woopf_bing_getAccountsclass\Ajax.php:26
authwp_ajax_muzaara_woopf_bing_linkAccountclass\Ajax.php:27
authwp_ajax_muzaara_woopf_bing_checkLinkclass\Ajax.php:28
authwp_ajax_muzaara_woopf_bing_getProductFieldsclass\Ajax.php:29
authwp_ajax_muzaara_woopf_bing_getProductCategoriesclass\Ajax.php:30
authwp_ajax_muzaara_woopf_bing_searchCatclass\Ajax.php:31
authwp_ajax_muzaara_woopf_bing_getConditionsclass\Ajax.php:32
authwp_ajax_muzaara_woopf_bing_createChannelclass\Ajax.php:33
authwp_ajax_muzaara_woopf_bing_getProductTypesclass\Ajax.php:34
authwp_ajax_muzaara_woopf_bing_getFeedsclass\Ajax.php:35
authwp_ajax_muzaara_woopf_bing_pauseFeedclass\Ajax.php:36
authwp_ajax_muzaara_woopf_bing_deleteFeedclass\Ajax.php:37
authwp_ajax_muzaara_woopf_bing_resumeFeedclass\Ajax.php:38
authwp_ajax_muzaara_woopf_bing_getFeedclass\Ajax.php:39
authwp_ajax_muzaara_woopf_bing_runFeedclass\Ajax.php:40
WordPress Hooks 12
actionadmin_menuclass\App.php:227
actionadmin_enqueue_scriptsclass\App.php:228
actionadmin_initclass\App.php:229
actioninitclass\App.php:232
filtermanage_edit-product_columnsclass\App.php:233
actionmanage_product_posts_custom_columnclass\App.php:234
filtercron_schedulesclass\App.php:235
filterwoocommerce_product_data_store_cpt_get_products_queryclass\App.php:237
actionwoocommerce_update_productclass\App.php:239
actionbefore_delete_postclass\App.php:240
actionwp_trash_postclass\App.php:241
actionadmin_noticesclass\App.php:300
Maintenance & Trust

Muzaara Content API Microsoft/Bing Data Feed Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedMar 1, 2024
PHP min version7.3
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Muzaara Content API Microsoft/Bing Data Feed Developer Profile

muzaara

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Muzaara Content API Microsoft/Bing Data Feed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/muzaara-micosoft-bing-product-data-feed/asset/css/bootstrap.min.css/wp-content/plugins/muzaara-micosoft-bing-product-data-feed/asset/css/custom.css/wp-content/plugins/muzaara-micosoft-bing-product-data-feed/asset/css/select2.min.css/wp-content/plugins/muzaara-micosoft-bing-product-data-feed/asset/js/bootstrap.min.js/wp-content/plugins/muzaara-micosoft-bing-product-data-feed/asset/js/custom.js/wp-content/plugins/muzaara-micosoft-bing-product-data-feed/asset/js/jquery-3.6.0.min.js/wp-content/plugins/muzaara-micosoft-bing-product-data-feed/asset/js/select2.min.js/wp-content/plugins/muzaara-micosoft-bing-product-data-feed/asset/js/vue.js+1 more
Script Paths
/wp-content/plugins/muzaara-micosoft-bing-product-data-feed/asset/js/bootstrap.min.js/wp-content/plugins/muzaara-micosoft-bing-product-data-feed/asset/js/custom.js/wp-content/plugins/muzaara-micosoft-bing-product-data-feed/asset/js/jquery-3.6.0.min.js/wp-content/plugins/muzaara-micosoft-bing-product-data-feed/asset/js/select2.min.js/wp-content/plugins/muzaara-micosoft-bing-product-data-feed/asset/js/vue.js/wp-content/plugins/muzaara-micosoft-bing-product-data-feed/asset/js/vue_app.js
Version Parameters
muzaara-micosoft-bing-product-data-feed/asset/css/bootstrap.min.css?ver=muzaara-micosoft-bing-product-data-feed/asset/css/custom.css?ver=muzaara-micosoft-bing-product-data-feed/asset/css/select2.min.css?ver=muzaara-micosoft-bing-product-data-feed/asset/js/bootstrap.min.js?ver=muzaara-micosoft-bing-product-data-feed/asset/js/custom.js?ver=muzaara-micosoft-bing-product-data-feed/asset/js/jquery-3.6.0.min.js?ver=muzaara-micosoft-bing-product-data-feed/asset/js/select2.min.js?ver=muzaara-micosoft-bing-product-data-feed/asset/js/vue.js?ver=muzaara-micosoft-bing-product-data-feed/asset/js/vue_app.js?ver=

HTML / DOM Fingerprints

CSS Classes
muzaara-woopf-bing-wrap
Data Attributes
data-field-mapping-iddata-category-mapping-iddata-filter-iddata-rule-iddata-rule-group-id
JS Globals
muzaara_woopf_bing
FAQ

Frequently Asked Questions about Muzaara Content API Microsoft/Bing Data Feed