
Signpost Sync for WooCommerce Security & Risk Analysis
wordpress.org/plugins/myworks-design-signpost-syncThe only WooCommerce plugin to automatically sync your WooCommerce users to your Signpost CRM dashboard - in real time!
Is Signpost Sync for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100Signpost Sync for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "myworks-design-signpost-sync" v1.4 demonstrates a generally good security posture with several positive indicators. The absence of any known vulnerabilities (CVEs) and the fact that all SQL queries are prepared statements are significant strengths. Furthermore, the static analysis reveals no critical or high severity taint flows, suggesting a lack of easily exploitable data handling issues. The plugin also has a small attack surface with no unprotected entry points identified.
However, there are areas that warrant caution. While the total number of output escapes is decent, a significant portion (36%) are not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in these unescaped outputs. Additionally, the plugin performs external HTTP requests, which, while not inherently insecure, can be a vector for certain types of attacks if not handled with care and proper validation. The presence of only one nonce check and zero capability checks for its entry points is a notable weakness, especially for the AJAX handlers, as it could allow unauthorized actions if exploited.
Overall, the plugin is built on a relatively solid foundation, particularly regarding its SQL handling and lack of critical vulnerabilities. The primary concern lies in the potential for XSS due to unescaped output and the insufficient authorization checks on its entry points. Addressing these areas would significantly enhance its security.
Key Concerns
- Unescaped output detected (36%)
- Only 1 nonce check for entry points
- 0 capability checks for entry points
Signpost Sync for WooCommerce Security Vulnerabilities
Signpost Sync for WooCommerce Code Analysis
Output Escaping
Signpost Sync for WooCommerce Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Signpost Sync for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Signpost Sync for WooCommerce Alternatives
Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation
zero-bs-crm
The CRM for small businesses. Manage leads, invoicing, billing, email marketing, clients, contacts, quotes, automation. Works with WooCommerce too.
AFI – The Easiest Integration Plugin
advanced-form-integration
Connect any WordPress form or event to 200+ apps — no code. Send leads, orders, and signups to your CRM, email, or sheets in minutes.
ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support
erp
Manage your business with a complete ERP system featuring powerful HR management, CRM tools, accounting, and seamless WooCommerce CRM integration.
Ultimate WP Mail
ultimate-wp-mail
Custom email and SMS notifications. Automatic send actions. WPForms SMS integration. WooCommerce notifications for purchases, abandoned cart and more!
Object Data Sync for Salesforce Integration with WP, Woo, Gravity, WPForms, Ninja, CF7 & more
object-data-sync-for-salesforce
Automate data sync with our Salesforce Integration plugin. Supports integrations with WooCommerce, Gravity, Ninja, CF7, WPForms, Event Calendar & more
Signpost Sync for WooCommerce Developer Profile
3 plugins · 6K total installs
How We Detect Signpost Sync for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/myworks-design-signpost-sync/css/mswp-style.css/wp-content/plugins/myworks-design-signpost-sync/js/mswp-js.js/wp-content/plugins/myworks-design-signpost-sync/js/mswp-js.jsmyworks-design-signpost-sync/css/mswp-style.css?ver=myworks-design-signpost-sync/js/mswp-js.js?ver=HTML / DOM Fingerprints
mwsp_mainmswp_sc_mainmswp-form-titlemwsp_form_fieldsmwsp_inputmwsp_actionmwsp-btnmwsp_status_msgmwsp_form_keymswp_js_val<h2 class="mswp-form-title">