Signpost Sync for WooCommerce Security & Risk Analysis

wordpress.org/plugins/myworks-design-signpost-sync

The only WooCommerce plugin to automatically sync your WooCommerce users to your Signpost CRM dashboard - in real time!

10 active installs v1.4 PHP + WP + Updated Apr 17, 2017
crmsignpostwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Signpost Sync for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Signpost Sync for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The plugin "myworks-design-signpost-sync" v1.4 demonstrates a generally good security posture with several positive indicators. The absence of any known vulnerabilities (CVEs) and the fact that all SQL queries are prepared statements are significant strengths. Furthermore, the static analysis reveals no critical or high severity taint flows, suggesting a lack of easily exploitable data handling issues. The plugin also has a small attack surface with no unprotected entry points identified.

However, there are areas that warrant caution. While the total number of output escapes is decent, a significant portion (36%) are not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in these unescaped outputs. Additionally, the plugin performs external HTTP requests, which, while not inherently insecure, can be a vector for certain types of attacks if not handled with care and proper validation. The presence of only one nonce check and zero capability checks for its entry points is a notable weakness, especially for the AJAX handlers, as it could allow unauthorized actions if exploited.

Overall, the plugin is built on a relatively solid foundation, particularly regarding its SQL handling and lack of critical vulnerabilities. The primary concern lies in the potential for XSS due to unescaped output and the insufficient authorization checks on its entry points. Addressing these areas would significantly enhance its security.

Key Concerns

  • Unescaped output detected (36%)
  • Only 1 nonce check for entry points
  • 0 capability checks for entry points
Vulnerabilities
None known

Signpost Sync for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Signpost Sync for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
28 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

64% escaped44 total outputs
Attack Surface

Signpost Sync for WooCommerce Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_mwsp_post_signpostmyworks-signpost.php:395
noprivwp_ajax_mwsp_post_signpostmyworks-signpost.php:396

Shortcodes 1

[mw_sp_form] myworks-signpost.php:146
WordPress Hooks 5
actionwp_enqueue_scriptsmyworks-signpost.php:59
actionadmin_menumyworks-signpost.php:63
actionadmin_initmyworks-signpost.php:66
actionwidgets_initmyworks-signpost.php:269
actionuser_registermyworks-signpost.php:399
Maintenance & Trust

Signpost Sync for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedApr 17, 2017
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Signpost Sync for WooCommerce Developer Profile

MyWorks

3 plugins · 6K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect Signpost Sync for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/myworks-design-signpost-sync/css/mswp-style.css/wp-content/plugins/myworks-design-signpost-sync/js/mswp-js.js
Script Paths
/wp-content/plugins/myworks-design-signpost-sync/js/mswp-js.js
Version Parameters
myworks-design-signpost-sync/css/mswp-style.css?ver=myworks-design-signpost-sync/js/mswp-js.js?ver=

HTML / DOM Fingerprints

CSS Classes
mwsp_mainmswp_sc_mainmswp-form-titlemwsp_form_fieldsmwsp_inputmwsp_actionmwsp-btnmwsp_status_msg
Data Attributes
mwsp_form_key
JS Globals
mswp_js_val
Shortcode Output
<h2 class="mswp-form-title">
FAQ

Frequently Asked Questions about Signpost Sync for WooCommerce