NS Add Product Frontend for Woocommerce Security & Risk Analysis

wordpress.org/plugins/ns-add-product-frontend

Add product without user frontend access!

100 active installs v2.0.5 PHP 5.6+ WP 4.3+ Updated Mar 24, 2023
add-productadd-productswoocommerce-add-productwoocommerce-productwoocommerce-products
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is NS Add Product Frontend for Woocommerce Safe to Use in 2026?

Generally Safe

Score 85/100

NS Add Product Frontend for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "ns-add-product-frontend" v2.0.5 plugin exhibits a mixed security posture. On the positive side, it demonstrates strong practices regarding SQL queries, exclusively using prepared statements, and has no recorded vulnerabilities (CVEs) or known issues. The absence of bundled libraries and file operations further reduces potential attack vectors.

However, significant concerns arise from the static analysis. The plugin presents a total of 7 AJAX handlers, with 2 lacking authentication checks, creating a clear entry point for unauthorized actions. Furthermore, the output escaping is notably poor, with only 16% of outputs being properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. While no critical or high severity taint flows were identified, the presence of 2 flows with unsanitized paths, although not classified as critical, warrants attention. The limited number of nonce and capability checks also contributes to a less robust security. The vulnerability history being completely clean is a positive indicator, suggesting that the developers may have addressed past issues or the plugin hasn't been targeted extensively. However, the current code analysis reveals weaknesses that could be exploited if not addressed.

In conclusion, while the plugin's SQL handling and lack of historical vulnerabilities are commendable, the unprotected AJAX endpoints and significantly under-escaped output pose substantial risks. The untainted paths, while not critical, also represent potential security gaps. Remediation of the unauthenticated AJAX actions and improvements in output escaping are strongly recommended to enhance the plugin's security.

Key Concerns

  • AJAX handlers without authentication checks
  • Low percentage of properly escaped output
  • Flows with unsanitized paths
  • Limited nonce checks
  • Limited capability checks
Vulnerabilities
None known

NS Add Product Frontend for Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

NS Add Product Frontend for Woocommerce Release Timeline

v2.0.5Current
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v2.0.0
v1.5.4
v1.5.3
v1.5.2
v1.5.1
v1.5.0
v1.4.0
v1.3.0
v1.2.3
v1.2.2
v1.2.1
v1.2.0
v1.1.4
v1.1.3
v1.1.2
Code Analysis
Analyzed Mar 16, 2026

NS Add Product Frontend for Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
36
7 escaped
Nonce Checks
3
Capability Checks
5
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

16% escaped43 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
pe_deactivation_ajax_function (plugineye\plugineye-ajax\plugineye_on_deactivation_function.php:5)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

NS Add Product Frontend for Woocommerce Attack Surface

Entry Points7
Unprotected2

AJAX Handlers 7

authwp_ajax_add_product_attributesasync\apf-product-attributes.php:3
noprivwp_ajax_add_product_attributesasync\apf-product-attributes.php:4
authwp_ajax_save_simple_productasync\apf-save-simple-product.php:3
noprivwp_ajax_save_simple_productasync\apf-save-simple-product.php:4
authwp_ajax_apf_review_actioninc\class-plugin-theme-review-request.php:51
authwp_ajax_pe_deactivation_ajax_functionplugineye\plugineye-ajax\plugineye_on_deactivation_function.php:2
noprivwp_ajax_pe_deactivation_ajax_functionplugineye\plugineye-ajax\plugineye_on_deactivation_function.php:3
WordPress Hooks 18
filterpage_templateinc\apf-include-template.php:2
actioninitinc\class-plugin-theme-review-request.php:50
actionadmin_noticesinc\class-plugin-theme-review-request.php:60
actionnetwork_admin_noticesinc\class-plugin-theme-review-request.php:61
actionuser_admin_noticesinc\class-plugin-theme-review-request.php:62
actionadmin_menuns-admin-options\ns-admin-options-setup.php:11
actionadmin_initns-admin-options\ns-admin-options-setup.php:28
actionadmin_enqueue_scriptsns-admin-options\ns-admin-options-setup.php:32
actionwp_enqueue_scriptsns-admin-options\ns-admin-options-setup.php:39
filteradmin_footer_textns-admin-options\ns_settings_custom.php:11
actionadmin_initns-apf-options.php:26
filterplugin_action_linksplugineye\plugineye-class.php:96
actionadmin_menuplugineye\plugineye-class.php:113
actionadmin_enqueue_scriptsplugineye\plugineye-class.php:125
actionadmin_enqueue_scriptsplugineye\plugineye-class.php:136
actionactivated_pluginplugineye\plugineye-class.php:147
actionin_admin_footerplugineye\plugineye-class.php:401
actionactivated_pluginplugineye\plugineye-class.php:440
Maintenance & Trust

NS Add Product Frontend for Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedMar 24, 2023
PHP min version5.6
Downloads14K

Community Trust

Rating80/100
Number of ratings8
Active installs100
Developer Profile

NS Add Product Frontend for Woocommerce Developer Profile

NsThemes

24 plugins · 4K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect NS Add Product Frontend for Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ns-add-product-frontend/templates//wp-content/plugins/ns-add-product-frontend/templates/selectize/dist/css/selectize.css/wp-content/plugins/ns-add-product-frontend/templates/selectize/dist/js/standalone/selectize.min.js
Script Paths
/wp-content/plugins/ns-add-product-frontend/templates//wp-content/plugins/ns-add-product-frontend/templates/selectize/dist/js/standalone/selectize.min.js/wp-content/plugins/ns-add-product-frontend/js/frontend/save-simple-product.js/wp-content/plugins/ns-add-product-frontend/js/frontend/product-attributes.js

HTML / DOM Fingerprints

Data Attributes
id="nswatlinkpremiumlinkpremium"
JS Globals
savesimpleproductproductattributes
FAQ

Frequently Asked Questions about NS Add Product Frontend for Woocommerce