Paapi Product Search for Amazon Security & Risk Analysis

wordpress.org/plugins/paapi-product-search-for-amazon

Search and display Amazon products directly on your WordPress site with live search, filters, and beautiful themes. No ASIN hunting required.

0 active installs v2.11.0 PHP 7.4+ WP 5.8+ Updated Mar 11, 2026
affiliateamazonecommerceproductssearch
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Paapi Product Search for Amazon Safe to Use in 2026?

Generally Safe

Score 100/100

Paapi Product Search for Amazon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 25d ago
Risk Assessment

The "paapi-product-search-for-amazon" plugin version 2.11.0 exhibits a mixed security posture. On the positive side, the plugin has a clean vulnerability history with no known CVEs, suggesting a generally well-maintained codebase. Furthermore, the vast majority of its outputs are properly escaped, and taint analysis reveals no critical or high-severity vulnerabilities related to unsanitized data flows. The absence of dangerous functions and unpatched vulnerabilities is also a strong positive indicator.

However, significant concerns arise from the attack surface analysis. The plugin exposes 10 AJAX handlers, with a notable 4 lacking any form of authentication checks. This is a critical oversight that could allow unauthenticated users to trigger potentially sensitive actions. Additionally, all 5 SQL queries are executed without prepared statements, increasing the risk of SQL injection vulnerabilities, especially when combined with the unprotected AJAX endpoints. The presence of file operations, though not explicitly flagged as risky, warrants caution given the lack of robust input validation on potential file paths.

While the plugin's history is spotless, the identified code analysis weaknesses create an unacceptable risk profile. The lack of authentication on multiple AJAX endpoints, coupled with raw SQL queries, presents a clear and present danger for exploitation. The bundled Freemius library, while likely not an immediate threat in itself without version context, adds to the overall complexity and potential for overlooked vulnerabilities. A robust security strategy would prioritize addressing these specific weaknesses to bring the plugin's security in line with its otherwise positive historical data.

Key Concerns

  • AJAX handlers without authentication checks
  • SQL queries not using prepared statements
Vulnerabilities
None known

Paapi Product Search for Amazon Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Paapi Product Search for Amazon Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
0 prepared
Unescaped Output
9
837 escaped
Nonce Checks
17
Capability Checks
9
File Operations
2
External Requests
10
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

0% prepared5 total queries

Output Escaping

99% escaped846 total outputs
Data Flows
All sanitized

Data Flow Analysis

10 flows
psfa_ajax_autocomplete (core\admin\ajax.php:262)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Paapi Product Search for Amazon Attack Surface

Entry Points11
Unprotected4

AJAX Handlers 10

authwp_ajax_psfa_load_morepaapi-product-search-for-amazon.php:128
noprivwp_ajax_psfa_load_morepaapi-product-search-for-amazon.php:129
authwp_ajax_psfa_autocompletepaapi-product-search-for-amazon.php:131
noprivwp_ajax_psfa_autocompletepaapi-product-search-for-amazon.php:132
authwp_ajax_psfa_test_connectionpaapi-product-search-for-amazon.php:134
authwp_ajax_psfa_save_settingspaapi-product-search-for-amazon.php:136
authwp_ajax_psfa_save_credentialspaapi-product-search-for-amazon.php:138
authwp_ajax_psfa_reset_settingspaapi-product-search-for-amazon.php:140
authwp_ajax_psfa_clear_cachepaapi-product-search-for-amazon.php:142
authwp_ajax_psfa_cache_statspaapi-product-search-for-amazon.php:144

Shortcodes 1

[psfa_search] paapi-product-search-for-amazon.php:124
WordPress Hooks 18
filterpsfa_admin_nav_sectionscore\admin\sections\admin-addons-promo.php:47
filterpsfa_admin_section_titlescore\admin\sections\admin-addons-promo.php:64
filterpsfa_admin_section_descriptionscore\admin\sections\admin-addons-promo.php:81
filterpsfa_render_admin_sectioncore\admin\sections\admin-addons-promo.php:110
filterplugin_iconpaapi-product-search-for-amazon.php:61
actiontemplate_redirectpaapi-product-search-for-amazon.php:110
actionadmin_menupaapi-product-search-for-amazon.php:113
actionadmin_initpaapi-product-search-for-amazon.php:114
actionadmin_initpaapi-product-search-for-amazon.php:115
actionadmin_initpaapi-product-search-for-amazon.php:116
actionupdate_option_psfa_auth_typepaapi-product-search-for-amazon.php:119
actionupdate_option_psfa_oauth_client_idpaapi-product-search-for-amazon.php:120
actionupdate_option_psfa_oauth_client_secretpaapi-product-search-for-amazon.php:121
actionadmin_enqueue_scriptspaapi-product-search-for-amazon.php:122
actionwp_enqueue_scriptspaapi-product-search-for-amazon.php:126
actionupdate_option_psfa_marketplacepaapi-product-search-for-amazon.php:146
actionupdate_option_psfa_associate_tagpaapi-product-search-for-amazon.php:147
actioninitsrc\core\shared\theme-manager.php:407
Maintenance & Trust

Paapi Product Search for Amazon Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 11, 2026
PHP min version7.4
Downloads687

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Paapi Product Search for Amazon Developer Profile

paapiplugin

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Paapi Product Search for Amazon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/paapi-product-search-for-amazon/src/assets/css/product-search.css/wp-content/plugins/paapi-product-search-for-amazon/src/assets/js/product-search.js/wp-content/plugins/paapi-product-search-for-amazon/src/assets/css/admin-style.css
Script Paths
/wp-content/plugins/paapi-product-search-for-amazon/src/assets/js/product-search.js
Version Parameters
paapi-product-search-for-amazon/src/assets/css/product-search.css?ver=paapi-product-search-for-amazon/src/assets/js/product-search.js?ver=paapi-product-search-for-amazon/src/assets/css/admin-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
psfa-search-resultspsfa-search-formpsfa-product-titlepsfa-product-pricepsfa-product-imagepsfa-product-linkpsfa-load-more-buttonpsfa-no-results+1 more
HTML Comments
<!-- PSFA_MOCK_MODE --><!-- Add admin menu for settings --><!-- Register shortcode (prefixed per WordPress.org guidelines) --><!-- Enqueue scripts and styles -->+24 more
Data Attributes
data-psfa-noncedata-psfa-iddata-psfa-namedata-psfa-pricedata-psfa-imagedata-psfa-url+14 more
JS Globals
PSFA_ProductSearchpsfa_autocomplete_paramspsfa_load_more_paramspsfa_admin_params
REST Endpoints
/wp-json/paapi-product-search-for-amazon/v1/settings/wp-json/paapi-product-search-for-amazon/v1/credentials/wp-json/paapi-product-search-for-amazon/v1/reset/wp-json/paapi-product-search-for-amazon/v1/cache/clear/wp-json/paapi-product-search-for-amazon/v1/cache/stats
Shortcode Output
[psfa_search]
FAQ

Frequently Asked Questions about Paapi Product Search for Amazon