افزونه استخراج اطلاعات محصولات ووکامرس – پارساژ Security & Risk Analysis

wordpress.org/plugins/parsazh-products-extractor-for-woocommerce

Automatically read product information from WooCommerce stores and sync product prices with Parsazh.

0 active installs v1.0.0 PHP 7.0+ WP 6.0+ Updated Oct 5, 2025
extractorpriceproductssyncwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is افزونه استخراج اطلاعات محصولات ووکامرس – پارساژ Safe to Use in 2026?

Generally Safe

Score 100/100

افزونه استخراج اطلاعات محصولات ووکامرس – پارساژ has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The plugin "parsazh-products-extractor-for-woocommerce" v1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices in handling SQL queries, utilizing prepared statements exclusively, and ensuring all output is properly escaped. There is also a capability check present in the code, indicating some awareness of WordPress security mechanisms. However, a significant concern arises from its attack surface. The plugin exposes two REST API routes that lack permission callbacks, making them accessible without authentication. This is a notable weakness that could be exploited by attackers to trigger functionality intended for authenticated users.

Furthermore, the absence of nonce checks on AJAX handlers, coupled with the presence of external HTTP requests, warrants attention. While no specific taint flows with unsanitized paths were identified in this analysis, the overall lack of robust authentication and authorization for key entry points, particularly the REST API, presents a tangible risk. The plugin's vulnerability history is clean, with no recorded CVEs, which is a strength. However, this clean history does not negate the risks identified in the static analysis. The plugin needs to implement proper authentication and authorization for its REST API endpoints to mitigate potential security threats.

Key Concerns

  • REST API routes without permission callbacks
  • AJAX handlers without auth checks
  • External HTTP requests detected
  • Nonce checks not implemented
Vulnerabilities
None known

افزونه استخراج اطلاعات محصولات ووکامرس – پارساژ Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

افزونه استخراج اطلاعات محصولات ووکامرس – پارساژ Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

افزونه استخراج اطلاعات محصولات ووکامرس – پارساژ Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
20 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped20 total outputs
Attack Surface
2 unprotected

افزونه استخراج اطلاعات محصولات ووکامرس – پارساژ Attack Surface

Entry Points2
Unprotected2

REST API Routes 2

POST/wp-json/parsazh/v1/productsparsazh-products-extractor-for-woocommerce.php:24
POST/wp-json/parsazh/v1/products/(?P<id>\d+)parsazh-products-extractor-for-woocommerce.php:30
WordPress Hooks 1
actionrest_api_initparsazh-products-extractor-for-woocommerce.php:23
Maintenance & Trust

افزونه استخراج اطلاعات محصولات ووکامرس – پارساژ Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.6
Last updatedOct 5, 2025
PHP min version7.0
Downloads333

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

افزونه استخراج اطلاعات محصولات ووکامرس – پارساژ Developer Profile

parsazh

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect افزونه استخراج اطلاعات محصولات ووکامرس – پارساژ

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

REST Endpoints
/parsazh/v1/products/parsazh/v1/products/(?P<id>\d+)
FAQ

Frequently Asked Questions about افزونه استخراج اطلاعات محصولات ووکامرس – پارساژ