POKY – Product Importer Security & Risk Analysis

wordpress.org/plugins/poky-product-importer

POKY enables WooCommerce merchants to import products from 28+ platforms to your store

900 active installs v2.2.0 PHP 5.0+ WP 4.4+ Updated Oct 8, 2024
amazonebayetsyshopifywoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is POKY – Product Importer Safe to Use in 2026?

Generally Safe

Score 92/100

POKY – Product Importer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'poky-product-importer' v2.2.0 plugin exhibits a concerning security posture due to a significant number of unprotected AJAX handlers. While the plugin demonstrates good practices in its handling of SQL queries by exclusively using prepared statements and has no recorded vulnerability history, the lack of authentication checks on its entry points is a major weakness. The static analysis reveals four AJAX handlers, all of which lack authorization, creating a substantial attack surface accessible to unauthenticated users. Although there are no critical or high severity taint flows identified and output escaping appears to be reasonably well-implemented, the absence of nonces and capability checks on these AJAX actions leaves them vulnerable to various attacks, including unauthorized data manipulation or execution of unintended actions. The lack of historical CVEs is a positive sign, suggesting a potentially stable codebase, but it does not mitigate the immediate risks posed by the current static analysis findings. Overall, the plugin has strengths in its database interaction and lack of historical vulnerabilities, but the high number of unprotected AJAX endpoints presents a critical security risk that needs immediate attention.

Key Concerns

  • Unprotected AJAX handlers
  • Missing nonce checks on AJAX handlers
  • Missing capability checks on AJAX handlers
  • Unescaped output on 2 out of 6 outputs
Vulnerabilities
None known

POKY – Product Importer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

POKY – Product Importer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

67% escaped6 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
poky_create_product (includes\poky-core-functions.php:61)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

POKY – Product Importer Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

authwp_ajax_poky_create_productincludes\poky-core-functions.php:58
noprivwp_ajax_poky_create_productincludes\poky-core-functions.php:59
authwp_ajax_poky_load_productsincludes\poky-core-functions.php:79
noprivwp_ajax_poky_load_productsincludes\poky-core-functions.php:80
WordPress Hooks 6
actionadmin_initincludes\class-poky-install.php:24
actionadmin_menuincludes\poky-core-functions.php:23
actionadmin_footerincludes\poky-core-functions.php:35
actionrest_api_initincludes\poky-core-functions.php:48
filterplugin_row_metapoky.php:58
actionbefore_woocommerce_initpoky.php:82
Maintenance & Trust

POKY – Product Importer Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedOct 8, 2024
PHP min version5.0
Downloads19K

Community Trust

Rating54/100
Number of ratings7
Active installs900
Developer Profile

POKY – Product Importer Developer Profile

adspair

1 plugin · 900 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect POKY – Product Importer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/poky-product-importer/assets/css/frontend.css/wp-content/plugins/poky-product-importer/assets/js/frontend.js
Script Paths
/wp-content/plugins/poky-product-importer/assets/js/frontend.js
Version Parameters
poky-product-importer/assets/css/frontend.css?ver=poky-product-importer/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about POKY – Product Importer