
POKY – Product Importer Security & Risk Analysis
wordpress.org/plugins/poky-product-importerPOKY enables WooCommerce merchants to import products from 28+ platforms to your store
Is POKY – Product Importer Safe to Use in 2026?
Generally Safe
Score 92/100POKY – Product Importer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'poky-product-importer' v2.2.0 plugin exhibits a concerning security posture due to a significant number of unprotected AJAX handlers. While the plugin demonstrates good practices in its handling of SQL queries by exclusively using prepared statements and has no recorded vulnerability history, the lack of authentication checks on its entry points is a major weakness. The static analysis reveals four AJAX handlers, all of which lack authorization, creating a substantial attack surface accessible to unauthenticated users. Although there are no critical or high severity taint flows identified and output escaping appears to be reasonably well-implemented, the absence of nonces and capability checks on these AJAX actions leaves them vulnerable to various attacks, including unauthorized data manipulation or execution of unintended actions. The lack of historical CVEs is a positive sign, suggesting a potentially stable codebase, but it does not mitigate the immediate risks posed by the current static analysis findings. Overall, the plugin has strengths in its database interaction and lack of historical vulnerabilities, but the high number of unprotected AJAX endpoints presents a critical security risk that needs immediate attention.
Key Concerns
- Unprotected AJAX handlers
- Missing nonce checks on AJAX handlers
- Missing capability checks on AJAX handlers
- Unescaped output on 2 out of 6 outputs
POKY – Product Importer Security Vulnerabilities
POKY – Product Importer Code Analysis
Output Escaping
Data Flow Analysis
POKY – Product Importer Attack Surface
AJAX Handlers 4
WordPress Hooks 6
Maintenance & Trust
POKY – Product Importer Maintenance & Trust
Maintenance Signals
Community Trust
POKY – Product Importer Alternatives
LitCommerce: Multi-channel Selling Tool For WooCommerce
litcommerce
Bulk List/Sync your WooCommerce Products and Orders with biggest online marketplaces like Amazon, eBay, Etsy, TikTok Shop, Walmart, Facebook Shop, Goo …
ExportYourStore
exportyourstore
Easily integrate your WooCommerce store with the largest online marketplaces.
SharkDropship & Affiliate for AliExpress, eBay, Amazon, Etsy and Temu
woo-aliexpress-dropshipping
🚀 Multi-Supplier Dropshipping & Affiliate Plugin for WooCommerce Import products from AliExpress, eBay, Amazon, Etsy, and Temu with one click.
Sellbrite
sellbrite
Helps you easily integrate your WooCommerce store with Sellbrite, a GoDaddy brand.
Eselt
eselt-ebay-amazon-multichannel
Easily connect your WooCommerce store with the Eselt app to easily sync and manage products across WooCommerce, eBay, and Amazon.
POKY – Product Importer Developer Profile
1 plugin · 900 total installs
How We Detect POKY – Product Importer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/poky-product-importer/assets/css/frontend.css/wp-content/plugins/poky-product-importer/assets/js/frontend.js/wp-content/plugins/poky-product-importer/assets/js/frontend.jspoky-product-importer/assets/css/frontend.css?ver=poky-product-importer/assets/js/frontend.js?ver=