
Product Catalog Feed by PixelYourSite Security & Risk Analysis
wordpress.org/plugins/product-catalog-feedWooCommerce auto-updated XML feeds for Facebook Product Catalogs (Dynamic Product Ads, Facebook Shops, Instagram), Google Merchant, and Pinterest Cata …
Is Product Catalog Feed by PixelYourSite Safe to Use in 2026?
Mostly Safe
Score 84/100Product Catalog Feed by PixelYourSite is generally safe to use though it hasn't been updated recently. 3 past CVEs were resolved.
The "product-catalog-feed" plugin v2.2.0 exhibits a mixed security posture. While it demonstrates some good practices, such as using prepared statements for a majority of its SQL queries and including a reasonable number of nonce and capability checks, there are significant areas of concern. The presence of 10 AJAX handlers, with 2 lacking authentication checks, presents a notable attack surface. Furthermore, the taint analysis reveals 5 high-severity flows with unsanitized paths, indicating a potential for data manipulation or execution vulnerabilities if these flows are triggered by untrusted input. The use of dangerous functions like `unserialize` and `create_function` also raises red flags, as these can be exploited if input is not rigorously sanitized. The plugin's vulnerability history, with 3 medium-severity CVEs in the past, primarily related to CSRF and XSS, suggests a pattern of past security weaknesses that, while currently patched, warrant attention. The past issues and the current taint analysis findings highlight a need for more robust input validation and sanitization. Overall, while the plugin isn't critically flawed, the combination of unprotected entry points, high-severity taint flows, and historical vulnerabilities suggests a medium-to-high risk profile that requires careful monitoring and potential remediation.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows
- Use of dangerous functions
- Low output escaping percentage
- Medium severity CVEs in history
Product Catalog Feed by PixelYourSite Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Product Catalog Feed by PixelYourSite <= 2.1.1 - Cross-Site Request Forgery
Product Catalog Feed by PixelYourSite <= 2.1.0 - Reflected Cross-Site Scripting via 'page'
Product Catalog Feed by PixelYourSite <= 2.1.0 - Reflected Cross-Site Scripting via 'edit'
Product Catalog Feed by PixelYourSite Release Timeline
Product Catalog Feed by PixelYourSite Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Product Catalog Feed by PixelYourSite Attack Surface
AJAX Handlers 10
WordPress Hooks 42
Scheduled Events 6
Maintenance & Trust
Product Catalog Feed by PixelYourSite Maintenance & Trust
Maintenance Signals
Community Trust
Product Catalog Feed by PixelYourSite Alternatives
GG Woo Feed for WooCommerce Shopping Feed on Google and Other Channels
gg-woo-feed
No #1 WooCommerce Feed Generator Creates product feed for marketing channel Google Shopping Merchant, Meta Remarketing, Printerest and Others Channels
Product XML Feed Manager for WooCommerce – Google Shopping, Social Sites, Skroutz & More
product-xml-feeds-for-woocommerce
Create your own XML feeds to export them, utilize tens of preconfigured shortcodes for you on your WooCommerce store as per marketplace needs
Daisycon prijsvergelijkers
daisycon
Promoot adverteerders van Daisycon eenvoudig en goed met de verschillende professionele prijsvergelijkers voor publishers.
Product Catalog Mode For WooCommerce
product-catalog-mode-for-woocommerce
Product Catalog Mode for WooCommerce TURN INTO your online store as CATALOG ONLY MODE hiding by product price, Add to Cart button on a single click.
Remove Product Content for WooCommerce
remove-product-content-for-woocommerce
The Remove Product Content for WooCommerce plugin allows store owners to easily customize product pages by removing unwanted sections or elements.
Product Catalog Feed by PixelYourSite Developer Profile
2 plugins · 508K total installs
How We Detect Product Catalog Feed by PixelYourSite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/product-catalog-feed/assets/css/style.css/wp-content/plugins/product-catalog-feed/assets/css/magnific-popup.css/wp-content/plugins/product-catalog-feed/assets/css/bootstrap.min.css/wp-content/plugins/product-catalog-feed/assets/css/pxls-admin.css/wp-content/plugins/product-catalog-feed/assets/js/bootstrap.min.js/wp-content/plugins/product-catalog-feed/assets/js/custom.js/wp-content/plugins/product-catalog-feed/assets/js/magnific-popup.js/wp-content/plugins/product-catalog-feed/assets/js/pxls-admin.js+1 more/wp-content/plugins/product-catalog-feed/assets/js/bootstrap.min.js/wp-content/plugins/product-catalog-feed/assets/js/custom.js/wp-content/plugins/product-catalog-feed/assets/js/magnific-popup.js/wp-content/plugins/product-catalog-feed/assets/js/pxls-admin.js/wp-content/plugins/product-catalog-feed/assets/js/woof-woo-products-feed.jsproduct-catalog-feed/assets/css/style.css?ver=product-catalog-feed/assets/css/magnific-popup.css?ver=product-catalog-feed/assets/css/bootstrap.min.css?ver=product-catalog-feed/assets/css/pxls-admin.css?ver=product-catalog-feed/assets/js/bootstrap.min.js?ver=product-catalog-feed/assets/js/custom.js?ver=product-catalog-feed/assets/js/magnific-popup.js?ver=product-catalog-feed/assets/js/pxls-admin.js?ver=product-catalog-feed/assets/js/woof-woo-products-feed.js?ver=HTML / DOM Fingerprints
wpwoof_product_catalogwpwoof-admin-noticewpwoof_add_field_categorywpwoof-google-taxonomy-containerwpwoof-mpn-containerwpwoof-gtin-containerwpwoof-brand-containerwpwoof-identifier_exists-container+7 moredata-wpwoof-debugdata-wpwoof-feed-idwpwoof_datawoocommerce_wpwoof_common/wp-json/wpwoof/v1/feeds