
Product XML Feed Manager for WooCommerce – Google Shopping, Social Sites, Skroutz & More Security & Risk Analysis
wordpress.org/plugins/product-xml-feeds-for-woocommerceCreate your own XML feeds to export them, utilize tens of preconfigured shortcodes for you on your WooCommerce store as per marketplace needs
Is Product XML Feed Manager for WooCommerce – Google Shopping, Social Sites, Skroutz & More Safe to Use in 2026?
Generally Safe
Score 97/100Product XML Feed Manager for WooCommerce – Google Shopping, Social Sites, Skroutz & More has a strong security track record. Known vulnerabilities have been patched promptly.
The "product-xml-feeds-for-woocommerce" plugin v3.0.0 exhibits a mixed security posture. While it demonstrates good practices in its use of prepared statements for SQL queries and the absence of dangerous functions, significant concerns arise from its attack surface and output handling. The presence of 12 AJAX handlers, with half of them lacking authentication checks, presents a substantial risk of unauthorized access and arbitrary action execution. Furthermore, the low percentage (47%) of properly escaped output suggests a high likelihood of cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into user-facing content.
The vulnerability history, though currently showing no unpatched CVEs, reveals a past pattern of "Improper Control of Generation of Code ('Code Injection')" and "Missing Authorization." This history, coupled with the static analysis findings of unprotected AJAX endpoints and insufficient output escaping, indicates a recurring theme of authorization and sanitization weaknesses within the plugin's codebase. While the plugin does implement some nonce and capability checks, their limited application on critical entry points is a notable deficiency.
In conclusion, the plugin has strengths in its database interaction and avoidance of known dangerous code patterns. However, the significant number of unprotected AJAX endpoints, along with the prevalent issue of unescaped output, creates a clear and present danger for XSS and unauthorized functionality execution. The historical context of code injection and authorization vulnerabilities further amplifies these concerns, suggesting that these types of flaws may be endemic to the plugin's development.
Key Concerns
- Unprotected AJAX handlers
- Low percentage of properly escaped output
- Past vulnerabilities: Code Injection
- Past vulnerabilities: Missing Authorization
- Limited nonce checks
- Limited capability checks
Product XML Feed Manager for WooCommerce – Google Shopping, Social Sites, Skroutz & More Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Product XML Feed Manager for WooCommerce <= 2.9.3 - Authenticated (Contributor+) Remote Code Execution
Product XML Feed Manager for WooCommerce <= 2.9.2 - Missing Authorization
Product XML Feed Manager for WooCommerce – Google Shopping, Social Sites, Skroutz & More Code Analysis
Output Escaping
Data Flow Analysis
Product XML Feed Manager for WooCommerce – Google Shopping, Social Sites, Skroutz & More Attack Surface
AJAX Handlers 12
WordPress Hooks 22
Maintenance & Trust
Product XML Feed Manager for WooCommerce – Google Shopping, Social Sites, Skroutz & More Maintenance & Trust
Maintenance Signals
Community Trust
Product XML Feed Manager for WooCommerce – Google Shopping, Social Sites, Skroutz & More Alternatives
WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel
wp-all-export
Easily export data from any post type, custom field, or taxonomy to a CSV, XML, or Excel file of any custom format. Supports WooCommerce products, ord …
WP Ultimate CSV Importer – Import CSV, XML & Excel into WordPress
wp-ultimate-csv-importer
Effortlessly import, export, and migrate your WordPress data with WP Ultimate CSV Importer. This all-in-one solution supports CSV, XML, and Excel file …
Import WooCommerce Suite
import-woocommerce
Use the WooCommerce Import Suite to import Products, Orders, Coupons, Customers, and Reviews with ease. Requires the WP Ultimate CSV Importer Free plu …
XML for Google Merchant Center
xml-for-google-merchant-center
Creates a XML feed that allows merchants to easily display their products across Google’s network.
WP All Export – Order Export for WooCommerce
order-export-for-woocommerce
Drag & drop to export orders to CSV, Excel, or XML files of any format. Supports customer data, line items, date range filtering, and more with po …
Product XML Feed Manager for WooCommerce – Google Shopping, Social Sites, Skroutz & More Developer Profile
63 plugins · 136K total installs
How We Detect Product XML Feed Manager for WooCommerce – Google Shopping, Social Sites, Skroutz & More
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/product-xml-feeds-for-woocommerce/assets/css/backend.css/wp-content/plugins/product-xml-feeds-for-woocommerce/assets/js/backend.js/wp-content/plugins/product-xml-feeds-for-woocommerce/assets/js/backend.jsproduct-xml-feeds-for-woocommerce/assets/css/backend.css?ver=product-xml-feeds-for-woocommerce/assets/js/backend.js?ver=HTML / DOM Fingerprints
alg-wc-xml-feed-admin-product-ajax-feed-generationalg-wc-xml-feed-admin-product-ajax-feed-generation-start<!-- Product XML Feeds for WooCommerce --><!-- Product XML Feeds for WooCommerce - Feed Section Settings -->data-alg-wc-xml-feed-noncealg_wc_xml_feed_params/wp-json/alg_wc_product_xml_feeds/v1/get_products/wp-json/alg_wc_product_xml_feeds/v1/get_cats/wp-json/alg_wc_product_xml_feeds/v1/get_tags