Products Feed Generator Security & Risk Analysis

wordpress.org/plugins/products-feed-generator

Generates an XML Products Feed for Google Merchant Center in RSS 2.0 format.

30 active installs v1.0.7 PHP 7.0+ WP 5.6+ Updated Apr 14, 2024
google-shoppinggoogle-shopping-feedproducts-feed-generatorwoocommerce-product-feedxml-data-feed
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Products Feed Generator Safe to Use in 2026?

Generally Safe

Score 92/100

Products Feed Generator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "products-feed-generator" plugin, version 1.0.7, exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping a high percentage of its output. It also has no recorded vulnerability history, suggesting a generally stable codebase. However, a significant concern arises from the presence of an unprotected AJAX handler, which represents a direct attack vector without any authentication or authorization checks. This single unprotected entry point, despite the limited overall attack surface, poses a tangible risk that could be exploited by unauthenticated users.

Key Concerns

  • Unprotected AJAX handler
  • Missing nonce check on AJAX handler
Vulnerabilities
None known

Products Feed Generator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Products Feed Generator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
1
41 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

98% escaped42 total outputs
Attack Surface
1 unprotected

Products Feed Generator Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_generate_google_products_feedincludes\class-products-feed-generator.php:187
WordPress Hooks 14
actionplugins_loadedincludes\class-products-feed-generator.php:147
actionadmin_enqueue_scriptsincludes\class-products-feed-generator.php:169
actionadmin_enqueue_scriptsincludes\class-products-feed-generator.php:170
actionadmin_enqueue_scriptsincludes\class-products-feed-generator.php:172
filterwoocommerce_get_sections_productsincludes\class-products-feed-generator.php:175
filterwoocommerce_get_settings_productsincludes\class-products-feed-generator.php:176
actionwoocommerce_admin_field_buttonincludes\class-products-feed-generator.php:177
actionwoocommerce_settings_save_productsincludes\class-products-feed-generator.php:178
actionwoocommerce_product_options_general_product_dataincludes\class-products-feed-generator.php:179
actionwoocommerce_process_product_metaincludes\class-products-feed-generator.php:180
actionwoocommerce_variation_options_pricingincludes\class-products-feed-generator.php:182
actionwoocommerce_save_product_variationincludes\class-products-feed-generator.php:183
actionwoocommerce_attribute_deletedincludes\class-products-feed-generator.php:185
actiongenerate_google_products_feedincludes\class-products-feed-generator.php:193

Scheduled Events 3

generate_google_products_feed
generate_google_products_feed
generate_google_products_feed
Maintenance & Trust

Products Feed Generator Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 14, 2024
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Products Feed Generator Developer Profile

Mike Carter

2 plugins · 30 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Products Feed Generator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/products-feed-generator/admin/css/pfg-admin-style.css/wp-content/plugins/products-feed-generator/admin/js/pfg-admin-script.js/wp-content/plugins/products-feed-generator/public/css/products-feed-generator-public.css/wp-content/plugins/products-feed-generator/public/js/products-feed-generator-public.js
Script Paths
/wp-content/plugins/products-feed-generator/admin/js/pfg-admin-script.js/wp-content/plugins/products-feed-generator/public/js/products-feed-generator-public.js
Version Parameters
products-feed-generator/admin/css/pfg-admin-style.css?ver=products-feed-generator/admin/js/pfg-admin-script.js?ver=products-feed-generator/public/css/products-feed-generator-public.css?ver=products-feed-generator/public/js/products-feed-generator-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
pfg_product_debug_logpfg_product_attributes_mappfg_product_identifiersfeed_managementload-iconview-feedview-urlfeed_management_error+1 more
Data Attributes
data-pfg-product-iddata-pfg-product-namedata-pfg-product-pricedata-pfg-product-urldata-pfg-product-imagedata-pfg-product-description+7 more
JS Globals
pfg_admin_params
REST Endpoints
/wp-json/products-feed-generator/v1/generate-feed
FAQ

Frequently Asked Questions about Products Feed Generator