REST API Products Importer for WooCommerce Security & Risk Analysis

wordpress.org/plugins/rest-api-products-importer-for-woocommerce

Import products from any external WordPress/WooCommerce site's REST API directly into your store.

0 active installs v1.0.0 PHP 7.4+ WP 5.0+ Updated Sep 30, 2025
apiimporterproductsrest-apiwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is REST API Products Importer for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

REST API Products Importer for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The 'rest-api-products-importer-for-woocommerce' plugin v1.0.0 demonstrates several positive security practices, including the absence of dangerous functions, exclusive use of prepared statements for SQL queries, and proper output escaping. Its vulnerability history is also clean, with no recorded CVEs, indicating a potentially stable security track record. However, a significant concern is the presence of an unprotected AJAX handler, which represents a direct entry point that could be exploited without proper authentication. While the plugin has nonce checks and capability checks implemented for some functionalities, the unprotected AJAX handler bypasses these crucial security layers, presenting a clear risk. The taint analysis, though limited in scope, did not reveal critical or high-severity unsanitized paths, which is a positive sign, but the unprotected entry point remains the primary vulnerability.

Overall, the plugin exhibits a mix of good security hygiene and a notable oversight. The lack of critical vulnerabilities in its history and the robust handling of SQL and output are strengths. Nevertheless, the unprotected AJAX handler is a critical weakness that requires immediate attention. Without this, the plugin could be considered reasonably secure for its limited entry points. The limited attack surface (2 entry points) is also a positive factor, but the presence of even one unprotected entry point is a significant security liability. Users should be aware of this specific risk.

Key Concerns

  • Unprotected AJAX handler found
Vulnerabilities
None known

REST API Products Importer for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

REST API Products Importer for WooCommerce Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

REST API Products Importer for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
120 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped120 total outputs
Data Flows · Security
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
wcapi_importer_ajax_import_product (rest-api-products-importer-for-woocommerce.php:118)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

REST API Products Importer for WooCommerce Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 2

authwp_ajax_wcapi_importer_ajax_import_productrest-api-products-importer-for-woocommerce.php:43
authwp_ajax_wcapi_importer_ajax_import_envato_productrest-api-products-importer-for-woocommerce.php:44
WordPress Hooks 5
actionadmin_noticesrest-api-products-importer-for-woocommerce.php:27
filterplugin_action_linksrest-api-products-importer-for-woocommerce.php:38
actionadmin_menurest-api-products-importer-for-woocommerce.php:40
actionadmin_initrest-api-products-importer-for-woocommerce.php:41
actionadmin_enqueue_scriptsrest-api-products-importer-for-woocommerce.php:42
Maintenance & Trust

REST API Products Importer for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 30, 2025
PHP min version7.4
Downloads267

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

REST API Products Importer for WooCommerce Developer Profile

AppZoic

3 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect REST API Products Importer for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rest-api-products-importer-for-woocommerce/assets/css/plugin.css/wp-content/plugins/rest-api-products-importer-for-woocommerce/assets/js/plugin.js
Script Paths
/wp-content/plugins/rest-api-products-importer-for-woocommerce/assets/js/plugin.js
Version Parameters
rest-api-products-importer-for-woocommerce/assets/css/plugin.css?ver=rest-api-products-importer-for-woocommerce/assets/js/plugin.js?ver=

HTML / DOM Fingerprints

JS Globals
wcapiImporterAjaxObj
REST Endpoints
/wp-json/wp/v2/product/
FAQ

Frequently Asked Questions about REST API Products Importer for WooCommerce