Sharespine Woocommerce Connector Security & Risk Analysis

wordpress.org/plugins/sharespine-woocommerce-connector

Premium Synchronizing of customers, products and orders from WooCommerce to Fortnox, Specter, Visma, Mamut, Hogia, CDON, Fyndiq, Tradera, Afound ...

500 active installs v4.8.56 PHP 5.2.4+ WP 4.7+ Updated May 21, 2025
cdone-commerceintegrationplugboardsharespine
99
A · Safe
CVEs total1
Unpatched0
Last CVEMay 16, 2025
Download
Safety Verdict

Is Sharespine Woocommerce Connector Safe to Use in 2026?

Generally Safe

Score 99/100

Sharespine Woocommerce Connector has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: May 16, 2025Updated 10mo ago
Risk Assessment

The "sharespine-woocommerce-connector" v4.8.56 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, and external HTTP requests is commendable. All SQL queries are prepared, and output is properly escaped, which are critical security practices. The plugin also correctly implements capability checks on all identified REST API routes, indicating a good understanding of WordPress security mechanisms.

However, the static analysis reveals a notable lack of nonce checks. While capability checks are present, the absence of nonces on AJAX handlers (even though there are none reported) and REST API endpoints can be a concern, as it could leave the application vulnerable to CSRF attacks if AJAX handlers were introduced later or if the capability checks were somehow bypassed. The plugin's vulnerability history includes one medium-severity vulnerability related to missing authorization, which, while patched, suggests a past pattern of authorization issues that warrants careful consideration.

In conclusion, the plugin demonstrates good coding practices regarding data handling and output. The primary weakness identified is the absence of nonce checks, which could present a risk if the attack surface expands. The past medium-severity vulnerability related to authorization, while resolved, highlights a historical area of concern. Overall, the plugin is relatively secure in its current state based on the analysis, but the lack of nonces is a potential area for improvement and vigilance.

Key Concerns

  • Missing nonce checks detected
  • Previous medium severity vulnerability (Missing Authorization)
Vulnerabilities
1

Sharespine Woocommerce Connector Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-48128medium · 4.3Missing Authorization

Sharespine Woocommerce Connector <= 4.7.55 - Missing Authorization

May 16, 2025 Patched in 4.8.56 (8d)
Code Analysis
Analyzed Mar 16, 2026

Sharespine Woocommerce Connector Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

Sharespine Woocommerce Connector Attack Surface

Entry Points3
Unprotected0

REST API Routes 3

GET/wp-json/wc/sharespine/infoapi-resource-info.php:13
GET/wp-json/wc/sharespine/orders/orderstatusesapi-resource-info.php:46
GET/wp-json/wc/sharespine/integratorapi-resource-integrator.php:10
WordPress Hooks 10
filterwoocommerce_rest_product_object_queryapi-lastmodifiedatorafter-filter.php:33
filterwoocommerce_rest_product_queryapi-lastmodifiedatorafter-filter.php:34
actionrest_api_initapi-product-extensions.php:7
actionrest_api_initapi-resource-info.php:12
actionrest_api_initapi-resource-integrator.php:8
actionadmin_menumenu-shsp-connector.php:7
actionbefore_woocommerce_initsharespine-woocommerce-connector.php:21
actionupdated_postmetawc-meta-update.php:62
actionwoocommerce_product_set_stockwc-meta-update.php:71
actionwoocommerce_variation_set_stockwc-meta-update.php:72
Maintenance & Trust

Sharespine Woocommerce Connector Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 21, 2025
PHP min version5.2.4
Downloads11K

Community Trust

Rating100/100
Number of ratings3
Active installs500
Developer Profile

Sharespine Woocommerce Connector Developer Profile

Sharespine

1 plugin · 500 total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect Sharespine Woocommerce Connector

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sharespine-woocommerce-connector/css/sharespine-connector.css/wp-content/plugins/sharespine-woocommerce-connector/js/sharespine-connector.js
Script Paths
/wp-content/plugins/sharespine-woocommerce-connector/js/sharespine-connector.js
Version Parameters
sharespine-woocommerce-connector/css/sharespine-connector.css?ver=sharespine-woocommerce-connector/js/sharespine-connector.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- SHARESPINE: WooCommerce Connector --><!-- SHARESPINE: Connector --><!-- SHARESPINE: Connector settings --><!-- SHARESPINE: Info -->
Data Attributes
data-sharespine-connector
JS Globals
sharespineConnector
REST Endpoints
/wp-json/wc/sharespine/info/wp-json/wc/sharespine/orders/orderstatuses/wp-json/wc/sharespine/integrator
FAQ

Frequently Asked Questions about Sharespine Woocommerce Connector