
Sharespine Woocommerce Connector Security & Risk Analysis
wordpress.org/plugins/sharespine-woocommerce-connectorPremium Synchronizing of customers, products and orders from WooCommerce to Fortnox, Specter, Visma, Mamut, Hogia, CDON, Fyndiq, Tradera, Afound ...
Is Sharespine Woocommerce Connector Safe to Use in 2026?
Generally Safe
Score 99/100Sharespine Woocommerce Connector has a strong security track record. Known vulnerabilities have been patched promptly.
The "sharespine-woocommerce-connector" v4.8.56 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, and external HTTP requests is commendable. All SQL queries are prepared, and output is properly escaped, which are critical security practices. The plugin also correctly implements capability checks on all identified REST API routes, indicating a good understanding of WordPress security mechanisms.
However, the static analysis reveals a notable lack of nonce checks. While capability checks are present, the absence of nonces on AJAX handlers (even though there are none reported) and REST API endpoints can be a concern, as it could leave the application vulnerable to CSRF attacks if AJAX handlers were introduced later or if the capability checks were somehow bypassed. The plugin's vulnerability history includes one medium-severity vulnerability related to missing authorization, which, while patched, suggests a past pattern of authorization issues that warrants careful consideration.
In conclusion, the plugin demonstrates good coding practices regarding data handling and output. The primary weakness identified is the absence of nonce checks, which could present a risk if the attack surface expands. The past medium-severity vulnerability related to authorization, while resolved, highlights a historical area of concern. Overall, the plugin is relatively secure in its current state based on the analysis, but the lack of nonces is a potential area for improvement and vigilance.
Key Concerns
- Missing nonce checks detected
- Previous medium severity vulnerability (Missing Authorization)
Sharespine Woocommerce Connector Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Sharespine Woocommerce Connector <= 4.7.55 - Missing Authorization
Sharespine Woocommerce Connector Code Analysis
Output Escaping
Sharespine Woocommerce Connector Attack Surface
REST API Routes 3
WordPress Hooks 10
Maintenance & Trust
Sharespine Woocommerce Connector Maintenance & Trust
Maintenance Signals
Community Trust
Sharespine Woocommerce Connector Alternatives
Data Exchange for WooCommerce and 1C:Enterprise/1С:Предприятие
woocommerce-and-1centerprise-data-exchange
Provides data exchange between the WooCommerce plugin and business application "1C:Enterprise 8. Trade Management" (and compatible ones).
Magento 2 WP Integration
m2wp
Combine Magento 2 with the CMS capabilities of WordPress. Seamless user experience for visitors by integrating the design of Magento and WordPress.
Sello ChannelConnector
sello-channelconnector
Easily send your products to multiple Nordic and European marketplaces like CDON, Fyndiq, Tradera, Wupti and Coolshop.
Integration E-conomic for WooCommerce
integration-e-conomic-for-woocommerce
Seamless WooCommerce Integration with E-conomic
VegaVend Merchant Connector
vegavend-merchant-connector
A plugin that seamlessly integrates and synchronises your products into the VegaVend marketplace.
Sharespine Woocommerce Connector Developer Profile
1 plugin · 500 total installs
How We Detect Sharespine Woocommerce Connector
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sharespine-woocommerce-connector/css/sharespine-connector.css/wp-content/plugins/sharespine-woocommerce-connector/js/sharespine-connector.js/wp-content/plugins/sharespine-woocommerce-connector/js/sharespine-connector.jssharespine-woocommerce-connector/css/sharespine-connector.css?ver=sharespine-woocommerce-connector/js/sharespine-connector.js?ver=HTML / DOM Fingerprints
<!-- SHARESPINE: WooCommerce Connector --><!-- SHARESPINE: Connector --><!-- SHARESPINE: Connector settings --><!-- SHARESPINE: Info -->data-sharespine-connectorsharespineConnector/wp-json/wc/sharespine/info/wp-json/wc/sharespine/orders/orderstatuses/wp-json/wc/sharespine/integrator