ShoppingFeeder Security & Risk Analysis

wordpress.org/plugins/shoppingfeeder

Seamlessly allows you to integrate your WooCommerce store with ShoppingFeeder and send to Google Shopping and Facebook Ads.

300 active installs v1.6.1 PHP + WP 3.0.1+ Updated Jul 3, 2025
comparison-shoppingfacebook-dynamic-product-adsgoogle-shoppingmarketplacesprice-comparison
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ShoppingFeeder Safe to Use in 2026?

Generally Safe

Score 100/100

ShoppingFeeder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The shoppingfeeder plugin v1.6.1 exhibits a generally positive security posture with no recorded vulnerabilities or CVEs, indicating a history of stable and secure development. The static analysis reveals a very small attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits potential entry points for attackers. Furthermore, all identified SQL queries utilize prepared statements, which is a strong practice against SQL injection. However, there are notable areas of concern. The presence of the `unserialize` function is a critical risk, as it can lead to Remote Code Execution if used with untrusted input. The low percentage of properly escaped output (37%) suggests a significant risk of Cross-Site Scripting (XSS) vulnerabilities across multiple output points. Additionally, the complete absence of nonce checks on the limited entry points, if any were to emerge, is a weakness. The single capability check is also a minimal security control. While the plugin's lack of historical vulnerabilities is a major strength, the identified code signals, particularly `unserialize` and widespread unescaped output, present tangible risks that require immediate attention.

Key Concerns

  • Use of unserialize function
  • Low percentage of properly escaped output
  • No nonce checks on entry points
  • Only one capability check
Vulnerabilities
None known

ShoppingFeeder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ShoppingFeeder Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
2 prepared
Unescaped Output
24
14 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Dangerous Functions Found

unserialize$unserialized = unserialize( $product_attribute_row->meta_value );includes\class-sf-attribute.php:41

SQL Query Safety

100% prepared2 total queries

Output Escaping

37% escaped38 total outputs
Attack Surface

ShoppingFeeder Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionparse_requestshoppingfeeder.php:64
actioninitshoppingfeeder.php:610
filterquery_varsshoppingfeeder.php:625
actionadmin_initshoppingfeeder.php:635
actionadmin_menushoppingfeeder.php:637
actionwoocommerce_checkout_order_processedshoppingfeeder.php:732
actionwp_headshoppingfeeder.php:744
Maintenance & Trust

ShoppingFeeder Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 3, 2025
PHP min version
Downloads16K

Community Trust

Rating100/100
Number of ratings20
Active installs300
Developer Profile

ShoppingFeeder Developer Profile

ShoppingFeeder

1 plugin · 300 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ShoppingFeeder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shoppingfeeder/css/shoppingfeeder.css/wp-content/plugins/shoppingfeeder/js/shoppingfeeder.js
Script Paths
/wp-content/plugins/shoppingfeeder/js/shoppingfeeder.js
Version Parameters
shoppingfeeder/css/shoppingfeeder.css?ver=shoppingfeeder/js/shoppingfeeder.js?ver=

HTML / DOM Fingerprints

CSS Classes
shoppingfeeder-debug-wrappershoppingfeeder-debug-response
HTML Comments
Copyright 2015 ShoppingFeeder (Pty) Ltd ( email : info@shoppingfeeder.com )This program is free software; you can redistribute it and/or modifyThis program is distributed in the hope that it will be useful,You should have received a copy of the GNU General Public License+1 more
Data Attributes
data-shoppingfeeder-debug-url
JS Globals
shoppingfeeder_debug_url
REST Endpoints
/wp-json/shoppingfeeder/v1/products/wp-json/shoppingfeeder/v1/orders/wp-json/shoppingfeeder/v1/debug/wp-json/shoppingfeeder/v1/test/wp-json/shoppingfeeder/v1/version/wp-json/shoppingfeeder/v1/attributes
FAQ

Frequently Asked Questions about ShoppingFeeder