
SJRubel Product Feed Generator Security & Risk Analysis
wordpress.org/plugins/sjrubel-product-feed-generatorShort Description: WooCommerce plugin to generate Google Merchant compatible XML product feeds with filtering and field mapping support.
Is SJRubel Product Feed Generator Safe to Use in 2026?
Generally Safe
Score 100/100SJRubel Product Feed Generator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sjrubel-product-feed-generator" v1.0.0 plugin exhibits a mixed security posture. On the positive side, it has no recorded vulnerability history, indicating a clean track record. The taint analysis shows no critical or high severity flows with unsanitized paths, which is a strong indicator of secure handling of user input in sensitive operations. Furthermore, the plugin demonstrates good practices in output escaping, with a very high percentage (95%) of outputs properly escaped, and a reasonable number of nonce and capability checks.
However, there are notable concerns. The static analysis reveals a significant attack surface with 5 AJAX handlers, and critically, 2 of these lack authentication checks. This represents a direct pathway for unauthenticated attackers to interact with potentially sensitive plugin functionality. Additionally, all three SQL queries are executed without prepared statements, increasing the risk of SQL injection vulnerabilities. While taint analysis didn't flag these, the absence of prepared statements is a fundamental security flaw that should be addressed.
In conclusion, while the plugin's lack of historical vulnerabilities and good output escaping are strengths, the unprotected AJAX handlers and the use of raw SQL queries are significant weaknesses that expose the plugin and the WordPress site to potential attacks. The absence of any known vulnerabilities could be due to the plugin's limited adoption or simply a lack of past rigorous security auditing.
Key Concerns
- Unprotected AJAX handlers
- SQL queries without prepared statements
SJRubel Product Feed Generator Security Vulnerabilities
SJRubel Product Feed Generator Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
SJRubel Product Feed Generator Attack Surface
AJAX Handlers 5
WordPress Hooks 14
Maintenance & Trust
SJRubel Product Feed Generator Maintenance & Trust
Maintenance Signals
Community Trust
SJRubel Product Feed Generator Alternatives
WebToffee WooCommerce Product Feeds – Google Shopping, Pinterest, TikTok Ads, & More
webtoffee-product-feed
Create WooCommerce product feeds containing unlimited number of products. Supports Google Product feed, Facebook catalog feed, Instagram, Bing & m …
AW Feed Manager For WooCommerce Product
my-feed
Generate error-free woocommerce product feed plugin for Google Shopping, Google Merchant.
Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce
woo-product-feed-pro
Most popular WooCommerce product feed plugin supporting Google shopping feed, meta/facebook feed, bing product feed & more.
Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces
best-woocommerce-feed
Generate WooCommerce product feeds for 200+ marketplaces. Sell on Google Shopping, Facebook, Instagram, Amazon, eBay, TikTok and more.
WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping
wp-product-feed-manager
Easily create high-quality product feeds for Google Shopping and Google Merchant Center in your WooCommerce store. Increase sales on Google now!
SJRubel Product Feed Generator Developer Profile
3 plugins · 10 total installs
How We Detect SJRubel Product Feed Generator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sjrubel-product-feed-generator/assets/admin/css/sjrubel_feed_config.css/wp-content/plugins/sjrubel-product-feed-generator/assets/admin/js/sjrubel-mapping.js/wp-content/plugins/sjrubel-product-feed-generator/assets/admin/js/sjrubel_feed_config.js/wp-content/plugins/sjrubel-product-feed-generator/assets/admin/js/sjrubel-mapping.js/wp-content/plugins/sjrubel-product-feed-generator/assets/admin/js/sjrubel_feed_config.jssjrubel-product-feed-generator/assets/admin/css/sjrubel_feed_config.css?ver=1.0sjrubel-product-feed-generator/assets/admin/js/sjrubel-mapping.js?ver=1.0sjrubel-product-feed-generator/assets/admin/js/sjrubel_feed_config.js?ver=1.0HTML / DOM Fingerprints
sjrubel_FeedAjax/wp-json/pa-google-feed/v1/generate-feed