
Sortable Amazon Wishlist Security & Risk Analysis
wordpress.org/plugins/sortable-amazon-wishlistwidget displaying sorted Amazon wishlist
Is Sortable Amazon Wishlist Safe to Use in 2026?
Generally Safe
Score 85/100Sortable Amazon Wishlist has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The sortable-amazon-wishlist plugin v0.2 exhibits a mixed security posture. On the positive side, it has no known CVEs, a clean vulnerability history, and all SQL queries utilize prepared statements, indicating a good understanding of preventing SQL injection. However, significant security concerns arise from the static analysis. The complete absence of nonce checks and capability checks across all entry points is a major weakness, leaving potential for CSRF and privilege escalation attacks if any vulnerabilities are discovered.
The code also demonstrates a concerning lack of output escaping, with 100% of outputs being unescaped. This presents a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the site. The presence of the `create_function` function is another red flag, as it is deprecated and can be a source of security issues if not handled with extreme care, especially when dealing with user-supplied input. The taint analysis revealing four flows with unsanitized paths, while not critical or high severity, is still a concern and suggests potential for vulnerabilities.
Overall, while the plugin has a clean history and good database practices, the identified weaknesses in output escaping, authorization checks, and the use of `create_function` create significant security risks. The lack of any reported vulnerabilities in the past could be due to its limited attack surface or simply good fortune, but the current analysis highlights areas that require immediate attention to improve its security.
Key Concerns
- 0% output escaping
- 0 nonce checks
- 0 capability checks
- Use of create_function
- 4 flows with unsanitized paths
Sortable Amazon Wishlist Security Vulnerabilities
Sortable Amazon Wishlist Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Sortable Amazon Wishlist Attack Surface
WordPress Hooks 4
Maintenance & Trust
Sortable Amazon Wishlist Maintenance & Trust
Maintenance Signals
Community Trust
Sortable Amazon Wishlist Alternatives
Amazon Wishlist Pro
amazon-wishlist-pro
This plugin will display your Amazon wishlist.
NutsForPress Sort Any Post
nutsforpress-sort-any-posts
NutsForPress Sort Any Posts is a simple and lightweight plugin that allows you to sort any kind of posts and show them in the order you've decided.
Wish Pics
wish-pics
Displays a wish list in the form of a grid of wanted items (for example CD, DVD or book covers).
Post Types Order
post-types-order
Sort posts and custom post type objects using a drag-and-drop, sortable JavaScript AJAX interface, or through the default WordPress dashboard
FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider
fluent-smtp
The Ultimate Forever Free Mail SMTP Plugin for WordPress. Connect with any SMTP, SendGrid, Mailgun, Amazon SES, Brevo, Postmark, Sparkpost, Google...
Sortable Amazon Wishlist Developer Profile
2 plugins · 210 total installs
How We Detect Sortable Amazon Wishlist
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sortable-amazon-wishlist/imgsquare.phpHTML / DOM Fingerprints
amazon-wishlist<!-- Plugin: Amazon Wishlist -->data-wishlistiddata-max-itemsdata-sortdata-size<div class="amazon-wishlist"><img src="/wp-content/plugins/amazon-wishlist/imgsquare.php?<img src="http://www.assoc-amazon.fr/e/ir?t=lesenever-21&l=as2&o=8&a=