
Splash Sync Security & Risk Analysis
wordpress.org/plugins/splash-connectorSplash Sync, the synchronization system of innovative companies! Synchronize your website with all your business applications.
Is Splash Sync Safe to Use in 2026?
Generally Safe
Score 99/100Splash Sync has a strong security track record. Known vulnerabilities have been patched promptly.
The splash-connector plugin, version 2.0.10, exhibits a generally good security posture in its static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events that represent an attack surface, and crucially, none of these are unprotected. The plugin also avoids dangerous functions, uses prepared statements for all its SQL queries, and performs no file operations or external HTTP requests. This indicates a strong focus on secure coding practices for these areas.
However, the static analysis does reveal a weakness in output escaping, with 25% of outputs being improperly escaped. Additionally, the taint analysis shows two flows with unsanitized paths. While these are not flagged as critical or high severity, they represent potential avenues for vulnerabilities if not properly handled. The vulnerability history, though, shows only one medium-severity CVE in the past, which is now patched. This, combined with the absence of unprotected entry points, suggests that previous vulnerabilities may have been addressed effectively.
In conclusion, splash-connector has a solid foundation with minimal attack surface and secure handling of critical areas like database interactions. The primary concerns lie in the potential for cross-site scripting (XSS) due to unescaped output and unsanitized taint flows. While the past vulnerability was medium severity and is patched, these identified code signals warrant attention to ensure future security.
Key Concerns
- Unsanitized Taint Flows
- Improper Output Escaping (25%)
Splash Sync Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Splash Sync <= 2.0.7 - Reflected Cross-Site Scripting
Splash Sync Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Splash Sync Attack Surface
WordPress Hooks 16
Maintenance & Trust
Splash Sync Maintenance & Trust
Maintenance Signals
Community Trust
Splash Sync Alternatives
Afterpay Gateway for WooCommerce
afterpay-gateway-for-woocommerce
Provide Afterpay as a payment option for WooCommerce orders.
Holded integration
holded-integration
Holded service integration with WooCommerce
FG PrestaShop to WooCommerce
fg-prestashop-to-woocommerce
A plugin to migrate PrestaShop e-commerce solution to WooCommerce
Stock Sync for WooCommerce
stock-sync-for-woocommerce
Sync stock quantities between two WooCommerce stores.
WSW – Shopify WooCommerce / WordPress Integration and Migration
wsw-import-export-ecommerce-integration
It links and imports products,categories,tags from Shopify and converts them into WooCommerce items automatically with the same metadata.
Splash Sync Developer Profile
1 plugin · 100 total installs
How We Detect Splash Sync
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/splash-connector/assets/css/splash-connector.css/wp-content/plugins/splash-connector/assets/js/splash-connector.jsSplash Connector 2.0.10/wp-content/plugins/splash-connector/assets/js/splash-connector.jssplash-connector/assets/css/splash-connector.css?ver=splash-connector/assets/js/splash-connector.js?ver=HTML / DOM Fingerprints
<!-- Splash Sync Wordpress Plugin --><!-- Splash Connector Main --><!-- Splash Connector Settings Page --><!-- Splash Connector Admin Menu -->+11 moredata-splash-connector-iddata-splash-connector-actiondata-splash-connector-targetdata-splash-connector-nonceSplashConnectorSettingsSplashConnectorAjax