
Spottr Security & Risk Analysis
wordpress.org/plugins/spottrSpottr is the world’s most advanced marketplace that helps people to find anything that is for sale within 2 minutes of thinking about it; thereby hel …
Is Spottr Safe to Use in 2026?
Generally Safe
Score 100/100Spottr has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The spottr v1.0.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, using prepared statements for all SQL queries, and properly escaping the vast majority of its output. The absence of any known historical vulnerabilities is also a strong indicator of a generally secure development process. The use of the Guzzle bundled library is noted, which will require ongoing vigilance regarding its security updates.
However, significant security concerns arise from the plugin's attack surface. With 8 AJAX handlers, 4 of which lack authentication checks, there's a substantial risk of unauthorized access and execution of these functions. While the taint analysis showed no critical or high severity flows, the presence of 2 flows with unsanitized paths, even if not deemed critical in this analysis, warrants attention as it could potentially lead to vulnerabilities if data sources change or are exploited in unexpected ways.
In conclusion, while the plugin's core code practices are commendable, the high number of unprotected AJAX endpoints represents a critical security weakness that could be exploited by unauthenticated users. The vulnerability history is clean, which is excellent, but the current state of the attack surface poses a real and present risk that needs immediate mitigation.
Key Concerns
- AJAX handlers without auth checks
- Flows with unsanitized paths
- Bundled library (Guzzle) - requires monitoring
Spottr Security Vulnerabilities
Spottr Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Spottr Attack Surface
AJAX Handlers 8
WordPress Hooks 12
Maintenance & Trust
Spottr Maintenance & Trust
Maintenance Signals
Community Trust
Spottr Alternatives
External Store for Shopify
wp-shopify
Display products from your Shopify store on your WordPress blog using shortcodes.
Premium Packages – Sell Digital Products Securely
wpdm-premium-packages
Premium Packages is a free, full-featured WordPress eCommerce plugin to sell digital products easily and securely.
ShopWP
wpshopify
Sell Shopify Products on WordPress. Display a simple buy button—or build a complex storefront. Power your WordPress store with a world-class ecommerce …
Cost Of Goods For WooCommerce
cost-of-goods
Maximize your store's profitability by accurately tracking the cost of goods sold (COGS) with our robust WooCommerce integration.
Products Lists from PrestaShop – Listados Personalizados
products-lists-from-prestashop
Plugin que muestra productos de una tienda PrestaShop en WordPress usando su API, con diseño responsive y opciones de listado en el backoffice
Spottr Developer Profile
1 plugin · 0 total installs
How We Detect Spottr
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/spottr/assets/css/spottr-admin.css/wp-content/plugins/spottr/assets/js/spottr-admin.js/wp-content/plugins/spottr/assets/js/spottr-admin.jsspottr/assets/css/spottr-admin.css?ver=spottr/assets/js/spottr-admin.js?ver=HTML / DOM Fingerprints
spottr-productspottr_productspottr_ajax_object/wp-json/spottr/v1/process