Spottr Security & Risk Analysis

wordpress.org/plugins/spottr

Spottr is the world’s most advanced marketplace that helps people to find anything that is for sale within 2 minutes of thinking about it; thereby hel …

0 active installs v1.0.0 PHP 5.5+ WP 3.6.0+ Updated Unknown
ecommerceproductshopspottrwoocomerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Spottr Safe to Use in 2026?

Generally Safe

Score 100/100

Spottr has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The spottr v1.0.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, using prepared statements for all SQL queries, and properly escaping the vast majority of its output. The absence of any known historical vulnerabilities is also a strong indicator of a generally secure development process. The use of the Guzzle bundled library is noted, which will require ongoing vigilance regarding its security updates.

However, significant security concerns arise from the plugin's attack surface. With 8 AJAX handlers, 4 of which lack authentication checks, there's a substantial risk of unauthorized access and execution of these functions. While the taint analysis showed no critical or high severity flows, the presence of 2 flows with unsanitized paths, even if not deemed critical in this analysis, warrants attention as it could potentially lead to vulnerabilities if data sources change or are exploited in unexpected ways.

In conclusion, while the plugin's core code practices are commendable, the high number of unprotected AJAX endpoints represents a critical security weakness that could be exploited by unauthenticated users. The vulnerability history is clean, which is excellent, but the current state of the attack surface poses a real and present risk that needs immediate mitigation.

Key Concerns

  • AJAX handlers without auth checks
  • Flows with unsanitized paths
  • Bundled library (Guzzle) - requires monitoring
Vulnerabilities
None known

Spottr Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Spottr Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
27 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

96% escaped28 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
syncFunction (includes\class-spottr.php:163)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Spottr Attack Surface

Entry Points8
Unprotected4

AJAX Handlers 8

authwp_ajax_spottr_loginincludes\class-spottr.php:19
noprivwp_ajax_spottr_loginincludes\class-spottr.php:20
authwp_ajax_spottr_disconnectincludes\class-spottr.php:22
noprivwp_ajax_spottr_disconnectincludes\class-spottr.php:23
authwp_ajax_spottr_contentincludes\class-spottr.php:25
noprivwp_ajax_spottr_contentincludes\class-spottr.php:26
authwp_ajax_sync_spottrincludes\class-spottr.php:48
noprivwp_ajax_sync_spottrincludes\class-spottr.php:49
WordPress Hooks 12
actionadmin_menuincludes\class-spottr.php:15
actionadmin_enqueue_scriptsincludes\class-spottr.php:17
filtermanage_edit-product_cat_columnsincludes\class-spottr.php:28
filtermanage_product_cat_custom_columnincludes\class-spottr.php:30
filtermanage_product_tag_custom_columnincludes\class-spottr.php:32
filtermanage_edit-product_tag_columnsincludes\class-spottr.php:34
actionproduct_cat_edit_form_fieldsincludes\class-spottr.php:36
actionproduct_tag_edit_form_fieldsincludes\class-spottr.php:38
filtermanage_edit-product_columnsincludes\class-spottr.php:40
filtermanage_product_posts_custom_columnincludes\class-spottr.php:42
actionedit_form_after_titleincludes\class-spottr.php:44
actionsave_postincludes\class-spottr.php:46
Maintenance & Trust

Spottr Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedUnknown
PHP min version5.5
Downloads588

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Spottr Developer Profile

spottr

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Spottr

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/spottr/assets/css/spottr-admin.css/wp-content/plugins/spottr/assets/js/spottr-admin.js
Script Paths
/wp-content/plugins/spottr/assets/js/spottr-admin.js
Version Parameters
spottr/assets/css/spottr-admin.css?ver=spottr/assets/js/spottr-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
spottr-product
Data Attributes
spottr_product
JS Globals
spottr_ajax_object
REST Endpoints
/wp-json/spottr/v1/process
FAQ

Frequently Asked Questions about Spottr