
Spreadr Woocommerce Plugin – Amazon Importer for Dropshipping and Affiliate Security & Risk Analysis
wordpress.org/plugins/spreadr-for-woocomerceSpreadr enables WooCommerce merchants to find and sell products from Amazon. To learn more about Spreadr, visit https://spreadr.co/woocommerce
Is Spreadr Woocommerce Plugin – Amazon Importer for Dropshipping and Affiliate Safe to Use in 2026?
Generally Safe
Score 98/100Spreadr Woocommerce Plugin – Amazon Importer for Dropshipping and Affiliate has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "spreadr-for-woocomerce" plugin version 1.0.8 exhibits a concerning security posture primarily due to a significant number of unprotected AJAX handlers. While the plugin demonstrates good practices by exclusively using prepared statements for SQL queries and having a moderate rate of output escaping, the sheer volume of unprotected entry points (25 out of 27) creates a substantial attack surface. This could allow unauthenticated users to trigger potentially sensitive actions or expose information.
The taint analysis shows 5 flows with unsanitized paths, which, while not classified as critical or high severity in this specific analysis, warrants attention. These flows could indicate potential vulnerabilities if user-supplied input is not properly validated or sanitized before being used in file operations or external requests. The plugin's history of 2 known CVEs, including a high and medium severity vulnerability, with the last one being recent, suggests a pattern of security weaknesses that have required patching. The common vulnerability type of 'Missing Authorization' directly correlates with the static analysis findings of numerous unprotected AJAX handlers.
In conclusion, while the plugin has strengths in its database query handling and output escaping, the pervasive lack of authorization checks on its AJAX endpoints presents a critical risk. Coupled with past vulnerabilities and the presence of unsanitized input flows, this plugin requires immediate attention to secure its entry points. The absence of unpatched vulnerabilities currently is positive, but the underlying architectural issues remain.
Key Concerns
- High number of unprotected AJAX handlers
- Unsanitized paths in taint analysis flows
- History of high and medium severity CVEs
- Missing capability checks
- Low nonce check coverage
Spreadr Woocommerce Plugin – Amazon Importer for Dropshipping and Affiliate Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Spreadr Woocommerce <= 1.0.4 - Missing Authorization
Spreadr Woocommerce <= 1.0.4 - Missing Authorization to Arbitrary Content Deletion
Spreadr Woocommerce Plugin – Amazon Importer for Dropshipping and Affiliate Release Timeline
Spreadr Woocommerce Plugin – Amazon Importer for Dropshipping and Affiliate Code Analysis
Output Escaping
Data Flow Analysis
Spreadr Woocommerce Plugin – Amazon Importer for Dropshipping and Affiliate Attack Surface
AJAX Handlers 27
WordPress Hooks 14
Maintenance & Trust
Spreadr Woocommerce Plugin – Amazon Importer for Dropshipping and Affiliate Maintenance & Trust
Maintenance Signals
Community Trust
Spreadr Woocommerce Plugin – Amazon Importer for Dropshipping and Affiliate Alternatives
Amazon Product in a Post Plugin
amazon-product-in-a-post-plugin
Add formatted Amazon Products to any page or post using the Amazon Product Advertising API.
Amazing Affiliates – Toolkit for Amazon Associates with Amazon Product Blocks and Amazon PAAPI5 / Creators API integration
amazingaffiliates
Monetize your Amazon Affiliate Income with Amazon API Integration & Amazon Product Blocks!
Add & Replace Affiliate Links for Amazon
add-replace-affiliate-links-for-amazon
Add & Replace Affiliate Links for Amazon plugin helps you to add or update Amazon Associate tag parameters in links.
AmaSync – Amazon Product Importer & Affiliate for WooCommerce
affiliate-products-importer-for-woocommerce
Easily import Amazon affiliate products into your WooCommerce store.
Affiliate Product Ads for Amazon
affiliate-product-ads-for-amazon-associates
Display Amazon Product Advertising product ads automatically on WordPress Post Pages
Spreadr Woocommerce Plugin – Amazon Importer for Dropshipping and Affiliate Developer Profile
1 plugin · 500 total installs
How We Detect Spreadr Woocommerce Plugin – Amazon Importer for Dropshipping and Affiliate
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/spreadr-for-woocomerce/assets/css/style.css/wp-content/plugins/spreadr-for-woocomerce/assets/js/spreadr-frontend.jsspreadr-for-woocomerce/assets/css/style.css?ver=spreadr-for-woocomerce/assets/js/spreadr-frontend.js?ver=HTML / DOM Fingerprints
single_add_to_cart_buttonspreadr_regionspreadr_product_titleSpreadrButtonClick<p class="cart"><a tag="href="javascript:void(0);" rel="nofollow" onclick="SpreadrButtonClick(