
StackCommerce Deal Feed Security & Risk Analysis
wordpress.org/plugins/stackcommerce-deal-feedThe StackCommerce Deal Feed plugin is the best way to surface curated and relevant tech & lifestyle deals in front of your readers.
Is StackCommerce Deal Feed Safe to Use in 2026?
Generally Safe
Score 85/100StackCommerce Deal Feed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "stackcommerce-deal-feed" plugin v1.1.6 exhibits a generally good security posture based on the static analysis provided. It has a limited attack surface with only one entry point (a shortcode) and no detected AJAX handlers or REST API routes that lack authentication. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its positive security profile. Furthermore, all SQL queries utilize prepared statements, which is a strong security practice.
However, several areas raise concerns. The most significant is the extremely low percentage of properly escaped output (8%). This indicates a high likelihood of cross-site scripting (XSS) vulnerabilities, as user-supplied data or data fetched from external sources may be rendered directly in the browser without adequate sanitization. Additionally, the complete lack of nonce checks and capability checks, even for the shortcode, suggests that actions triggered by the shortcode might be susceptible to CSRF attacks or unauthorized execution if the shortcode's functionality is sensitive.
The plugin's vulnerability history is notably clean, with no known CVEs. This, combined with the lack of detected critical or high severity issues in the taint analysis, suggests that if vulnerabilities exist, they are likely low impact or have not been discovered. While this is a strength, the significant output escaping issue overshadows this positive aspect, indicating a potential blind spot in the development process.
Key Concerns
- Low output escaping percentage (8%)
- Missing nonce checks
- Missing capability checks
StackCommerce Deal Feed Security Vulnerabilities
StackCommerce Deal Feed Code Analysis
Output Escaping
StackCommerce Deal Feed Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
StackCommerce Deal Feed Maintenance & Trust
Maintenance Signals
Community Trust
StackCommerce Deal Feed Alternatives
Sotmarket Affiliate plugin
sotmarket-affiliate-plugin
Универсальный плагин для работы с партнёрской программой sotmarket.ru
Custom Sidebars – Dynamic Sidebar Classic Widget Area Manager
custom-sidebars
Flexible sidebars for custom classic widget configurations on any page or post. Create custom sidebars with ease!
Image Widget
image-widget
A simple image widget that uses the native WordPress media manager to add image widgets to your site.
Widget Logic
widget-logic
Widget Logic lets you control on which pages widgets appear using WP's conditional tags.
WooSidebars
woosidebars
WooSidebars adds functionality to display different widgets in a sidebar, according to a context (for example, a specific page or a category).
StackCommerce Deal Feed Developer Profile
2 plugins · 20 total installs
How We Detect StackCommerce Deal Feed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/stackcommerce-deal-feed/wp/js/stackcommerce-admin.js/wp-content/plugins/stackcommerce-deal-feed/wp/js/stackcommerce.js/wp-content/plugins/stackcommerce-deal-feed/wp/css/stackcommerce-admin.css/wp-content/plugins/stackcommerce-deal-feed/wp/css/stackcommerce.css/wp-content/plugins/stackcommerce-deal-feed/wp/js/stackcommerce-admin.js/wp-content/plugins/stackcommerce-deal-feed/wp/js/stackcommerce.jsstackcommerce-deal-feed/wp/js/stackcommerce-admin.js?ver=stackcommerce-deal-feed/wp/js/stackcommerce.js?ver=stackcommerce-deal-feed/wp/css/stackcommerce-admin.css?ver=stackcommerce-deal-feed/wp/css/stackcommerce.css?ver=HTML / DOM Fingerprints
stackcommerce-deal-feedstackcommerce-widgetstackcommerce-widget__contentdata-publisheriddata-open-new-tabdata-utm-sourcedata-additional-url-paramsdata-affiliateidstackcommerceStackCommerceWidgetSettings[stackcommerce-deal-feed]