StackCommerce Deal Feed Security & Risk Analysis

wordpress.org/plugins/stackcommerce-deal-feed

The StackCommerce Deal Feed plugin is the best way to surface curated and relevant tech & lifestyle deals in front of your readers.

10 active installs v1.1.6 PHP + WP 4.0+ Updated Apr 7, 2017
ecommercesidebarwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is StackCommerce Deal Feed Safe to Use in 2026?

Generally Safe

Score 85/100

StackCommerce Deal Feed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "stackcommerce-deal-feed" plugin v1.1.6 exhibits a generally good security posture based on the static analysis provided. It has a limited attack surface with only one entry point (a shortcode) and no detected AJAX handlers or REST API routes that lack authentication. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its positive security profile. Furthermore, all SQL queries utilize prepared statements, which is a strong security practice.

However, several areas raise concerns. The most significant is the extremely low percentage of properly escaped output (8%). This indicates a high likelihood of cross-site scripting (XSS) vulnerabilities, as user-supplied data or data fetched from external sources may be rendered directly in the browser without adequate sanitization. Additionally, the complete lack of nonce checks and capability checks, even for the shortcode, suggests that actions triggered by the shortcode might be susceptible to CSRF attacks or unauthorized execution if the shortcode's functionality is sensitive.

The plugin's vulnerability history is notably clean, with no known CVEs. This, combined with the lack of detected critical or high severity issues in the taint analysis, suggests that if vulnerabilities exist, they are likely low impact or have not been discovered. While this is a strength, the significant output escaping issue overshadows this positive aspect, indicating a potential blind spot in the development process.

Key Concerns

  • Low output escaping percentage (8%)
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

StackCommerce Deal Feed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

StackCommerce Deal Feed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
96
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

8% escaped104 total outputs
Attack Surface

StackCommerce Deal Feed Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[stackCommerce] wp\includes\class-stackCommerce-shortcode.php:82
WordPress Hooks 6
actionadmin_menuwp\includes\admin-settings.php:18
actionadmin_initwp\includes\admin-settings.php:143
actionadmin_enqueue_scriptswp\includes\admin-settings.php:154
actionwidgets_initwp\includes\class-stackCommerce-widget.php:447
actionadmin_enqueue_scriptswp\includes\display-functions.php:12
actionwp_enqueue_scriptswp\includes\display-functions.php:86
Maintenance & Trust

StackCommerce Deal Feed Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedApr 7, 2017
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

StackCommerce Deal Feed Developer Profile

stackcommerce

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect StackCommerce Deal Feed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/stackcommerce-deal-feed/wp/js/stackcommerce-admin.js/wp-content/plugins/stackcommerce-deal-feed/wp/js/stackcommerce.js/wp-content/plugins/stackcommerce-deal-feed/wp/css/stackcommerce-admin.css/wp-content/plugins/stackcommerce-deal-feed/wp/css/stackcommerce.css
Script Paths
/wp-content/plugins/stackcommerce-deal-feed/wp/js/stackcommerce-admin.js/wp-content/plugins/stackcommerce-deal-feed/wp/js/stackcommerce.js
Version Parameters
stackcommerce-deal-feed/wp/js/stackcommerce-admin.js?ver=stackcommerce-deal-feed/wp/js/stackcommerce.js?ver=stackcommerce-deal-feed/wp/css/stackcommerce-admin.css?ver=stackcommerce-deal-feed/wp/css/stackcommerce.css?ver=

HTML / DOM Fingerprints

CSS Classes
stackcommerce-deal-feedstackcommerce-widgetstackcommerce-widget__content
Data Attributes
data-publisheriddata-open-new-tabdata-utm-sourcedata-additional-url-paramsdata-affiliateid
JS Globals
stackcommerceStackCommerceWidgetSettings
Shortcode Output
[stackcommerce-deal-feed]
FAQ

Frequently Asked Questions about StackCommerce Deal Feed