Syncee for Suppliers Security & Risk Analysis

wordpress.org/plugins/syncee-for-suppliers

Expand your product reach and sell through dropshipping or wholesale globally. Grow your WooCommerce store's easily.

40 active installs v1.0.22 PHP 7.2+ WP 4.4+ Updated Dec 17, 2025
dropshippingecommercesales-channelsupplierswholesale
100
A · Safe
CVEs total1
Unpatched0
Last CVEOct 27, 2022
Download
Safety Verdict

Is Syncee for Suppliers Safe to Use in 2026?

Generally Safe

Score 100/100

Syncee for Suppliers has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Oct 27, 2022Updated 3mo ago
Risk Assessment

The 'syncee-for-suppliers' plugin v1.0.22 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, proper use of prepared statements for all SQL queries, and complete output escaping are significant strengths. The plugin also demonstrates good practice by performing capability checks on at least one entry point and avoids bundling external libraries, which can often introduce vulnerabilities. However, the analysis does reveal areas for improvement. The presence of two taint flows with unsanitized paths, even without critical or high severity designations, suggests potential for information leakage or unexpected behavior if not handled carefully. The lack of any nonce checks across all analyzed entry points is a notable concern, as nonces are a primary defense against CSRF attacks. Furthermore, while there are no currently unpatched CVEs, the plugin has a history of vulnerabilities, specifically missing authorization, which indicates a past pattern of security oversight. This history, coupled with the identified taint flows and lack of nonce checks, necessitates careful consideration despite the otherwise good static analysis results. Overall, the plugin has good foundations but requires attention to its limited attack surface's specific vulnerabilities and a review of its past security incidents to ensure continued protection.

Key Concerns

  • Taint flows with unsanitized paths
  • No nonce checks on any entry points
  • Past vulnerability history (Missing Authorization)
Vulnerabilities
1

Syncee for Suppliers Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

Syncee for Suppliers <= 1.0.5 - Missing Authorization to Sensitive Information Disclosure

Oct 27, 2022 Patched in 1.0.10 (453d)
Code Analysis
Analyzed Mar 16, 2026

Syncee for Suppliers Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
11 escaped
Nonce Checks
0
Capability Checks
1
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped11 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

3 flows2 with unsanitized paths
saveAccessTokenFromSyncee (includes\RestForSynceeSupplier.php:126)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Syncee for Suppliers Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionrest_api_initincludes\RestForSynceeSupplier.php:25
actionadmin_enqueue_scriptsSynceeSupplier.php:36
actionadmin_enqueue_scriptsSynceeSupplier.php:37
actionwp_enqueue_scriptsSynceeSupplier.php:39
actionwp_enqueue_scriptsSynceeSupplier.php:40
actionadmin_menuSynceeSupplier.php:178
Maintenance & Trust

Syncee for Suppliers Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 17, 2025
PHP min version7.2
Downloads6K

Community Trust

Rating68/100
Number of ratings5
Active installs40
Developer Profile

Syncee for Suppliers Developer Profile

akosglys

2 plugins · 1K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
453 days
View full developer profile
Detection Fingerprints

How We Detect Syncee for Suppliers

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/syncee-for-suppliers/View/bootstrap.css/wp-content/plugins/syncee-for-suppliers/JS/index_supplier.js/wp-content/plugins/syncee-for-suppliers/JS/sweetalert.js
Script Paths
/wp-content/plugins/syncee-for-suppliers/JS/index_supplier.js/wp-content/plugins/syncee-for-suppliers/JS/sweetalert.js
Version Parameters
syncee-for-suppliers/JS/index_supplier.js?ver=syncee-for-suppliers/JS/sweetalert.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-syncee_access_token_supplierdata-syncee_user_token_supplierdata-data_to_syncee_installer_supplier
JS Globals
syncee_globals_supplier
REST Endpoints
/wp-json/syncee/supplier/v1/
Shortcode Output
[syncee-for-suppliers]
FAQ

Frequently Asked Questions about Syncee for Suppliers