FeedCraft Product Feed Security & Risk Analysis

wordpress.org/plugins/thebasics-product-feed

Powerful Google Merchant Center feed generator for WooCommerce. Adds GTIN, MPN, and Brand fields with high-performance XML/JSON REST API feeds.

0 active installs v2.0.2 PHP 7.4+ WP 6.2+ Updated Jan 20, 2026
google-merchant-centerproduct-feedshopping-feedwoocommercexml-feed
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is FeedCraft Product Feed Safe to Use in 2026?

Generally Safe

Score 100/100

FeedCraft Product Feed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The plugin "thebasics-product-feed" v2.0.2 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified attack surface, dangerous functions, direct SQL queries, or taint flows is a significant strength. Furthermore, the plugin demonstrates good practices by utilizing prepared statements for SQL and implementing nonce and capability checks, indicating a developer awareness of common WordPress security vulnerabilities.

However, a notable area of concern is the output escaping. With 52% of outputs properly escaped, there is a risk that the remaining 48% could be vulnerable to Cross-Site Scripting (XSS) attacks if the data originates from user input and is not properly sanitized before rendering. While no specific vulnerabilities or CVEs are recorded, this unescaped output presents a potential, albeit unconfirmed, risk.

In conclusion, the plugin is well-defended against many common attack vectors. The primary weakness lies in the incomplete output escaping, which warrants attention. The lack of recorded vulnerabilities is positive but should not lead to complacency, especially given the identified output escaping issues.

Key Concerns

  • Significant portion of outputs not properly escaped
Vulnerabilities
None known

FeedCraft Product Feed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

FeedCraft Product Feed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
24
26 escaped
Nonce Checks
3
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

52% escaped50 total outputs
Attack Surface

FeedCraft Product Feed Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_enqueue_scriptsthebasics-product-feed.php:51
actionwoocommerce_product_options_general_product_datathebasics-product-feed.php:57
actionwoocommerce_process_product_metathebasics-product-feed.php:62
actionwoocommerce_product_after_variable_attributesthebasics-product-feed.php:68
actionwoocommerce_save_product_variationthebasics-product-feed.php:75
actionrest_api_initthebasics-product-feed.php:83
filterrest_pre_serve_requestthebasics-product-feed.php:86
actionadmin_menuthebasics-product-feed.php:94
actionadmin_initthebasics-product-feed.php:95
actionplugins_loadedthebasics-product-feed.php:1691
Maintenance & Trust

FeedCraft Product Feed Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 20, 2026
PHP min version7.4
Downloads119

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

FeedCraft Product Feed Developer Profile

ahme1016

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect FeedCraft Product Feed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/thebasics-product-feed/assets/css/admin.css/wp-content/plugins/thebasics-product-feed/assets/js/admin.js
Script Paths
/wp-content/plugins/thebasics-product-feed/assets/js/admin.js
Version Parameters
thebasics-product-feed/assets/css/admin.css?ver=thebasics-product-feed/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
feedcraft-settings
Data Attributes
name="prime_feed_default_age_group"name="prime_feed_default_gender"name="prime_feed_require_images"name="prime_feed_color_attributes"name="prime_feed_size_attributes"name="prime_feed_size_case"+1 more
REST Endpoints
/wp-json/feedcraft-product-feed/v1/xml/wp-json/feedcraft-product-feed/v1/json
FAQ

Frequently Asked Questions about FeedCraft Product Feed