Trade Runner Security & Risk Analysis

wordpress.org/plugins/traderunner

WooCommerce to Trade Me integration.

100 active installs v3.14 PHP 5.6+ WP 4.1.1+ Updated Feb 24, 2025
trademetraderunnerwoocommerce
66
C · Use Caution
CVEs total3
Unpatched1
Last CVENov 30, 2025
Download
Safety Verdict

Is Trade Runner Safe to Use in 2026?

Use With Caution

Score 66/100

Trade Runner has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

3 known CVEs 1 unpatched Last CVE: Nov 30, 2025Updated 1yr ago
Risk Assessment

The "traderunner" v3.14 plugin exhibits a mixed security posture. On one hand, the static analysis reveals excellent adherence to secure coding practices within its current version. The absence of any dangerous functions, properly escaped output, secure handling of SQL queries with prepared statements, and a lack of file operations or external HTTP requests are all positive indicators. Furthermore, the attack surface appears minimal, with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication or proper checks.

However, the plugin's vulnerability history presents significant concerns. With a total of 3 known CVEs, and notably one that remains unpatched, there is a clear track record of security flaws. The common vulnerability types identified, Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS), are serious issues that can lead to unauthorized actions and data compromise. The fact that the last vulnerability was identified in November 2025 (though this is in the future and likely a data entry error, it still indicates recent past issues) suggests that the plugin has historically struggled with security.

While the current version of the code demonstrates good development practices, the past vulnerability record, especially the unpatched CVE, poses a substantial risk. Users should be aware that despite apparent good coding in v3.14, the plugin has a history of significant vulnerabilities. The lack of nonces and capabilities checks on some entry points (though the analysis shows 0 unprotected entry points, the presence of capability checks at all suggests there might be areas that could benefit from stricter access control, though the static analysis does not highlight this as a direct risk in v3.14) is less of a concern given the lack of exposed entry points, but the unpatched CVE is a critical outstanding issue.

Key Concerns

  • Unpatched CVEs
  • History of medium severity vulnerabilities
  • Vulnerabilities: CSRF and XSS
Vulnerabilities
3

Trade Runner Security Vulnerabilities

CVEs by Year

2 CVEs in 2022
2022
1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2025-67625medium · 4.3Cross-Site Request Forgery (CSRF)

Trade Runner <= 3.14 - Cross-Site Request Forgery

Nov 30, 2025Unpatched
WF-d8c0cd48-b27c-4bc1-9e5f-d918448290fb-traderunnermedium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Trade Runner <= 3.9 - Authenticated (Admin+) Stored Cross-Site Scripting

Jun 2, 2022 Patched in 3.10 (600d)
WF-5d0d44bb-a6b9-44cc-ba38-0e28ad318594-traderunnermedium · 5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Trade Runner <= 3.9 - Cross-Site Scripting

May 30, 2022 Patched in 3.10 (603d)
Code Analysis
Analyzed Mar 16, 2026

Trade Runner Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
51 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

100% escaped51 total outputs
Attack Surface

Trade Runner Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_inittraderunner.php:27
actionadmin_menutraderunner.php:235
actionplugins_loadedtraderunner.php:239
actionwp_headtraderunner.php:240
actionwp_headtraderunner.php:241
Maintenance & Trust

Trade Runner Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 24, 2025
PHP min version5.6
Downloads5K

Community Trust

Rating100/100
Number of ratings3
Active installs100
Developer Profile

Trade Runner Developer Profile

tmtraderunner

1 plugin · 100 total installs

55
trust score
Avg Security Score
66/100
Avg Patch Time
602 days
View full developer profile
Detection Fingerprints

How We Detect Trade Runner

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/traderunner/css//wp-content/plugins/traderunner/js/
Script Paths
/wp-content/plugins/traderunner/js/traderunner.js
Version Parameters
traderunner/css/traderunner.css?ver=traderunner/js/traderunner.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-traderunner-nonce
JS Globals
traderunner_data
FAQ

Frequently Asked Questions about Trade Runner