Ultimate Products Feed : Woocommerce to Google Shopping Security & Risk Analysis

wordpress.org/plugins/ultimate-products-feed

Add your products feed to Google Shopping and attract more customers. this plugin is the best way to boost your sales very quickly.

20 active installs v2.11 PHP 5.6+ WP 4.5+ Updated Feb 8, 2019
google-adwordsgoogle-merchantgoogle-shoppingproducts-feedwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ultimate Products Feed : Woocommerce to Google Shopping Safe to Use in 2026?

Generally Safe

Score 85/100

Ultimate Products Feed : Woocommerce to Google Shopping has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The security posture of the "ultimate-products-feed" plugin v2.11 appears to have a mix of positive indicators and significant concerns based on the provided static analysis. On the positive side, the plugin reports zero known CVEs, has no dangerous functions, performs all SQL queries using prepared statements, and has no file operations or external HTTP requests. This suggests a focus on core WordPress security best practices in these areas. However, a major concern lies with the output escaping, where only 20% of the 93 outputs are properly escaped. This indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, as unescaped user-supplied data displayed on the frontend or backend could be manipulated. Additionally, the taint analysis revealed two flows with unsanitized paths, which, while not classified as critical or high severity in this report, warrant careful investigation as they can be precursors to more severe vulnerabilities if data is not handled properly throughout its lifecycle. The absence of AJAX handlers, REST API routes, shortcodes, cron events, and nonce/capability checks contributes to a seemingly small attack surface, but this is overshadowed by the potential for XSS due to poor output sanitization.

Key Concerns

  • Poor output escaping (20% properly escaped)
  • Taint flows with unsanitized paths (2 flows)
Vulnerabilities
None known

Ultimate Products Feed : Woocommerce to Google Shopping Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Ultimate Products Feed : Woocommerce to Google Shopping Release Timeline

v2.00
Code Analysis
Analyzed Apr 16, 2026

Ultimate Products Feed : Woocommerce to Google Shopping Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
74
19 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

20% escaped93 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
category_form_custom_field_save (inc/google-shopping/google-category-field.php:59)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Ultimate Products Feed : Woocommerce to Google Shopping Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 23
filtercmb_meta_boxesinc/google-shopping/google-category-field.php:113
actioninitinc/google-shopping/google-shopping-feed.php:19
actionadmin_menuindex.php:62
actionadmin_enqueue_scriptsindex.php:79
filtermanage_product_posts_columnsindex.php:96
actionmanage_posts_custom_columnindex.php:100
filtermanage_edit-product_sortable_columnsindex.php:124
actionwoocommerce_product_quick_edit_endindex.php:129
actionwoocommerce_product_quick_edit_saveindex.php:143
actionadmin_enqueue_scriptsindex.php:167
actionpre_get_postsindex.php:197
filterwoocommerce_structured_data_product_offerindex.php:267
filterwoocommerce_structured_data_productindex.php:301
actionplugins_loadedindex.php:310
actionadmin_initindex.php:341
actionadmin_initindex.php:350
actionadmin_noticesindex.php:431
actioninitindex.php:538
actionwp_headindex.php:550
actionwoocommerce_product_options_general_product_dataindex.php:705
actionwoocommerce_process_product_metaindex.php:764
actionwoocommerce_product_after_variable_attributesindex.php:771
actionwoocommerce_save_product_variationindex.php:794
Maintenance & Trust

Ultimate Products Feed : Woocommerce to Google Shopping Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedFeb 8, 2019
PHP min version5.6
Downloads3K

Community Trust

Rating60/100
Number of ratings3
Active installs20
Developer Profile

Ultimate Products Feed : Woocommerce to Google Shopping Developer Profile

fredericgalline

2 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ultimate Products Feed : Woocommerce to Google Shopping

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ultimate-products-feed/inc/css/admin.css/wp-content/plugins/ultimate-products-feed/inc/css/tabs.scss/wp-content/plugins/ultimate-products-feed/inc/js/tabs.js/wp-content/plugins/ultimate-products-feed/inc/js/populate.js
Script Paths
/wp-content/plugins/ultimate-products-feed/inc/js/tabs.js/wp-content/plugins/ultimate-products-feed/inc/js/populate.js

HTML / DOM Fingerprints

CSS Classes
custom_field_demo
HTML Comments
Notes: Met à jour$_REQUEST['_gtin'] -> the custom field we added aboveOnly save custom fields on quick edit option on appropriate product types (simple, etc..)Custom fields are just post meta
Data Attributes
name="_gtin"class="text"
FAQ

Frequently Asked Questions about Ultimate Products Feed : Woocommerce to Google Shopping