
Ultimate Products Feed : Woocommerce to Google Shopping Security & Risk Analysis
wordpress.org/plugins/ultimate-products-feedAdd your products feed to Google Shopping and attract more customers. this plugin is the best way to boost your sales very quickly.
Is Ultimate Products Feed : Woocommerce to Google Shopping Safe to Use in 2026?
Generally Safe
Score 85/100Ultimate Products Feed : Woocommerce to Google Shopping has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the "ultimate-products-feed" plugin v2.11 appears to have a mix of positive indicators and significant concerns based on the provided static analysis. On the positive side, the plugin reports zero known CVEs, has no dangerous functions, performs all SQL queries using prepared statements, and has no file operations or external HTTP requests. This suggests a focus on core WordPress security best practices in these areas. However, a major concern lies with the output escaping, where only 20% of the 93 outputs are properly escaped. This indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, as unescaped user-supplied data displayed on the frontend or backend could be manipulated. Additionally, the taint analysis revealed two flows with unsanitized paths, which, while not classified as critical or high severity in this report, warrant careful investigation as they can be precursors to more severe vulnerabilities if data is not handled properly throughout its lifecycle. The absence of AJAX handlers, REST API routes, shortcodes, cron events, and nonce/capability checks contributes to a seemingly small attack surface, but this is overshadowed by the potential for XSS due to poor output sanitization.
Key Concerns
- Poor output escaping (20% properly escaped)
- Taint flows with unsanitized paths (2 flows)
Ultimate Products Feed : Woocommerce to Google Shopping Security Vulnerabilities
Ultimate Products Feed : Woocommerce to Google Shopping Release Timeline
Ultimate Products Feed : Woocommerce to Google Shopping Code Analysis
Output Escaping
Data Flow Analysis
Ultimate Products Feed : Woocommerce to Google Shopping Attack Surface
WordPress Hooks 23
Maintenance & Trust
Ultimate Products Feed : Woocommerce to Google Shopping Maintenance & Trust
Maintenance Signals
Community Trust
Ultimate Products Feed : Woocommerce to Google Shopping Alternatives
WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping
wp-product-feed-manager
The WooCommerce product feed plugin built for Google. Create a Google Merchant feed in 5 minutes—no coding, no errors. Start selling on Google Shoppin …
WebToffee WooCommerce Product Feeds – Google Shopping, Pinterest, TikTok Ads, & More
webtoffee-product-feed
Create WooCommerce product feeds containing unlimited number of products. Supports Google Product feed, Facebook catalog feed, Instagram, Bing & m …
ELEX WooCommerce Google Shopping (Google Product Feed)
elex-woocommerce-google-product-feed-plugin-basic
The ELEX WooCommerce Google Shopping (Google Product Feed) plugin is a free WooCommerce plugin that serves in feeding your WooCommerce products to Goo …
TFM Google Product Feed
tfm-google-product-feed
The ThemesFor.me Google Product Feed allows to expose all your products from WooCommerce and provide them in the Google Merchants Console.
Products Feed Generator
products-feed-generator
Generates an XML Products Feed for Google Merchant Center in RSS 2.0 format.
Ultimate Products Feed : Woocommerce to Google Shopping Developer Profile
2 plugins · 30 total installs
How We Detect Ultimate Products Feed : Woocommerce to Google Shopping
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ultimate-products-feed/inc/css/admin.css/wp-content/plugins/ultimate-products-feed/inc/css/tabs.scss/wp-content/plugins/ultimate-products-feed/inc/js/tabs.js/wp-content/plugins/ultimate-products-feed/inc/js/populate.js/wp-content/plugins/ultimate-products-feed/inc/js/tabs.js/wp-content/plugins/ultimate-products-feed/inc/js/populate.jsHTML / DOM Fingerprints
custom_field_demoNotes: Met à jour$_REQUEST['_gtin'] -> the custom field we added aboveOnly save custom fields on quick edit option on appropriate product types (simple, etc..)Custom fields are just post metaname="_gtin"class="text"