
Spreadconnect Security & Risk Analysis
wordpress.org/plugins/wc-spodReady to add merch to your website? Spreadconnect is a Print on Demand Dropshipping plug-in for WooCommerce that’s trusted by over 100,000 creators an …
Is Spreadconnect Safe to Use in 2026?
Mostly Safe
Score 78/100Spreadconnect is generally safe to use. 1 past CVE were resolved. Keep it updated.
The "wc-spod" plugin v2.1.5 exhibits a mixed security posture. While it demonstrates some good practices, such as a high percentage of SQL queries using prepared statements and the presence of nonce checks, significant concerns are present. The static analysis reveals a notable number of outputs that are not properly escaped, posing a risk of cross-site scripting (XSS) vulnerabilities. Furthermore, the taint analysis indicates flows with unsanitized paths, which could lead to security issues if not handled carefully. The plugin's vulnerability history, specifically a currently unpatched medium severity CVE, raises a red flag, especially given the pattern of past vulnerabilities. The presence of an unprotected AJAX handler significantly increases the attack surface and is a direct security risk. The lack of capability checks is also a critical oversight, allowing unauthorized users to potentially interact with sensitive functionalities. This plugin requires immediate attention to address the identified vulnerabilities and improve its overall security.
In conclusion, while "wc-spod" v2.1.5 shows some positive security attributes, the combination of unpatched vulnerabilities, unprotected entry points, and insufficient input/output sanitization presents a considerable risk. The history of vulnerabilities, particularly missing authorization, suggests a recurring weakness that needs robust remediation. Organizations using this plugin should prioritize updating to a patched version if available, or consider alternative solutions until these security gaps are addressed.
Key Concerns
- Unpatched CVE (Medium)
- Unprotected AJAX handler
- Low proper output escaping
- Flows with unsanitized paths
- No capability checks
Spreadconnect Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Spreadconnect <= 2.1.5 - Missing Authorization
Spreadconnect Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Spreadconnect Attack Surface
AJAX Handlers 1
WordPress Hooks 20
Scheduled Events 2
Maintenance & Trust
Spreadconnect Maintenance & Trust
Maintenance Signals
Community Trust
Spreadconnect Alternatives
Printseek: Print on Demand
printseek
Connect your WooCommerce store with PrintSeek for seamless print-on-demand fulfillment. Auto-sync orders, push products, and track shipments.
EPROLO-Dropshipping
eprolo-dropshipping
EPROLO dropshipping allows to import products from Aliexpress or EPROLO to wordpress, woocommerce in one click.
Selfnamed: Cosmetics on demand
selfnamed-cosmetics-on-demand
Create and sell organic & vegan skincare products trough print-on-demand dropshipping.
Hoplix Integration for WooCommerce
hoplix-print-on-demand-platform
Grow your store with the top print-on-demand dropshipping plugin
Popcustoms – Print on demand & dropshipping, Free Personalizer
popcustoms-integration-for-woocommerce
Print on demand products & embroidery provider, fulfillment & global dropshipping, customize shoes, T-shirt, hats, hoodie, jacket, blanket and more.
Spreadconnect Developer Profile
1 plugin · 800 total installs
How We Detect Spreadconnect
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-spod/admin/css/spod_pod-admin.css/wp-content/plugins/wc-spod/admin/js/spod_pod-admin.js/wp-content/plugins/wc-spod/admin/js/spod_pod-admin.jswc-spod/admin/css/spod_pod-admin.css?ver=wc-spod/admin/js/spod_pod-admin.js?ver=HTML / DOM Fingerprints
data-ng-spod-pod-uniqueng_spod_pod_unique