Spreadconnect Security & Risk Analysis

wordpress.org/plugins/wc-spod

Ready to add merch to your website? Spreadconnect is a Print on Demand Dropshipping plug-in for WooCommerce that’s trusted by over 100,000 creators an …

800 active installs v2.1.5 PHP 7.4+ WP + Updated May 6, 2025
dropshippingpodprintprint-on-demandwoocommerce
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEJun 27, 2025
Safety Verdict

Is Spreadconnect Safe to Use in 2026?

Mostly Safe

Score 78/100

Spreadconnect is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Jun 27, 2025Updated 11mo ago
Risk Assessment

The "wc-spod" plugin v2.1.5 exhibits a mixed security posture. While it demonstrates some good practices, such as a high percentage of SQL queries using prepared statements and the presence of nonce checks, significant concerns are present. The static analysis reveals a notable number of outputs that are not properly escaped, posing a risk of cross-site scripting (XSS) vulnerabilities. Furthermore, the taint analysis indicates flows with unsanitized paths, which could lead to security issues if not handled carefully. The plugin's vulnerability history, specifically a currently unpatched medium severity CVE, raises a red flag, especially given the pattern of past vulnerabilities. The presence of an unprotected AJAX handler significantly increases the attack surface and is a direct security risk. The lack of capability checks is also a critical oversight, allowing unauthorized users to potentially interact with sensitive functionalities. This plugin requires immediate attention to address the identified vulnerabilities and improve its overall security.

In conclusion, while "wc-spod" v2.1.5 shows some positive security attributes, the combination of unpatched vulnerabilities, unprotected entry points, and insufficient input/output sanitization presents a considerable risk. The history of vulnerabilities, particularly missing authorization, suggests a recurring weakness that needs robust remediation. Organizations using this plugin should prioritize updating to a patched version if available, or consider alternative solutions until these security gaps are addressed.

Key Concerns

  • Unpatched CVE (Medium)
  • Unprotected AJAX handler
  • Low proper output escaping
  • Flows with unsanitized paths
  • No capability checks
Vulnerabilities
1

Spreadconnect Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-53291medium · 5.4Missing Authorization

Spreadconnect <= 2.1.5 - Missing Authorization

Jun 27, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Spreadconnect Code Analysis

Dangerous Functions
0
Raw SQL Queries
7
32 prepared
Unescaped Output
41
15 escaped
Nonce Checks
1
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

SQL Query Safety

82% prepared39 total queries

Output Escaping

27% escaped56 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
serversideAjax (classes\SpodPodAdmin.php:311)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Spreadconnect Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_serversidefunctionclasses\SpodPodPlugin.php:105
WordPress Hooks 20
actionplugins_loadedclasses\SpodPodPlugin.php:84
actionadmin_enqueue_scriptsclasses\SpodPodPlugin.php:98
actionadmin_enqueue_scriptsclasses\SpodPodPlugin.php:99
filterupload_mimesclasses\SpodPodPlugin.php:100
actionadmin_initclasses\SpodPodPlugin.php:101
actionadmin_menuclasses\SpodPodPlugin.php:106
actionwoocommerce_order_status_processingclasses\SpodPodPlugin.php:107
actionwoocommerce_order_status_cancelledclasses\SpodPodPlugin.php:108
actioninitclasses\SpodPodPlugin.php:109
actionadmin_noticesclasses\SpodPodPlugin.php:110
filterwc_order_statusesclasses\SpodPodPlugin.php:111
actioninitclasses\SpodPodPlugin.php:123
actionquery_varsclasses\SpodPodPlugin.php:124
actionparse_requestclasses\SpodPodPlugin.php:125
filtercron_schedulescron.php:21
actionwpcron.php:32
actionspodpod_scheduler_image_add_deletecron.php:43
actionspodpod_logger_cleanupcron.php:52
actionbefore_woocommerce_initwc-spod.php:33
actionplugins_loadedwc-spod.php:82

Scheduled Events 2

spodpod_scheduler_image_add_delete
spodpod_logger_cleanup
Maintenance & Trust

Spreadconnect Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedMay 6, 2025
PHP min version7.4
Downloads15K

Community Trust

Rating56/100
Number of ratings9
Active installs800
Developer Profile

Spreadconnect Developer Profile

spoddev2021

1 plugin · 800 total installs

79
trust score
Avg Security Score
78/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Spreadconnect

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-spod/admin/css/spod_pod-admin.css/wp-content/plugins/wc-spod/admin/js/spod_pod-admin.js
Script Paths
/wp-content/plugins/wc-spod/admin/js/spod_pod-admin.js
Version Parameters
wc-spod/admin/css/spod_pod-admin.css?ver=wc-spod/admin/js/spod_pod-admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-ng-spod-pod-unique
JS Globals
ng_spod_pod_unique
FAQ

Frequently Asked Questions about Spreadconnect