SharkDropship & Affiliate for AliExpress, eBay, Amazon, Etsy and Temu Security & Risk Analysis

wordpress.org/plugins/woo-aliexpress-dropshipping

🚀 Multi-Supplier Dropshipping & Affiliate Plugin for WooCommerce Import products from AliExpress, eBay, Amazon, Etsy, and Temu with one click.

600 active installs v3.2.0 PHP 7.4+ WP 5.0+ Updated Jan 28, 2026
aliexpressamazonebayetsytemu
99
A · Safe
CVEs total2
Unpatched0
Last CVEApr 22, 2024
Download
Safety Verdict

Is SharkDropship & Affiliate for AliExpress, eBay, Amazon, Etsy and Temu Safe to Use in 2026?

Generally Safe

Score 99/100

SharkDropship & Affiliate for AliExpress, eBay, Amazon, Etsy and Temu has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Apr 22, 2024Updated 2mo ago
Risk Assessment

The "woo-aliexpress-dropshipping" v3.2.0 plugin exhibits a generally good security posture based on the static analysis. The absence of dangerous functions, file operations, external HTTP requests, and the consistent use of prepared statements for SQL queries are positive indicators. Furthermore, all identified output is properly escaped, and the plugin implements nonce and capability checks on its AJAX handlers, which is a crucial security practice for preventing unauthorized actions.

The plugin's vulnerability history, while showing a recent medium severity vulnerability, indicates that previously identified issues have been patched, as there are currently no unpatched CVEs. The common vulnerability type being 'Missing Authorization' in the past suggests a historical pattern that the developers appear to have addressed in recent versions, as the current static analysis shows no unprotected entry points.

However, the presence of 7 AJAX handlers, even with authentication checks, represents a notable attack surface that could be a target for brute-force or enumeration attacks if not robustly protected. While no critical or high severity issues were found in the current analysis, the historical trend of missing authorization warrants continued vigilance. Overall, the plugin demonstrates a commitment to security by addressing past vulnerabilities and implementing good coding practices, but the attack surface size remains a potential area of focus.

Key Concerns

  • 7 AJAX handlers represent a notable attack surface
  • Historical medium severity vulnerabilities found
Vulnerabilities
2

SharkDropship & Affiliate for AliExpress, eBay, Amazon, Etsy and Temu Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-32724medium · 5.3Missing Authorization

Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy <= 2.1.1 - Unauthenticated Arbitrary Content Deletion

Apr 22, 2024 Patched in 2.1.2 (8d)
CVE-2023-49848medium · 5.3Missing Authorization

Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy <= 2.1.1 - Missing Authorization

Dec 6, 2023 Patched in 2.1.2 (183d)
Code Analysis
Analyzed Mar 16, 2026

SharkDropship & Affiliate for AliExpress, eBay, Amazon, Etsy and Temu Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
79 escaped
Nonce Checks
7
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped79 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
multisupplier_admin_page (includes\class-multisupplier-admin.php:95)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

SharkDropship & Affiliate for AliExpress, eBay, Amazon, Etsy and Temu Attack Surface

Entry Points7
Unprotected0

AJAX Handlers 7

authwp_ajax_multisupplier_get_productsincludes\class-multisupplier-admin.php:24
authwp_ajax_multisupplier_update_viewsincludes\class-multisupplier-admin.php:25
authwp_ajax_multisupplier_dismiss_noticeincludes\class-multisupplier-admin.php:26
authwp_ajax_multisupplier_get_advanced_metricsincludes\class-multisupplier-admin.php:27
authwp_ajax_multisupplier_frontend_track_viewincludes\class-multisupplier-ajax.php:22
noprivwp_ajax_multisupplier_frontend_track_viewincludes\class-multisupplier-ajax.php:23
authwp_ajax_multisupplier_delete_productincludes\class-multisupplier-ajax.php:24
WordPress Hooks 8
actionadmin_menuincludes\class-multisupplier-admin.php:22
actionadmin_enqueue_scriptsincludes\class-multisupplier-admin.php:23
actionpost_submitbox_misc_actionsincludes\class-multisupplier-admin.php:30
actionadmin_headincludes\class-multisupplier-admin.php:31
actionwp_headincludes\class-multisupplier-frontend.php:22
actionwp_enqueue_scriptsincludes\class-multisupplier-frontend.php:23
actioninitsharkdropship-multisupplier.php:40
actionadmin_noticessharkdropship-multisupplier.php:49
Maintenance & Trust

SharkDropship & Affiliate for AliExpress, eBay, Amazon, Etsy and Temu Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJan 28, 2026
PHP min version7.4
Downloads67K

Community Trust

Rating74/100
Number of ratings31
Active installs600
Developer Profile

SharkDropship & Affiliate for AliExpress, eBay, Amazon, Etsy and Temu Developer Profile

Marc dooder

3 plugins · 960 total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
94 days
View full developer profile
Detection Fingerprints

How We Detect SharkDropship & Affiliate for AliExpress, eBay, Amazon, Etsy and Temu

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-aliexpress-dropshipping/assets/css/multisupplier-admin.css/wp-content/plugins/woo-aliexpress-dropshipping/assets/js/multisupplier-admin.js
Version Parameters
woo-aliexpress-dropshipping/assets/css/multisupplier-admin.css?ver=woo-aliexpress-dropshipping/assets/js/multisupplier-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
toplevel_page_sharkdropship-multisupplier
HTML Comments
<!-- Prevent direct access -->
Data Attributes
data-hook
JS Globals
multisupplier_ajax
REST Endpoints
/wp-json/multisupplier/v1/settings/wp-json/multisupplier/v1/products/wp-json/multisupplier/v1/categories/wp-json/multisupplier/v1/settings
FAQ

Frequently Asked Questions about SharkDropship & Affiliate for AliExpress, eBay, Amazon, Etsy and Temu