Skroutz & Bestprice XML feed for WooCommerce Security & Risk Analysis

wordpress.org/plugins/woo-xml-feed-for-skroutzgr-bestpricegr

Create Skroutz and Bestprice XML feeds for Woocommerce

1K active installs v1.6.9.1 PHP + WP 4.7+ Updated Sep 23, 2025
e-commerceecommercefeedwordpress-ecommercexml
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Skroutz & Bestprice XML feed for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Skroutz & Bestprice XML feed for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The "woo-xml-feed-for-skroutzgr-bestpricegr" v1.6.9.1 plugin exhibits a mixed security posture. On one hand, it demonstrates good practices by exclusively using prepared statements for SQL queries and having no file operations or external HTTP requests, which are common vectors for compromise. The absence of known CVEs also suggests a relatively stable security history.

However, there are significant concerns arising from the static analysis. The presence of the `unserialize` function twice is a critical risk, as unserialization of untrusted data can lead to Remote Code Execution (RCE) or other severe vulnerabilities. Furthermore, only 35% of output escaping is properly done, indicating a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of any capability checks or nonce checks on potential entry points, though the attack surface appears limited in the static analysis, means any unauthenticated or improperly authenticated access could exploit these weaknesses.

While the plugin has no recorded vulnerabilities, this doesn't negate the inherent risks identified in the code. The presence of dangerous functions like `unserialize` and insufficient output escaping are serious issues that require immediate attention. The overall conclusion is that while the plugin avoids certain common pitfalls, the identified code-level risks, particularly `unserialize` and unescaped output, represent a significant security concern that outweighs the lack of historical vulnerabilities.

Key Concerns

  • Dangerous function 'unserialize' used
  • Insufficient output escaping (only 35% proper)
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Skroutz & Bestprice XML feed for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Skroutz & Bestprice XML feed for WooCommerce Code Analysis

Dangerous Functions
2
Raw SQL Queries
0
0 prepared
Unescaped Output
55
29 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$_product_attributes = unserialize($_product_attributes_ser_ds);wooshop-skroutzxml.php:577
unserialize$_product_attributes = unserialize($_product_attributes_ser_ds);wooshop-skroutzxml.php:1164

Output Escaping

35% escaped84 total outputs
Attack Surface

Skroutz & Bestprice XML feed for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_menuwooshop-skroutzxml.php:38
actionadmin_initwooshop-skroutzxml.php:39
actionadmin_enqueue_scriptswooshop-skroutzxml.php:50
actionadmin_headwooshop-skroutzxml.php:76
actionwpwooshop-skroutzxml.php:80
actionskroutz_xml_hourly_eventwooshop-skroutzxml.php:492

Scheduled Events 2

skroutz_xml_hourly_event
skroutz_xml_hourly_event
Maintenance & Trust

Skroutz & Bestprice XML feed for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedSep 23, 2025
PHP min version
Downloads30K

Community Trust

Rating78/100
Number of ratings11
Active installs1K
Developer Profile

Skroutz & Bestprice XML feed for WooCommerce Developer Profile

Papaki (Enartia S.A.)

6 plugins · 12K total installs

83
trust score
Avg Security Score
93/100
Avg Patch Time
87 days
View full developer profile
Detection Fingerprints

How We Detect Skroutz & Bestprice XML feed for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-xml-feed-for-skroutzgr-bestpricegr/images/xml-icon.png/wp-content/plugins/woo-xml-feed-for-skroutzgr-bestpricegr/images/skroutz.png/wp-content/plugins/woo-xml-feed-for-skroutzgr-bestpricegr/images/bp.png/wp-content/plugins/woo-xml-feed-for-skroutzgr-bestpricegr/images/skroutz_bestprice.png

HTML / DOM Fingerprints

CSS Classes
skroutz_bestprice
Data Attributes
instockavailabilityifoutofstockinclude_taxgroup_variationscustom_productIdcustom_mpn
JS Globals
select2
FAQ

Frequently Asked Questions about Skroutz & Bestprice XML feed for WooCommerce