Sharkdropship & affiliate for AliExpress Security & Risk Analysis

wordpress.org/plugins/wooshark-aliexpress-importer

Transform your WooCommerce store into a profitable AliExpress dropshipping or affiliate business with ease!

300 active installs v3.0.1 PHP 7.4+ WP 5.0+ Updated Jan 28, 2026
affiliate-marketingaliexpressdropshippingecommerceproduct-import
99
A · Safe
CVEs total2
Unpatched0
Last CVEApr 1, 2024
Safety Verdict

Is Sharkdropship & affiliate for AliExpress Safe to Use in 2026?

Generally Safe

Score 99/100

Sharkdropship & affiliate for AliExpress has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Apr 1, 2024Updated 2mo ago
Risk Assessment

The "wooshark-aliexpress-importer" plugin v3.0.1 demonstrates a generally strong security posture with excellent adherence to secure coding practices. The static analysis reveals a remarkably low attack surface, with all identified entry points (AJAX handlers) protected by appropriate checks. The code exhibits robust practices, with a high percentage of SQL queries using prepared statements and an overwhelming majority of outputs properly escaped, indicating a good defense against common injection and XSS vulnerabilities. The absence of file operations and external HTTP requests further minimizes potential attack vectors.

However, the plugin's vulnerability history presents a significant concern. With two previously documented CVEs, including one high and one medium severity vulnerability, the pattern of "Missing Authorization" is a clear indicator of past security weaknesses that have required patching. Although there are currently no unpatched vulnerabilities, this history suggests a recurring issue with securing sensitive functionality, which warrants caution. The fact that these vulnerabilities have been fixed is positive, but the historical pattern necessitates ongoing vigilance and thorough review of any future updates.

In conclusion, while the current version of "wooshark-aliexpress-importer" is technically well-implemented with minimal exploitable code-level weaknesses found in this static analysis, its past vulnerability record, specifically related to authorization, is a notable drawback. Users should remain aware of this history and ensure they are always running the latest patched versions. The strengths lie in its well-protected entry points and strong output sanitization, but the weakness lies in the historical pattern of authorization flaws.

Key Concerns

  • High severity vulnerability in history
  • Medium severity vulnerability in history
Vulnerabilities
2

Sharkdropship & affiliate for AliExpress Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

High
1
Medium
1

2 total CVEs

CVE-2024-1732medium · 5.3Missing Authorization

Sharkdropship for AliExpress Dropshipping and Affiliate <= 2.2.4 - Missing Authorization to Unauthenticated Arbitrary Post Deletion

Apr 1, 2024 Patched in 2.2.5 (1d)
CVE-2023-30870high · 7.3Missing Authorization

Sharkdropship for AliExpress Dropship and Affiliate <= 2.2.4 - Missing Authorization

Oct 3, 2023 Patched in 2.2.5 (182d)
Code Analysis
Analyzed Mar 16, 2026

Sharkdropship & affiliate for AliExpress Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
14 prepared
Unescaped Output
2
59 escaped
Nonce Checks
4
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

88% prepared16 total queries

Output Escaping

97% escaped61 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
sharkdropship_admin_page (includes\class-admin.php:81)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Sharkdropship & affiliate for AliExpress Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 5

authwp_ajax_sharkdropship_get_productsincludes\class-admin.php:24
authwp_ajax_sharkdropship_update_viewsincludes\class-admin.php:25
authwp_ajax_sharkdropship_dismiss_noticeincludes\class-admin.php:26
authwp_ajax_sharkdropship_frontend_track_viewincludes\class-ajax.php:22
noprivwp_ajax_sharkdropship_frontend_track_viewincludes\class-ajax.php:23
WordPress Hooks 7
actioninitaliexpress-wp-plugin.php:43
actionplugins_loadedaliexpress-wp-plugin.php:44
actionadmin_noticesaliexpress-wp-plugin.php:53
actionadmin_menuincludes\class-admin.php:22
actionadmin_enqueue_scriptsincludes\class-admin.php:23
actionwp_headincludes\class-frontend.php:22
actionwp_enqueue_scriptsincludes\class-frontend.php:23
Maintenance & Trust

Sharkdropship & affiliate for AliExpress Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 28, 2026
PHP min version7.4
Downloads94K

Community Trust

Rating84/100
Number of ratings38
Active installs300
Developer Profile

Sharkdropship & affiliate for AliExpress Developer Profile

Marc dooder

3 plugins · 960 total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
94 days
View full developer profile
Detection Fingerprints

How We Detect Sharkdropship & affiliate for AliExpress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wooshark-aliexpress-importer/assets/css/admin.css/wp-content/plugins/wooshark-aliexpress-importer/assets/js/admin.js
Script Paths
/wp-content/plugins/wooshark-aliexpress-importer/assets/js/admin.js
Version Parameters
wooshark-aliexpress-importer/assets/js/admin.js?ver=wooshark-aliexpress-importer/assets/css/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
sharkdropship-admin-wrap
Data Attributes
data-ajax-urldata-nonce
JS Globals
sharkdropship_ajax
FAQ

Frequently Asked Questions about Sharkdropship & affiliate for AliExpress