Zonify – Amazon Product Importer for WooCommerce Security & Risk Analysis

wordpress.org/plugins/zonify

Import Amazon products into WooCommerce and optionally redirect customers to Amazon using affiliate links.

100 active installs v1.0.4 PHP 7.4+ WP 5.0+ Updated Feb 1, 2026
affiliate-linksamazondropshippingproduct-importerwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Zonify – Amazon Product Importer for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Zonify – Amazon Product Importer for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "zonify" plugin v1.0.4 demonstrates a mixed security posture. On the positive side, the code shows good practices regarding SQL queries, exclusively using prepared statements, and all identified output operations are properly escaped, mitigating common injection and cross-site scripting risks. The absence of known historical vulnerabilities, critical taint flows, dangerous function usage, and file operations is also a strong indicator of a relatively secure codebase. However, a significant concern arises from its attack surface, which consists of two AJAX handlers, both lacking any form of authentication checks. This leaves these entry points open to unauthenticated access, which can be a gateway for attackers to exploit any logic flaws within these handlers. The plugin also lacks nonce checks for its AJAX endpoints, further increasing the risk of CSRF attacks. While the plugin has no recorded vulnerabilities, the presence of unprotected AJAX handlers represents a substantial security gap that needs immediate attention.

Key Concerns

  • AJAX handlers without auth checks
  • AJAX handlers without nonce checks
Vulnerabilities
None known

Zonify – Amazon Product Importer for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Zonify – Amazon Product Importer for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
6 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped6 total outputs
Attack Surface
2 unprotected

Zonify – Amazon Product Importer for WooCommerce Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

noprivwp_ajax_zonify_installationzonify.php:37
authwp_ajax_zonify_installationzonify.php:38
WordPress Hooks 3
actionadmin_enqueue_scriptszonify.php:34
actionadmin_menuzonify.php:35
actionwp_headzonify.php:36
Maintenance & Trust

Zonify – Amazon Product Importer for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 1, 2026
PHP min version7.4
Downloads7K

Community Trust

Rating50/100
Number of ratings2
Active installs100
Developer Profile

Zonify – Amazon Product Importer for WooCommerce Developer Profile

importify

4 plugins · 2K total installs

88
trust score
Avg Security Score
100/100
Avg Patch Time
55 days
View full developer profile
Detection Fingerprints

How We Detect Zonify – Amazon Product Importer for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zonify/assets/css/style.css/wp-content/plugins/zonify/assets/js/script.js
Script Paths
https://app.zonifyapp.com/dashboard/js/affiliate-woo.js
Version Parameters
zonify/assets/css/style.css?ver=zonify/assets/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
zonify_icon
Data Attributes
id="devzonifyScript"id="zonifyScript"
JS Globals
window.Zonify
FAQ

Frequently Asked Questions about Zonify – Amazon Product Importer for WooCommerce