
Conversion Optimization by 40Nuggets Security & Risk Analysis
wordpress.org/plugins/40nuggetsConvert anonymous visitors into subscribers and customers with 40Nuggets' intelligent screen overlays
Is Conversion Optimization by 40Nuggets Safe to Use in 2026?
Generally Safe
Score 85/100Conversion Optimization by 40Nuggets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "40nuggets" plugin v0.6.8 exhibits a mixed security posture. On the positive side, it demonstrates good practices by not registering any AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits its attack surface. Furthermore, all observed SQL queries utilize prepared statements, and there are no known vulnerabilities (CVEs) recorded for this plugin. The plugin also includes capability checks, which is a positive security control.
However, there are notable concerns. A significant portion of the output (92%) is not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. While the taint analysis shows no critical or high severity flows, the fact that all three analyzed flows involve "unsanitized paths" is a red flag. This suggests that the plugin may be mishandling file paths, which could lead to directory traversal or other file system-related vulnerabilities if these paths are user-controlled or derived from external input.
Despite the lack of documented vulnerability history, the presence of unescaped output and unsanitized path flows presents inherent risks. The absence of nonce checks is also a weakness, particularly if any of the limited entry points were to become exposed or if future updates introduce more interactive features. Overall, while the plugin has a small attack surface and good SQL handling, the significant output escaping issues and potential for path manipulation warrant caution.
Key Concerns
- High percentage of unescaped output
- Taint flows with unsanitized paths
- No nonce checks implemented
Conversion Optimization by 40Nuggets Security Vulnerabilities
Conversion Optimization by 40Nuggets Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Conversion Optimization by 40Nuggets Attack Surface
WordPress Hooks 5
Maintenance & Trust
Conversion Optimization by 40Nuggets Maintenance & Trust
Maintenance Signals
Community Trust
Conversion Optimization by 40Nuggets Alternatives
Advanced ActiveCampaign Site Tracking
advanced-activecampaign-site-tracking
Adds ActiveCampaign Site Tracking Code and links to users email if logged in.
Liana with GrowthStack
liana-with-growthstack
Add world class marketing automation features like personalization to your website.
Light AB Test
light-ab-testing
A simple AB Testing plugin.
Personyze WordPress Plugin
personyze-web-analytics
Personyze is an advanced Web analytics and personalization tool.
Dalton – AI Website Optimization
dalton-ai-website-optimization
Launch AI-powered website experiments 5x faster. Multi-armed bandit optimization delivers results in weeks, not months. No developers needed.
Conversion Optimization by 40Nuggets Developer Profile
1 plugin · 10 total installs
How We Detect Conversion Optimization by 40Nuggets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/40nuggets/js/track.js/wp-content/plugins/40nuggets/js/track.js40nuggets/js/track.js?ver=HTML / DOM Fingerprints
data-40nmcid_40nmcid/wp-json/40nuggets