Conversion Optimization by 40Nuggets Security & Risk Analysis

wordpress.org/plugins/40nuggets

Convert anonymous visitors into subscribers and customers with 40Nuggets' intelligent screen overlays

10 active installs v0.6.8 PHP + WP 3.3+ Updated Mar 27, 2017
ab-testingactivecampaignanalyticsautomated-marketingautomatic
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Conversion Optimization by 40Nuggets Safe to Use in 2026?

Generally Safe

Score 85/100

Conversion Optimization by 40Nuggets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "40nuggets" plugin v0.6.8 exhibits a mixed security posture. On the positive side, it demonstrates good practices by not registering any AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits its attack surface. Furthermore, all observed SQL queries utilize prepared statements, and there are no known vulnerabilities (CVEs) recorded for this plugin. The plugin also includes capability checks, which is a positive security control.

However, there are notable concerns. A significant portion of the output (92%) is not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. While the taint analysis shows no critical or high severity flows, the fact that all three analyzed flows involve "unsanitized paths" is a red flag. This suggests that the plugin may be mishandling file paths, which could lead to directory traversal or other file system-related vulnerabilities if these paths are user-controlled or derived from external input.

Despite the lack of documented vulnerability history, the presence of unescaped output and unsanitized path flows presents inherent risks. The absence of nonce checks is also a weakness, particularly if any of the limited entry points were to become exposed or if future updates introduce more interactive features. Overall, while the plugin has a small attack surface and good SQL handling, the significant output escaping issues and potential for path manipulation warrant caution.

Key Concerns

  • High percentage of unescaped output
  • Taint flows with unsanitized paths
  • No nonce checks implemented
Vulnerabilities
None known

Conversion Optimization by 40Nuggets Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Conversion Optimization by 40Nuggets Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
23
2 escaped
Nonce Checks
0
Capability Checks
2
File Operations
2
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

8% escaped25 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
<login> (login.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Conversion Optimization by 40Nuggets Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_noticesfortynuggets.php:52
actionadmin_initFortynuggets_OptionsManager.php:248
actionadmin_menuFortynuggets_Plugin.php:34
actionadmin_headFortynuggets_Plugin_menus.php:14
actionwp_footerFortynuggets_ShortCodeScriptLoader.php:40
Maintenance & Trust

Conversion Optimization by 40Nuggets Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedMar 27, 2017
PHP min version
Downloads8K

Community Trust

Rating80/100
Number of ratings10
Active installs10
Developer Profile

Conversion Optimization by 40Nuggets Developer Profile

40Nuggets

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Conversion Optimization by 40Nuggets

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/40nuggets/js/track.js
Script Paths
/wp-content/plugins/40nuggets/js/track.js
Version Parameters
40nuggets/js/track.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-40nmcid
JS Globals
_40nmcid
REST Endpoints
/wp-json/40nuggets
FAQ

Frequently Asked Questions about Conversion Optimization by 40Nuggets