
abtestkit – AB testing for WooCommerce Security & Risk Analysis
wordpress.org/plugins/abtestkitSplit testing for WooCommerce, compatible with all themes, page builders & caching plugins.
Is abtestkit – AB testing for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100abtestkit – AB testing for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "abtestkit" plugin v1.2.1 exhibits a generally strong security posture with good practices in place. The static analysis reveals a low number of potential entry points, and a high percentage of SQL queries utilize prepared statements and outputs are properly escaped. The plugin also demonstrates a commitment to security with a significant number of capability checks and nonce checks, indicating an effort to restrict access to sensitive actions. Its vulnerability history is completely clean, with no recorded CVEs, which is a positive indicator of its historical security development.
However, there are a couple of areas that warrant attention. The presence of 2 REST API routes without permission callbacks represents a potential attack surface that could be exploited if sensitive data or functionality is exposed. While the taint analysis found no critical or high-severity unsanitized paths, the mere existence of unprotected API endpoints is a concern. The single file operation and external HTTP request, while not flagged as immediately dangerous, are always points to monitor for potential vulnerabilities, especially if they handle user-supplied input without rigorous sanitization.
In conclusion, "abtestkit" v1.2.1 is a reasonably secure plugin, primarily due to its clean vulnerability history and good implementation of core security practices like prepared statements and output escaping. The main weakness lies in the unprotected REST API endpoints, which, although not currently associated with known vulnerabilities or taint issues, represent a latent risk. Further investigation into the functionality of these specific API routes and the implementation of permission checks would be beneficial to solidify its security.
Key Concerns
- REST API routes without permission callbacks
abtestkit – AB testing for WooCommerce Security Vulnerabilities
abtestkit – AB testing for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
abtestkit – AB testing for WooCommerce Attack Surface
REST API Routes 9
WordPress Hooks 86
Maintenance & Trust
abtestkit – AB testing for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
abtestkit – AB testing for WooCommerce Alternatives
Unbounce Landing Pages
unbounce
Unbounce is the most powerful standalone landing page builder available.
Personizely — A/B Testing, Personalization, Popups & CRO
personizely
Personizely is a Conversion Optimization Toolkit that helps you boost engagement and sales through A/B testing, website personalization, and popups.
Sigmize: A/B Testing, Session Recordings, Heatmaps & Revenue Tracking for WooCommerce, SureCart & EDD
sigmize
Powerful A/B testing for WordPress with heatmaps, session replays, and e-commerce tracking for WooCommerce, SureCart, and EDD.
PageTest.ai – AI-Powered A/B and Multivariate Testing for WordPress
pagetest-ai
Run AI-powered A/B and multivariate tests on your WordPress site—no coding needed. Optimize conversions by finding your best content.
A/B See
ab-see
WordPress A/B testing in two shortcodes.
abtestkit – AB testing for WooCommerce Developer Profile
1 plugin · 10 total installs
How We Detect abtestkit – AB testing for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/abtestkit/dist/index.js/wp-content/plugins/abtestkit/dist/style.css/wp-content/plugins/abtestkit/dist/index.jsabtestkit/dist/index.js?ver=abtestkit/dist/style.css?ver=HTML / DOM Fingerprints
<!-- AB Test Kit --><!-- AB Test Kit Settings -->data-abtestkit-triggerdata-abtestkit-campaigndata-abtestkit-variantabTestKitabTestKitAsyncInit/wp-json/abtestkit/v1/campaigns/wp-json/abtestkit/v1/track[abtestkit_campaign][abtestkit_variant]