ACR Kit for WooCommerce Security & Risk Analysis

wordpress.org/plugins/acr-kit

Recover lost sales with automated email sequences with email builder, one-click recovery links, and smart browser tab notifications for WooCommerce.

0 active installs v0.5.0 PHP 7.4+ WP 6.0+ Updated Jan 7, 2026
abandoned-cartcart-recoveryemail-marketingsales-recoverywoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ACR Kit for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

ACR Kit for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The acr-kit plugin version 0.5.0 exhibits a generally strong security posture based on the provided static analysis. It has a remarkably small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events, and crucially, none of these entry points are exposed without authentication checks. The code also demonstrates good practices with 100% of SQL queries using prepared statements, a good output escaping rate (91%), and the presence of nonce and capability checks. The lack of any recorded vulnerabilities, critical or otherwise, further reinforces its current security stability. However, the presence of two taint flows with unsanitized paths, although not categorized as critical or high severity, warrants attention as it indicates a potential avenue for unexpected data handling that could be exploited in conjunction with other factors.

Key Concerns

  • Taint flows with unsanitized paths
Vulnerabilities
None known

ACR Kit for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ACR Kit for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
10 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

91% escaped11 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
clickTrack (includes\Support\Email.php:32)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ACR Kit for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionadmin_menuincludes\ACRKit.php:16
filterscript_loader_tagincludes\Loader.php:50
actionadmin_enqueue_scriptsincludes\Loader.php:129
actionwp_enqueue_scriptsincludes\Loader.php:131
actionadmin_enqueue_scriptsincludes\Loader.php:137
actionwp_enqueue_scriptsincludes\Loader.php:139
actionrest_api_initincludes\Rest.php:19
actionwoocommerce_cart_updatedincludes\Support\Cart.php:24
actionwoocommerce_store_api_checkout_order_processedincludes\Support\Cart.php:25
actionwoocommerce_checkout_order_createdincludes\Support\Cart.php:26
actiontemplate_redirectincludes\Support\Cart.php:27
Maintenance & Trust

ACR Kit for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 7, 2026
PHP min version7.4
Downloads161

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

ACR Kit for WooCommerce Developer Profile

Mehedi Hasan

3 plugins · 20 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ACR Kit for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/acr-kit/assets/admin-BqI9HNTc.css/wp-content/plugins/acr-kit/assets/admin-CEtyd_du.js/wp-content/plugins/acr-kit/assets/frontend-DpW2eW7-.js
Script Paths
http://localhost:5174/@vite/clienthttp://localhost:5174/src/admin.tshttp://localhost:5174/src/frontend.ts

HTML / DOM Fingerprints

JS Globals
acrKitApp
REST Endpoints
/wp-json/acr-kit/ping/wp-json/acr-kit/connect/wp-json/acr-kit/tokens/wp-json/acr-kit/app-tokens
FAQ

Frequently Asked Questions about ACR Kit for WooCommerce