Add Tiktok Pixel for Tiktok ads (+Woocommerce) Security & Risk Analysis

wordpress.org/plugins/add-tiktok-advertising-pixel

Add Tiktok Pixel allows you to install Tiktok pixel properly on your website to track conversion & maximize ROI by ensuring your most important au …

2K active installs v1.2.8 PHP 5.6+ WP 4.1+ Updated Jan 16, 2026
conversionpixelretargetingtiktoktiktok-pixel
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Add Tiktok Pixel for Tiktok ads (+Woocommerce) Safe to Use in 2026?

Generally Safe

Score 100/100

Add Tiktok Pixel for Tiktok ads (+Woocommerce) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "add-tiktok-advertising-pixel" plugin v1.2.8 demonstrates a generally good security posture, with no critical or high-severity issues identified in the static analysis or vulnerability history. The absence of direct SQL queries, file operations, and external HTTP requests is a positive sign. Nonce and capability checks are present, indicating an attempt to secure entry points, although the total attack surface is zero, which is unusual for a functional plugin and might indicate limitations in the analysis or the plugin's functionality.

However, a significant concern lies in the output escaping. With 128 total outputs and only 40% properly escaped, there's a considerable risk of Cross-Site Scripting (XSS) vulnerabilities. This means user-supplied or dynamically generated data might be rendered directly in the browser without sufficient sanitization, allowing attackers to inject malicious scripts. The vulnerability history is clean, which is encouraging, but the lack of past vulnerabilities should not be seen as a guarantee of future safety, especially given the identified output escaping issues.

In conclusion, while the plugin avoids common pitfalls like raw SQL and insecure file operations, the poor output escaping is a notable weakness that requires immediate attention. The clean vulnerability history is a strength, but the identified code signal deficiency suggests a potential for exploitable issues if user input is not handled with extreme care when displayed. Addressing the output escaping is crucial to mitigate XSS risks.

Key Concerns

  • Low output escaping rate
Vulnerabilities
None known

Add Tiktok Pixel for Tiktok ads (+Woocommerce) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Add Tiktok Pixel for Tiktok ads (+Woocommerce) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
77
51 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

40% escaped128 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
page (admin\controllers\SettingsController.php:20)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Add Tiktok Pixel for Tiktok ads (+Woocommerce) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionwp_headadmin\controllers\TrackingController.php:8
actionadmin_menuadmin\Settings.php:11
actionadd_meta_boxesadmin\Settings.php:13
actionsave_postadmin\Settings.php:15
actionadmin_enqueue_scriptsadmin\Settings.php:20
filterconnect_urltiktok-advertising-pixel.php:71
filterafter_skip_urltiktok-advertising-pixel.php:72
filterafter_connect_urltiktok-advertising-pixel.php:73
filterafter_pending_connect_urltiktok-advertising-pixel.php:74
filterplugin_icontiktok-advertising-pixel.php:79
filterconnect_messagetiktok-advertising-pixel.php:94
actioninittiktok-advertising-pixel.php:104
Maintenance & Trust

Add Tiktok Pixel for Tiktok ads (+Woocommerce) Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 16, 2026
PHP min version5.6
Downloads41K

Community Trust

Rating60/100
Number of ratings11
Active installs2K
Developer Profile

Add Tiktok Pixel for Tiktok ads (+Woocommerce) Developer Profile

Pagup

17 plugins · 33K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
439 days
View full developer profile
Detection Fingerprints

How We Detect Add Tiktok Pixel for Tiktok ads (+Woocommerce)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/add-tiktok-advertising-pixel/admin/assets/icon.jpg

HTML / DOM Fingerprints

JS Globals
ttap__fs
FAQ

Frequently Asked Questions about Add Tiktok Pixel for Tiktok ads (+Woocommerce)