Adsmurai One Tag Security & Risk Analysis

wordpress.org/plugins/adsmurai-one-tag

OneTag is a no-code WordPress and Woocommerce plugin that automates conversion tracking across ad platforms using Conversion APIs—no coding required.

10 active installs v1.0.9 PHP 7.0+ WP 6.4+ Updated Unknown
conversion-apiconversion-trackingpixelproduct-feedwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Adsmurai One Tag Safe to Use in 2026?

Generally Safe

Score 100/100

Adsmurai One Tag has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The adsmurai-one-tag v1.0.9 plugin exhibits a strong security posture based on the provided static analysis. There are no identified vulnerabilities in its vulnerability history, and the static analysis reveals no dangerous functions, unsanitized taint flows, raw SQL queries, or unprotected entry points. The plugin demonstrates good practices with 100% of SQL queries using prepared statements and 100% of outputs being properly escaped. Furthermore, capability checks are in place for some operations, indicating an awareness of WordPress security principles.

Despite these positive indicators, a few areas warrant attention. The absence of nonce checks on any entry points is a significant concern, as this leaves the plugin susceptible to Cross-Site Request Forgery (CSRF) attacks. While the attack surface appears minimal (0 entry points), any unauthenticated or improperly authenticated AJAX requests could be exploited if the underlying functionality is sensitive. The presence of file operations and external HTTP requests, while not inherently insecure, are points where vulnerabilities could be introduced if not handled with extreme care and proper sanitization, though no specific issues were flagged in the taint analysis.

In conclusion, the plugin is well-developed from a code perspective with no known vulnerabilities or immediate critical security flaws. However, the lack of nonce checks on potentially any new or existing entry points is a notable weakness that could lead to significant security risks if not addressed. The plugin's history of zero vulnerabilities is a positive trend, suggesting diligent development, but it's crucial to maintain this by implementing robust security measures like nonce validation for all applicable actions.

Key Concerns

  • Missing nonce checks on entry points
Vulnerabilities
None known

Adsmurai One Tag Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Adsmurai One Tag Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
15 escaped
Nonce Checks
0
Capability Checks
3
File Operations
2
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped15 total outputs
Attack Surface

Adsmurai One Tag Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actioninitincludes\Admin\Setup.php:17
actionadmin_menuincludes\Admin\Setup.php:18
actionadmin_enqueue_scriptsincludes\Admin\Setup.php:19
actionfluentform/submission_insertedincludes\Integrations\FluentForms.php:24
actionforminator_form_after_save_entryincludes\Integrations\Forminator.php:24
actionninja_forms_after_submissionincludes\Integrations\NinjaForms.php:24
actiontemplate_redirectincludes\Integrations\PageView.php:22
actionwpcf7_submitincludes\Integrations\WPCF7.php:23
actionwpforms_process_completeincludes\Integrations\WPForms.php:24
filterquery_varsone-tag.php:52
actionwp_enqueue_scriptsone-tag.php:97
actionplugins_loadedone-tag.php:333
actionrest_api_initone-tag.php:334
Maintenance & Trust

Adsmurai One Tag Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.0
Downloads752

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Adsmurai One Tag Developer Profile

Adsmurai

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Adsmurai One Tag

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/adsmurai-one-tag/public/js/product.js
Script Paths
/wp-content/plugins/adsmurai-one-tag/public/js/product.js

HTML / DOM Fingerprints

Data Attributes
data-event_iddata-event_namedata-_pixelsdata-valuedata-currencydata-order_id+2 more
JS Globals
onetagDetails
REST Endpoints
/wp-json/one-tag/v1/forms/wp-json/one-tag/v1/feed/wp-json/one-tag/v1/settings
FAQ

Frequently Asked Questions about Adsmurai One Tag