AFS Analytics for WooCommerce Security & Risk Analysis

wordpress.org/plugins/afs-analytics-for-woocommerce

Advanced eCommerce Analytics solution. Grow your online business by measuring user satisfaction and site efficiency.

20 active installs v2.20 PHP 5.3+ WP 3.5.0+ Updated Jun 5, 2025
afsanalyticsanalyticsheatmapsreal-time-analyticswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AFS Analytics for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

AFS Analytics for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The 'afs-analytics-for-woocommerce' plugin, version 2.20, exhibits a mixed security posture. On the positive side, it has no recorded vulnerabilities (CVEs) and a good proportion of its SQL queries are prepared. The code also demonstrates some use of nonces and capability checks, indicating an awareness of security best practices. However, a significant concern arises from its attack surface, which includes one AJAX handler that lacks authentication checks. This unprotected entry point presents a clear avenue for potential abuse.

The static analysis also reveals areas for improvement. While no critical or high severity taint flows were identified, 3 out of 4 analyzed flows have unsanitized paths, suggesting a risk of data injection or manipulation if these paths are exploited. Additionally, only 66% of output is properly escaped, meaning there's a chance of cross-site scripting (XSS) vulnerabilities. The presence of file operations and external HTTP requests, while not inherently insecure, warrants careful review to ensure they are implemented securely.

Given the absence of historical vulnerabilities, the plugin might not have been extensively targeted or may have been developed with reasonable security in mind. Nevertheless, the identified unprotected AJAX handler and the unsanitized paths in taint flows are critical weaknesses that could be exploited. The overall assessment is that the plugin has a decent foundation with no known historical issues, but it requires immediate attention to secure its unprotected entry points and address potential data sanitization and output escaping deficiencies to prevent future vulnerabilities.

Key Concerns

  • Unprotected AJAX handler
  • Flows with unsanitized paths (3/4)
  • Output escaping (66% proper)
  • SQL queries with low prepared statement usage (29%)
Vulnerabilities
None known

AFS Analytics for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AFS Analytics for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
2 prepared
Unescaped Output
17
33 escaped
Nonce Checks
3
Capability Checks
1
File Operations
1
External Requests
2
Bundled Libraries
0

SQL Query Safety

29% prepared7 total queries

Output Escaping

66% escaped50 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

4 flows3 with unsanitized paths
render_tabs (includes\controllers\settings\class-afsa-setting-page.php:102)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

AFS Analytics for WooCommerce Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_afsa_stats_serverafs-analytics-woocommerce.php:60
WordPress Hooks 15
actionplugins_loadedafs-analytics-woocommerce.php:49
actionadmin_initafs-analytics-woocommerce.php:51
actionadmin_menuafs-analytics-woocommerce.php:52
actionadmin_enqueue_scriptsafs-analytics-woocommerce.php:53
actionwp_enqueue_scriptsafs-analytics-woocommerce.php:55
actionwp_headafs-analytics-woocommerce.php:56
actionwp_footerafs-analytics-woocommerce.php:57
actionedit_form_after_titleincludes\class-afsa-admin.php:16
actionsave_postincludes\class-afsa-admin.php:17
actionadmin_headincludes\class-afsa-admin.php:19
actionadmin_footerincludes\class-afsa-admin.php:20
actionwp_admin_enqueue_scriptsincludes\class-afsa-admin.php:22
actionwp_dashboard_setupincludes\class-afsa-admin.php:24
actionwp_dashboard_setupincludes\class-afsa-admin.php:118
filterupdate_footerincludes\controllers\renderer\class-afsa-renderer.php:12
Maintenance & Trust

AFS Analytics for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 5, 2025
PHP min version5.3
Downloads3K

Community Trust

Rating80/100
Number of ratings3
Active installs20
Developer Profile

AFS Analytics for WooCommerce Developer Profile

AFS Analytics

2 plugins · 620 total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
228 days
View full developer profile
Detection Fingerprints

How We Detect AFS Analytics for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/afs-analytics-for-woocommerce/css/welcome.css/wp-content/plugins/afs-analytics-for-woocommerce/css/settings.css/wp-content/plugins/afs-analytics-for-woocommerce/js/intro.js/wp-content/plugins/afs-analytics-for-woocommerce/js/dashboard.js/wp-content/plugins/afs-analytics-for-woocommerce/js/admin.js/wp-content/plugins/afs-analytics-for-woocommerce/js/tracker.js/wp-content/plugins/afs-analytics-for-woocommerce/js/script.js
Script Paths
/wp-content/plugins/afs-analytics-for-woocommerce/js/admin.js/wp-content/plugins/afs-analytics-for-woocommerce/js/tracker.js/wp-content/plugins/afs-analytics-for-woocommerce/js/script.js
Version Parameters
afs-analytics-for-woocommerce/css/welcome.css?ver=afs-analytics-for-woocommerce/css/settings.css?ver=afs-analytics-for-woocommerce/js/intro.js?ver=afs-analytics-for-woocommerce/js/dashboard.js?ver=afs-analytics-for-woocommerce/js/admin.js?ver=afs-analytics-for-woocommerce/js/tracker.js?ver=afs-analytics-for-woocommerce/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
afsa_dashboard_widget
JS Globals
AFSA_DEBUG_MODEAFSA_MODULE_VERSIONAFSA_Core_Stats_PluginAFSA_ConfigAFSA_AjaxAFSA_Infos_Manager+21 more
FAQ

Frequently Asked Questions about AFS Analytics for WooCommerce