BaoBrain Analytics for WooCommerce Security & Risk Analysis

wordpress.org/plugins/baobrain-analytics-for-woocommerce

AI-powered customer intelligence that connects what shoppers SAY online with what they DO on your store.

0 active installs v1.0.1 PHP 7.4+ WP 5.8+ Updated Jan 17, 2026
aianalyticsecommercesocial-listeningwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BaoBrain Analytics for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

BaoBrain Analytics for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

Based on the static analysis and vulnerability history, the 'baobrain-analytics-for-woocommerce' plugin version 1.0.1 exhibits a strong security posture. The code demonstrates good security practices, with all identified SQL queries utilizing prepared statements and all output being properly escaped. The plugin also correctly implements nonce and capability checks on its AJAX endpoints, and there are no shortcodes or cron events contributing to the attack surface. The absence of known CVEs and a clean vulnerability history further indicates a generally secure plugin.

While the plugin has a small attack surface with two AJAX handlers, both are protected by authentication checks, mitigating direct exploitation risks. The single external HTTP request is a potential area of concern, as it could be a vector if the external service is compromised or if data is sent insecurely. However, without further analysis of this specific request, it's difficult to assign a definitive risk. The lack of any identified taint flows with unsanitized paths or dangerous functions is a significant positive indicator.

In conclusion, this version of the plugin appears to be well-secured, with robust implementation of security best practices. The minimal attack surface and strong adherence to authentication, authorization, and output sanitization are commendable. The primary area for continued vigilance would be the single external HTTP request.

Key Concerns

  • External HTTP request identified
Vulnerabilities
None known

BaoBrain Analytics for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

BaoBrain Analytics for WooCommerce Release Timeline

v1.0.1Current
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

BaoBrain Analytics for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
57 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped57 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<class-baobrain-admin> (admin/class-baobrain-admin.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

BaoBrain Analytics for WooCommerce Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_baobrain_disconnectadmin/class-baobrain-admin.php:44
authwp_ajax_baobrain_finalize_connectionadmin/class-baobrain-admin.php:45
WordPress Hooks 10
actionadmin_menuadmin/class-baobrain-admin.php:39
actionadmin_enqueue_scriptsadmin/class-baobrain-admin.php:40
actionadmin_initadmin/class-baobrain-admin.php:41
actionadmin_initbaobrain-tracker.php:136
actionwp_enqueue_scriptsbaobrain-tracker.php:146
actionwoocommerce_before_single_productbaobrain-tracker.php:147
actionbefore_woocommerce_initbaobrain-tracker.php:151
actionadmin_noticesbaobrain-tracker.php:185
filterscript_loader_tagbaobrain-tracker.php:268
actionplugins_loadedbaobrain-tracker.php:317
Maintenance & Trust

BaoBrain Analytics for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 17, 2026
PHP min version7.4
Downloads156

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

BaoBrain Analytics for WooCommerce Developer Profile

baobrain

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BaoBrain Analytics for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/baobrain-analytics-for-woocommerce/admin/js/baobrain-admin.js/wp-content/plugins/baobrain-analytics-for-woocommerce/admin/css/baobrain-admin.css
Script Paths
https://www.googletagmanager.com/gtag/jshttps://app.baobrain.com/woocommerce/sessions.jshttps://app.baobrain.com/woocommerce/tracker.js
Version Parameters
baobrain-analytics-for-woocommerce/admin/js/baobrain-admin.js?ver=baobrain-analytics-for-woocommerce/admin/css/baobrain-admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
baobrain-notice
Data Attributes
data-baobrain-site-iddata-baobrain-site-token
JS Globals
baobrain_settings
FAQ

Frequently Asked Questions about BaoBrain Analytics for WooCommerce