CausalFunnel – Conversion Rate Optimization Tool (Heatmap, User Journey, A/B Testing) Security & Risk Analysis

wordpress.org/plugins/causalfunnel-datascience

AI-powered conversion rate optimization with heatmaps, user journey analytics, and A/B testing — no cookies required.

10 active installs v2.2.0 PHP 7.0+ WP 4.7+ Updated Apr 5, 2026
a-b-testingconversion-optimizationdata-scienceheatmapuser-journey
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is CausalFunnel – Conversion Rate Optimization Tool (Heatmap, User Journey, A/B Testing) Safe to Use in 2026?

Generally Safe

Score 100/100

CausalFunnel – Conversion Rate Optimization Tool (Heatmap, User Journey, A/B Testing) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The causalfunnel-datascience plugin v2.2.0 exhibits a generally strong security posture based on the static analysis. The absence of identified dangerous functions, raw SQL queries, file operations, and a remarkably low number of unsanitized paths in taint analysis are significant strengths. The plugin also demonstrates good practices regarding output escaping and utilizes nonce and capability checks, contributing to its secure foundation. The lack of any recorded vulnerabilities in its history further reinforces this positive assessment, suggesting a commitment to security or simply a lack of past exploitation.

However, a few areas warrant attention. The presence of two flows with unsanitized paths, while not classified as critical or high severity in taint analysis, represents a potential avenue for vulnerabilities if exploited. Additionally, the four external HTTP requests, while not inherently insecure, could become a risk if the target endpoints are compromised or if the data sent is sensitive and not properly handled. The very limited attack surface is a positive, but the absence of any unprotected entry points is also notable. Overall, the plugin appears robust, but continued vigilance on the two unsanitized paths and careful management of external requests are advisable.

Key Concerns

  • Flows with unsanitized paths found
  • External HTTP requests made
Vulnerabilities
None known

CausalFunnel – Conversion Rate Optimization Tool (Heatmap, User Journey, A/B Testing) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

CausalFunnel – Conversion Rate Optimization Tool (Heatmap, User Journey, A/B Testing) Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

CausalFunnel – Conversion Rate Optimization Tool (Heatmap, User Journey, A/B Testing) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
420 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
4
Bundled Libraries
0

Output Escaping

98% escaped430 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
causalfunnel_heatmap_page (pages/heatmap-page.php:10)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

CausalFunnel – Conversion Rate Optimization Tool (Heatmap, User Journey, A/B Testing) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_initcausalfunnel-datascience.php:47
actionwp_enqueue_scriptscausalfunnel-datascience.php:56
filterscript_loader_tagcausalfunnel-datascience.php:59
filterwp_resource_hintscausalfunnel-datascience.php:62
actionadmin_menucausalfunnel-datascience.php:65
actionadmin_initincludes/consent-manager.php:127
Maintenance & Trust

CausalFunnel – Conversion Rate Optimization Tool (Heatmap, User Journey, A/B Testing) Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 5, 2026
PHP min version7.0
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

CausalFunnel – Conversion Rate Optimization Tool (Heatmap, User Journey, A/B Testing) Developer Profile

causalfunnel

2 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CausalFunnel – Conversion Rate Optimization Tool (Heatmap, User Journey, A/B Testing)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/causalfunnel-datascience/assets/cfCKYv1_*.js/wp-content/plugins/causalfunnel-datascience/assets/cf-abtest.js
Script Paths
https://www.scripts.causalfunnel.com/assets/cfCKYv1_*.jshttps://abtest.causalfunnel.org/assets/cf-abtest.js
Version Parameters
causalfunnel-datascience/style.css?ver=causalf-script?rand=causalf-abtest-script?cf_username=

HTML / DOM Fingerprints

Data Attributes
data-minifydata-cfasyncnitro-excludedata-no-optimize
JS Globals
window.causalfunnel
FAQ

Frequently Asked Questions about CausalFunnel – Conversion Rate Optimization Tool (Heatmap, User Journey, A/B Testing)