Official CleverReach® Plugin for WooCommerce Security & Risk Analysis

wordpress.org/plugins/cleverreach-wc

Connect your WooCommerce store to our email software and say hello to successful and simple newsletter marketing – just like Spotify, Bugatti & DHL!

400 active installs v3.4.9 PHP 5.3+ WP 4.7+ Updated Jan 26, 2026
email-automationemail-marketing-toolintegrationmarketing-automationnewsletter
99
A · Safe
CVEs total1
Unpatched0
Last CVEApr 4, 2025
Safety Verdict

Is Official CleverReach® Plugin for WooCommerce Safe to Use in 2026?

Generally Safe

Score 99/100

Official CleverReach® Plugin for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Apr 4, 2025Updated 3mo ago
Risk Assessment

The cleverreach-wc plugin v3.4.9 demonstrates a generally strong security posture based on the provided static analysis. The absence of any identified critical or high severity taint flows, along with a high percentage of SQL queries using prepared statements and properly escaped output, indicates good development practices in preventing common injection and XSS vulnerabilities. The limited number of file operations and external HTTP requests further reduces the potential attack surface. However, the vulnerability history does reveal a past medium severity Cross-Site Request Forgery (CSRF) vulnerability, even though it is currently patched. This suggests that while the developers are responsive to patching, the potential for CSRF issues exists and warrants continued vigilance. The complete lack of capability checks on entry points, while not directly flagged as an issue in the static analysis due to the absence of entry points, remains a theoretical concern if new entry points are introduced without proper authorization mechanisms. Overall, the plugin appears to be well-secured, with the primary area for attention being the historical precedent for CSRF vulnerabilities and the importance of maintaining robust authorization checks for any future additions to the attack surface.

Key Concerns

  • Past Medium CSRF Vulnerability
Vulnerabilities
1 published

Official CleverReach® Plugin for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-32241medium · 4.3Cross-Site Request Forgery (CSRF)

Official CleverReach Plugin for WooCommerce <= 3.4.4 - Cross-Site Request Forgery to Settings Update

Apr 4, 2025 Patched in 3.4.7 (218d)
Version History

Official CleverReach® Plugin for WooCommerce Release Timeline

v3.4.9Current
v3.4.8
v3.4.7
v3.4.61 CVE
v3.4.51 CVE
v3.4.41 CVE
v3.4.31 CVE
v3.4.21 CVE
v3.4.11 CVE
v3.4.01 CVE
v3.3.21 CVE
v3.3.11 CVE
v3.3.01 CVE
v3.2.31 CVE
v3.2.21 CVE
v3.2.11 CVE
v3.2.01 CVE
v3.1.131 CVE
v3.1.121 CVE
v3.1.111 CVE
Code Analysis
Analyzed Mar 16, 2026

Official CleverReach® Plugin for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
6
79 prepared
Unescaped Output
4
650 escaped
Nonce Checks
12
Capability Checks
0
File Operations
4
External Requests
0
Bundled Libraries
0

SQL Query Safety

93% prepared85 total queries

Output Escaping

99% escaped654 total outputs
Attack Surface

Official CleverReach® Plugin for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 28
actionadmin_noticesclass-plugin.php:381
actioninitclass-plugin.php:393
actionadmin_initclass-plugin.php:394
actionupgrader_process_completeclass-plugin.php:395
filterquery_varsclass-plugin.php:396
actiontemplate_redirectclass-plugin.php:397
actionwp_logoutclass-plugin.php:398
actionwp_loginclass-plugin.php:399
actionwp_loginclass-plugin.php:400
actionwoocommerce_before_checkout_formclass-plugin.php:401
actionwp_enqueue_scriptsclass-plugin.php:407
actiondelete_blogclass-plugin.php:414
actionbefore_woocommerce_initclass-plugin.php:417
actionadmin_enqueue_scriptsclass-plugin.php:419
actionadmin_menuclass-plugin.php:480
actionregister_formclass-plugin.php:490
actionuser_new_formclass-plugin.php:491
actionshow_user_profileclass-plugin.php:492
actionedit_user_profileclass-plugin.php:493
actionwoocommerce_register_formclass-plugin.php:495
actionwoocommerce_edit_account_formclass-plugin.php:496
actionwoocommerce_after_checkout_billing_formclass-plugin.php:497
actionwoocommerce_blocks_loadedclass-plugin.php:502
actionwoocommerce_blocks_checkout_block_registrationclass-plugin.php:509
actionwoocommerce_after_checkout_billing_formclass-plugin.php:525
filterwoocommerce_admin_reportsclass-plugin.php:537
actionload-woocommerce_page_wc-reportsclass-plugin.php:538
actionadmin_print_footer_scriptsclass-plugin.php:552
Maintenance & Trust

Official CleverReach® Plugin for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 26, 2026
PHP min version5.3
Downloads27K

Community Trust

Rating86/100
Number of ratings4
Active installs400
Developer Profile

Official CleverReach® Plugin for WooCommerce Developer Profile

CleverReach®

3 plugins · 6K total installs

87
trust score
Avg Security Score
98/100
Avg Patch Time
82 days
View full developer profile
Detection Fingerprints

How We Detect Official CleverReach® Plugin for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cleverreach-wc/resources/views/partial/register-form-newsletter-checkbox.php/wp-content/plugins/cleverreach-wc/resources/views/partial/checkout-form-newsletter-checkbox.php/wp-content/plugins/cleverreach-wc/resources/views/partial/profile-newsletter-checkbox.php/wp-content/plugins/cleverreach-wc/resources/views/partial/abandoned-cart-billing-email-listener.php
Script Paths
/resources/js/cleverreach.checkout-form-newsletter-checkbox.js/resources/js/cleverreach.ac-billing-email-listener.js/resources/js/cleverreach.ac-overview.js
Version Parameters
ver=?ver=

HTML / DOM Fingerprints

CSS Classes
cleverreach-wc-form-wrapper
HTML Comments
<!-- CleverReach - Abandoned Carts -->
Data Attributes
data-cleverreach-wc-form-id
JS Globals
cleverreach_wc_params
FAQ

Frequently Asked Questions about Official CleverReach® Plugin for WooCommerce