ClimateTrade's Carbon Offset Security & Risk Analysis

wordpress.org/plugins/climatetrades-carbon-offset

ClimateTrade’s easy to integrate widget allows your customers to offset the carbon footprint of their purchases in just a few clicks

0 active installs v1.0.0 PHP + WP 5.0+ Updated Unknown
carbon-offsetclimatewoocoomerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ClimateTrade's Carbon Offset Safe to Use in 2026?

Generally Safe

Score 100/100

ClimateTrade's Carbon Offset has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The climatetrades-carbon-offset plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL queries, using prepared statements exclusively, and a very high percentage of properly escaped output, minimizing risks of SQL injection and cross-site scripting. The absence of known vulnerabilities in its history is also a strong indicator of a well-maintained and secure codebase. However, the plugin has a significant security concern with its attack surface. It exposes two AJAX handlers, and critically, neither of these have any authentication checks. This leaves them wide open for unauthenticated users to trigger potentially sensitive actions.

The static analysis did not reveal any dangerous functions, file operations, or issues with bundled libraries. Taint analysis also reported zero flows, indicating that even with the identified entry points, no exploitable data flows were detected by the analysis. The presence of external HTTP requests is noted but without further context on what it communicates with, it's a minor point of observation rather than an immediate risk. The lack of nonce checks on the AJAX handlers is a critical oversight that directly contributes to the unprotected entry points.

In conclusion, while the plugin is free from historical vulnerabilities and has strong internal code hygiene for SQL and output, the lack of authentication on its AJAX endpoints represents a substantial security risk. This could allow any visitor to the site to interact with these handlers, potentially leading to unintended consequences or further exploitation if the handlers perform sensitive operations. The absence of capability checks further exacerbates this issue, as it means there are no checks to ensure only authorized users can access these functions.

Key Concerns

  • AJAX handlers without auth checks
  • AJAX handlers without nonce checks
  • AJAX handlers without capability checks
Vulnerabilities
None known

ClimateTrade's Carbon Offset Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ClimateTrade's Carbon Offset Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
69 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

99% escaped70 total outputs
Attack Surface
2 unprotected

ClimateTrade's Carbon Offset Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

noprivwp_ajax_climatetrade_updatecartwidgetclimatetrade.php:356
authwp_ajax_climatetrade_updatecartwidgetclimatetrade.php:357
WordPress Hooks 8
actioninitwidgetclimatetrade.php:40
actioninitwidgetclimatetrade.php:43
actionadmin_initwidgetclimatetrade.php:73
actionadmin_menuwidgetclimatetrade.php:74
actionwoocommerce_checkout_before_customer_detailswidgetclimatetrade.php:331
actionwp_enqueue_scriptswidgetclimatetrade.php:339
actionwoocommerce_before_calculate_totalswidgetclimatetrade.php:388
actionwoocommerce_order_status_processingwidgetclimatetrade.php:404
Maintenance & Trust

ClimateTrade's Carbon Offset Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedUnknown
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

ClimateTrade's Carbon Offset Developer Profile

woocommerceclimatetrade

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ClimateTrade's Carbon Offset

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
roboto--boldgrey1fs-14mt-30custom__inputmt-10mb-10blue1+13 more
Data Attributes
climatetrade_api_keyclimatetrade_compensationclimatetrade_paymentclimatetrade_imageclimatetrade_titleclimatetrade_description+4 more
JS Globals
WCT_SKUWCT_URL_APIC_API_KEYC_COMPENSATIONC_PAYMENTC_IMAGE+8 more
REST Endpoints
/v1/widget/calculate_offset_given_amount//v1/offsets/
FAQ

Frequently Asked Questions about ClimateTrade's Carbon Offset