
CodeAtoz Campaign Manager for WooCommerce Security & Risk Analysis
wordpress.org/plugins/codeatoz-campaign-managerRun flash sales & WooCommerce promotions with countdown timers, urgency badges, and a clean campaign dashboard. No recurring fees.
Is CodeAtoz Campaign Manager for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100CodeAtoz Campaign Manager for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The codeatoz-campaign-manager plugin, version 1.3.1, exhibits a generally good security posture with some significant concerns. The plugin demonstrates strong adherence to secure coding practices, with all SQL queries utilizing prepared statements and a very high percentage of outputs being properly escaped. The absence of dangerous functions, file operations, and external HTTP requests further bolster its security. However, the presence of one unprotected REST API route presents a clear attack vector. While taint analysis found only one flow with unsanitized paths and no critical or high-severity issues, this single flow highlights a potential for vulnerabilities if it involves sensitive data or functionality.
The plugin's vulnerability history is remarkably clean, with zero recorded CVEs. This, combined with the limited number of identified code signals, suggests a well-developed and maintained plugin. Despite the positive history and strong coding practices, the unprotected REST API route is a notable weakness. The single unprotected entry point is a concern that could be exploited if it allows for any form of state modification or sensitive data leakage. Overall, the plugin is in a decent state, but the identified unprotected endpoint requires immediate attention to mitigate potential risks.
Key Concerns
- Unprotected REST API route
- Flow with unsanitized paths
CodeAtoz Campaign Manager for WooCommerce Security Vulnerabilities
CodeAtoz Campaign Manager for WooCommerce Release Timeline
CodeAtoz Campaign Manager for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
CodeAtoz Campaign Manager for WooCommerce Attack Surface
REST API Routes 1
WordPress Hooks 25
Maintenance & Trust
CodeAtoz Campaign Manager for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
CodeAtoz Campaign Manager for WooCommerce Alternatives
Finale Lite – Sales Countdown Timer & Discount for WooCommerce
finale-woocommerce-sales-countdown-timer-discount
Finale lets you create scheduled one time or recurring campaigns. It induces urgency with visual elements such as Countdown Timer and Counter Bar to m …
wiseCampaign – Banners, Discounts & Sales Notifications for WooCommerce
wisecampaign
Boost WooCommerce sales with countdown banners, stock urgency bars, discount manager, direct checkout and sales notifications. No coding needed.
PromoTimer – Flash Sale Scheduler for WooCommerce
flash-sale-scheduler-for-woocommerce
Schedule WooCommerce sale prices with start/end date + time, show a live countdown timer, and display customizable promo messages.
NIXSMART Strategic Discount Manager
nixsmart-strategic-discount-manager
Manage WooCommerce discounts, list prices, and countdown timers from a single, intuitive interface.
Offer Countdown Timer for WooCommerce
offer-countdown-time
Offer Countdown Timer is the best for sle boosting.
CodeAtoz Campaign Manager for WooCommerce Developer Profile
2 plugins · 0 total installs
How We Detect CodeAtoz Campaign Manager for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/codeatoz-campaign-manager/admin/css/scm-admin.css/wp-content/plugins/codeatoz-campaign-manager/admin/js/scm-admin.js/wp-content/plugins/codeatoz-campaign-manager/public/css/scm-public.css/wp-content/plugins/codeatoz-campaign-manager/public/js/scm-widget.jsadmin/js/scm-admin.jspublic/js/scm-widget.jscodeatoz-campaign-manager/admin/css/scm-admin.css?ver=codeatoz-campaign-manager/admin/js/scm-admin.js?ver=codeatoz-campaign-manager/public/css/scm-public.css?ver=codeatoz-campaign-manager/public/js/scm-widget.js?ver=HTML / DOM Fingerprints
codeatoz-scm-admincodeatoz-scm-publiccodeatoz-scm-widgetdata-scm-campaign-idcodeatoz_scm_admincodeatoz_scm_data/wp-json/codeatoz-scm/v1/active-campaign