CodeAtoz Campaign Manager for WooCommerce Security & Risk Analysis

wordpress.org/plugins/codeatoz-campaign-manager

Run flash sales & WooCommerce promotions with countdown timers, urgency badges, and a clean campaign dashboard. No recurring fees.

0 active installs v1.3.1 PHP 7.4+ WP 6.0+ Updated Apr 14, 2026
countdown-timerdiscountflash-salepromotionswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CodeAtoz Campaign Manager for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

CodeAtoz Campaign Manager for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The codeatoz-campaign-manager plugin, version 1.3.1, exhibits a generally good security posture with some significant concerns. The plugin demonstrates strong adherence to secure coding practices, with all SQL queries utilizing prepared statements and a very high percentage of outputs being properly escaped. The absence of dangerous functions, file operations, and external HTTP requests further bolster its security. However, the presence of one unprotected REST API route presents a clear attack vector. While taint analysis found only one flow with unsanitized paths and no critical or high-severity issues, this single flow highlights a potential for vulnerabilities if it involves sensitive data or functionality.

The plugin's vulnerability history is remarkably clean, with zero recorded CVEs. This, combined with the limited number of identified code signals, suggests a well-developed and maintained plugin. Despite the positive history and strong coding practices, the unprotected REST API route is a notable weakness. The single unprotected entry point is a concern that could be exploited if it allows for any form of state modification or sensitive data leakage. Overall, the plugin is in a decent state, but the identified unprotected endpoint requires immediate attention to mitigate potential risks.

Key Concerns

  • Unprotected REST API route
  • Flow with unsanitized paths
Vulnerabilities
None known

CodeAtoz Campaign Manager for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

CodeAtoz Campaign Manager for WooCommerce Release Timeline

v1.3.1Current
v1.3.0
v1.2.0
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

CodeAtoz Campaign Manager for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
9 prepared
Unescaped Output
4
241 escaped
Nonce Checks
3
Capability Checks
15
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared9 total queries

Output Escaping

98% escaped245 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
render_campaign_form (includes/class-scm-admin.php:389)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

CodeAtoz Campaign Manager for WooCommerce Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

GET/wp-json/codeatoz-scm/v1/active-campaignincludes/class-scm-widget.php:51
WordPress Hooks 25
actionbefore_woocommerce_initcodeatoz-campaign-manager.php:51
actionplugins_loadedcodeatoz-campaign-manager.php:67
actionplugins_loadedcodeatoz-campaign-manager.php:148
actionplugins_loadedcodeatoz-campaign-manager.php:149
actionadmin_menucodeatoz-campaign-manager.php:151
actionadmin_enqueue_scriptscodeatoz-campaign-manager.php:152
actionwp_enqueue_scriptscodeatoz-campaign-manager.php:153
actionadmin_noticescodeatoz-campaign-manager.php:164
actionwp_dashboard_setupcodeatoz-campaign-manager.php:319
actionadmin_noticesincludes/class-scm-cron-check.php:41
filterwoocommerce_product_get_priceincludes/class-scm-discount.php:41
filterwoocommerce_product_get_regular_priceincludes/class-scm-discount.php:42
filterwoocommerce_product_get_sale_priceincludes/class-scm-discount.php:43
filterwoocommerce_product_variation_get_priceincludes/class-scm-discount.php:45
filterwoocommerce_product_variation_get_sale_priceincludes/class-scm-discount.php:46
filterwoocommerce_product_is_on_saleincludes/class-scm-discount.php:48
filterwoocommerce_get_price_htmlincludes/class-scm-discount.php:49
actionwoocommerce_before_shop_loop_item_titleincludes/class-scm-discount.php:51
actionwoocommerce_before_cartincludes/class-scm-discount.php:52
actionwoocommerce_single_product_summaryincludes/class-scm-discount.php:53
actionadmin_noticesincludes/class-scm-scheduler.php:42
actioncodeatoz_scm_activate_campaignincludes/class-scm-scheduler.php:46
actioncodeatoz_scm_expire_campaignincludes/class-scm-scheduler.php:47
actionrest_api_initincludes/class-scm-widget.php:41
actionwp_footerincludes/class-scm-widget.php:44
Maintenance & Trust

CodeAtoz Campaign Manager for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 14, 2026
PHP min version7.4
Downloads128

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

CodeAtoz Campaign Manager for WooCommerce Developer Profile

codeatoz

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CodeAtoz Campaign Manager for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/codeatoz-campaign-manager/admin/css/scm-admin.css/wp-content/plugins/codeatoz-campaign-manager/admin/js/scm-admin.js/wp-content/plugins/codeatoz-campaign-manager/public/css/scm-public.css/wp-content/plugins/codeatoz-campaign-manager/public/js/scm-widget.js
Script Paths
admin/js/scm-admin.jspublic/js/scm-widget.js
Version Parameters
codeatoz-campaign-manager/admin/css/scm-admin.css?ver=codeatoz-campaign-manager/admin/js/scm-admin.js?ver=codeatoz-campaign-manager/public/css/scm-public.css?ver=codeatoz-campaign-manager/public/js/scm-widget.js?ver=

HTML / DOM Fingerprints

CSS Classes
codeatoz-scm-admincodeatoz-scm-publiccodeatoz-scm-widget
Data Attributes
data-scm-campaign-id
JS Globals
codeatoz_scm_admincodeatoz_scm_data
REST Endpoints
/wp-json/codeatoz-scm/v1/active-campaign
FAQ

Frequently Asked Questions about CodeAtoz Campaign Manager for WooCommerce