
Convead Security & Risk Analysis
wordpress.org/plugins/convead-for-woocommerceConvead - Аnalytics and Actions Combined. Convead makes it easy to retain and return customers for eCommerce. Supports WooCommerce 2.x.
Is Convead Safe to Use in 2026?
Generally Safe
Score 85/100Convead has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The convead-for-woocommerce plugin v1.1.7 presents a mixed security posture. While the static analysis indicates a small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events, and a promising 100% of SQL queries using prepared statements, there are significant concerns regarding output escaping and the use of a dangerous function. The lack of proper output escaping across all identified outputs is a critical weakness that could lead to cross-site scripting (XSS) vulnerabilities if any of the plugin's output is rendered in a user-facing context without sanitization. Furthermore, the presence of the `unserialize` function, especially without clear evidence of sanitization of its input or capability checks surrounding its use, poses a potential risk for object injection vulnerabilities.
The plugin's vulnerability history is currently clean, with no known CVEs, which is a positive indicator. This suggests that, to date, no publicly disclosed vulnerabilities have been found or patched. However, this lack of history, combined with the identified code signals of poor output sanitization and potentially risky function usage, means that the plugin might have undiscovered vulnerabilities. The absence of capability checks is also a concern, as it implies that any entry points, if they were to exist, might not be adequately protected against unauthorized access. Overall, while the attack surface is minimal and SQL practices are good, the lack of output escaping and the use of `unserialize` without apparent safeguards introduce notable risks that require attention.
Key Concerns
- Output escaping is not properly implemented
- Use of dangerous function: unserialize
- Missing capability checks
Convead Security Vulnerabilities
Convead Code Analysis
Dangerous Functions Found
Output Escaping
Convead Attack Surface
WordPress Hooks 9
Maintenance & Trust
Convead Maintenance & Trust
Maintenance Signals
Community Trust
Convead Alternatives
Carrot quest
carrot-quest
Carrot quest совмещает в себе все инструменты для автоматизации маркетинга, продаж и коммуникации с пользователями. Поддерживает WooCommerce 5.x, 6.
Markeaze for WooCommerce
markeaze
Live chat by Markeaze is an all-in-one communication solution designed specifically for the needs of online stores.
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Exclusive Addons for Elementor
exclusive-addons-for-elementor
Exclusive Addons is one of the Best Elementor Addons With 90+ Elementor Free & Pro Widgets with all the customizations options you ever imagined.
Product Filter for WooCommerce by WBW
woo-product-filter
Filter products by categories, attributes, prices, and more. Elementor Compatibility. Shoppers easily find products with WooCommerce Product Filter
Convead Developer Profile
1 plugin · 20 total installs
How We Detect Convead
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/convead-for-woocommerce/css/convead.css/wp-content/plugins/convead-for-woocommerce/js/convead.js/wp-content/plugins/convead-for-woocommerce/js/convead.jsHTML / DOM Fingerprints
convead-settings<!-- Calling a function add administrative menu. --><!-- Function for delete options --><!-- Function formed content of the plugin's admin page. -->name='convead_key'name='currency_excange_rate'name='only_product_id'value='1'value='0'name='convead_plgn_form_submit'+2 moreCONVEAD_PLUGIN_URLCONVEAD_PLUGIN_DIR