Convertful – Your Ultimate On-Site Conversion Tool Security & Risk Analysis

wordpress.org/plugins/convertful

All the modern on-site conversion solutions, natively integrates with all modern Email Marketing Platforms.

4K active installs v2.8 PHP + WP 4.0+ Updated Mar 5, 2026
barmailchimpopt-inoptinpopup
100
A · Safe
CVEs total1
Unpatched0
Last CVEOct 24, 2023
Safety Verdict

Is Convertful – Your Ultimate On-Site Conversion Tool Safe to Use in 2026?

Generally Safe

Score 100/100

Convertful – Your Ultimate On-Site Conversion Tool has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Oct 24, 2023Updated 29d ago
Risk Assessment

The Convertful plugin, version 2.8, presents a mixed security posture. Static analysis reveals a relatively small attack surface with only 6 total entry points, but a concerning 4 of these lack authorization checks. The plugin demonstrates good practices in handling SQL queries, utilizing prepared statements exclusively and effectively escaping most output. There are no identified dangerous functions, file operations, external requests, or tainted flows in this version, which is positive. However, the absence of capability checks on entry points and only one nonce check across the entire plugin are significant weaknesses.

The vulnerability history shows a single known CVE for this plugin, which is now patched. While this is reassuring, the historical common vulnerability type of 'Missing Authorization' aligns with the static analysis findings of unprotected REST API routes, highlighting a recurring area of concern. The plugin's strengths lie in its secure SQL handling and output escaping. The primary weaknesses are the direct exposure of REST API routes without permission callbacks and the general lack of robust authorization checks on its entry points, which could be exploited by unauthenticated users to access or manipulate data.

In conclusion, while Convertful 2.8 has made strides in areas like SQL security, the significant number of unprotected REST API routes poses a notable risk. The lack of comprehensive authorization checks on these entry points is the most critical finding. This, combined with the history of authorization vulnerabilities, suggests a need for more stringent access control mechanisms within the plugin's API endpoints to fully mitigate potential security risks.

Key Concerns

  • Unprotected REST API routes
  • Lack of capability checks
  • Minimal nonce checks
  • History of missing authorization vulnerabilities
  • Low output escaping for 5% of outputs
Vulnerabilities
1

Convertful – Your Ultimate On-Site Conversion Tool Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-46605medium · 5.3Missing Authorization

Convertful – Your Ultimate On-Site Conversion Tool <= 2.5 - Missing Authorization via add_woo_coupon

Oct 24, 2023 Patched in 2.6 (91d)
Code Analysis
Analyzed Mar 16, 2026

Convertful – Your Ultimate On-Site Conversion Tool Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
38 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped40 total outputs
Attack Surface
4 unprotected

Convertful – Your Ultimate On-Site Conversion Tool Attack Surface

Entry Points6
Unprotected4

REST API Routes 4

POST/wp-json/convertful/v2/complete_authorization/convertful.php:35
POST/wp-json/convertful/v2/get_info/convertful.php:41
POST/wp-json/convertful/v2/add_to_woo_cart/functions\woocommerce.php:6
POST/wp-json/convertful/v2/add_woo_coupon/functions\woocommerce.php:11

Shortcodes 2

[convertful] functions\shortcodes.php:5
[optin] functions\shortcodes.php:6
WordPress Hooks 10
actioninitconvertful.php:23
actionrest_api_initconvertful.php:34
actionwp_enqueue_scriptsconvertful.php:65
filterscript_loader_tagconvertful.php:66
filterthe_contentconvertful.php:67
actionadmin_enqueue_scriptsfunctions\admin_pages.php:3
actionactivated_pluginfunctions\admin_pages.php:14
actionadmin_menufunctions\admin_pages.php:42
actioninitfunctions\shortcodes.php:3
actionrest_api_initfunctions\woocommerce.php:5
Maintenance & Trust

Convertful – Your Ultimate On-Site Conversion Tool Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 5, 2026
PHP min version
Downloads129K

Community Trust

Rating86/100
Number of ratings6
Active installs4K
Developer Profile

Convertful – Your Ultimate On-Site Conversion Tool Developer Profile

Convertful Team

1 plugin · 4K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
91 days
View full developer profile
Detection Fingerprints

How We Detect Convertful – Your Ultimate On-Site Conversion Tool

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/convertful/js/convertful-admin.js/wp-content/plugins/convertful/js/convertful-editor.js/wp-content/plugins/convertful/js/convertful-api.js
Script Paths
https://convertful.com/Convertful.js
Version Parameters
convertful/js/convertful-admin.js?ver=convertful/js/convertful-editor.js?ver=convertful/js/convertful-api.js?ver=

HTML / DOM Fingerprints

CSS Classes
conv-place
Data Attributes
id="convertful-api"id="optin-api"
JS Globals
convPlatformVars
REST Endpoints
/wp-json/convertful/v2/complete_authorization//wp-json/convertful/v2/get_info/
FAQ

Frequently Asked Questions about Convertful – Your Ultimate On-Site Conversion Tool