
Convertiser Widgets Security & Risk Analysis
wordpress.org/plugins/convertiser-widgetsSimplifies Convertiser widgets integration into your website.
Is Convertiser Widgets Safe to Use in 2026?
Generally Safe
Score 85/100Convertiser Widgets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'convertiser-widgets' plugin v1.3.1 exhibits a generally good security posture, with no known vulnerabilities and a significant portion of its output being properly escaped. The absence of any recorded CVEs, critical or high severity taint flows, and file operations are all positive indicators. The plugin also includes some basic security measures like nonce checks and uses reputable bundled libraries like Select2 and jQuery.
However, there are notable concerns. The plugin performs SQL queries without using prepared statements, which is a significant risk for SQL injection vulnerabilities, especially if the data originates from user input. Additionally, the absence of capability checks on its entry points (AJAX handlers, shortcodes, cron events) means that any user, regardless of their role or permissions, could potentially trigger these functionalities. While the static analysis did not reveal any unsanitized paths in taint flows, the lack of capability checks combined with raw SQL queries presents a substantial theoretical attack surface that could be exploited if specific conditions are met.
In conclusion, while the plugin benefits from a clean vulnerability history and good output escaping practices, the critical shortcomings in SQL query sanitization and the lack of capability checks on its entry points pose significant security risks. These issues require immediate attention to bring the plugin up to a more secure standard.
Key Concerns
- Raw SQL queries without prepared statements
- No capability checks on entry points
Convertiser Widgets Security Vulnerabilities
Convertiser Widgets Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Convertiser Widgets Attack Surface
AJAX Handlers 1
Shortcodes 3
WordPress Hooks 49
Scheduled Events 2
Maintenance & Trust
Convertiser Widgets Maintenance & Trust
Maintenance Signals
Community Trust
Convertiser Widgets Alternatives
Content Egg – Affiliate Product Importer & Price Comparison
content-egg
Import affiliate products, compare prices, sync to WooCommerce, and auto-generate SEO content with AI — all in one toolkit.
Meks Easy Ads Widget
meks-easy-ads-widget
Display unlimited number of ads inside your WordPress widget.
Meks ThemeForest Smart Widget
meks-themeforest-smart-widget
Easily display ThemeForest items inside WordPress widget.
Booking.com Product Helper
bookingcom-product-helper
The Booking.com Product Helper allows you to embed any Booking.com affiliate product anywhere on your website.
LWS Affiliation
lws-affiliation
Add banners and widgets from the affiliate program of LWS.
Convertiser Widgets Developer Profile
1 plugin · 10 total installs
How We Detect Convertiser Widgets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/convertiser-widgets/assets/css/general.css/wp-content/plugins/convertiser-widgets/assets/js/bootstrap/bootstrap-prefixed.min.js/wp-content/plugins/convertiser-widgets/assets/js/general.min.js/wp-content/plugins/convertiser-widgets/assets/js/notice.min.jsconvertiser-widgets/assets/css/general.css?ver=convertiser-widgets/assets/js/bootstrap/bootstrap-prefixed.min.js?ver=convertiser-widgets/assets/js/general.min.js?ver=convertiser-widgets/assets/js/notice.min.js?ver=HTML / DOM Fingerprints
<!-- Decrease priority for `addNotices` so it run *after* notices has been added. --><!-- Use handler if defined, otherwise try to include view file -->data-dismiss="alert"ConvertiserWidgetsNotice