
Convertizer.fr Security & Risk Analysis
wordpress.org/plugins/convertizerfrConvertizer, Créez un lien avec vos clients.
Is Convertizer.fr Safe to Use in 2026?
Generally Safe
Score 85/100Convertizer.fr has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "convertizerfr" plugin v1.3.2 reveals an exceptionally small attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events. This lack of direct entry points is a strong positive security indicator. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests, along with the use of prepared statements for all SQL queries, demonstrates adherence to several secure coding practices.
However, a significant concern arises from the output escaping signal, where 100% of the 12 identified outputs are not properly escaped. This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities if any of the plugin's data, even indirectly, can be controlled by an attacker. The complete lack of nonce checks and capability checks, combined with zero detected taint flows, is unusual. While this could mean the plugin is extremely simple and has no user-controllable input, it also prevents a thorough assessment of potential vulnerabilities if the plugin were to evolve or have hidden interaction points.
The vulnerability history is also completely clean, with zero known CVEs. This, in conjunction with the limited attack surface and lack of critical code signals, suggests that up to this version, the plugin has been relatively secure or has not been a target. However, the identified unescaped output is a critical weakness that overshadows the otherwise clean security profile. The plugin's strengths lie in its minimal attack surface and secure SQL handling, but its weaknesses in output sanitization present a clear and present danger.
Key Concerns
- Output escaping is not implemented
- No nonce checks detected
- No capability checks detected
- No taint flows analyzed
Convertizer.fr Security Vulnerabilities
Convertizer.fr Release Timeline
Convertizer.fr Code Analysis
Output Escaping
Convertizer.fr Attack Surface
WordPress Hooks 5
Maintenance & Trust
Convertizer.fr Maintenance & Trust
Maintenance Signals
Community Trust
Convertizer.fr Alternatives
No alternatives data available yet.
Convertizer.fr Developer Profile
6 plugins · 130 total installs
How We Detect Convertizer.fr
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/convertizerfr/css/admin.csshttps://api.convertizer.fr/partner.jsconvertizerfr/style.css?ver=convertizer-async/partner.js?v=HTML / DOM Fingerprints
WordPressLiveSupportDashboardWordPressLiveSupportDashboardSettingsconvertizerfrid="convertizerfr"jQuery