
EasyTest – Simplify A/B Testing Security & Risk Analysis
wordpress.org/plugins/convertproEasyTest allows you to perform A/B testing, split testing, and compare pages with ease.
Is EasyTest – Simplify A/B Testing Safe to Use in 2026?
Mostly Safe
Score 76/100EasyTest – Simplify A/B Testing is generally safe to use. 2 past CVEs were resolved. Keep it updated.
The ConvertPro plugin exhibits a mixed security posture. While it demonstrates good practices in SQL query preparation and output escaping, a significant concern lies in its attack surface, particularly the high number of AJAX handlers lacking proper authentication checks. The taint analysis further highlights this by identifying a substantial number of flows with unsanitized paths, including five deemed high severity. This suggests a potential for attackers to exploit these entry points to manipulate data or execute unintended actions. The plugin's vulnerability history, despite a recent medium severity vulnerability, indicates a pattern of missing authorization, reinforcing the concerns raised by the static analysis. While the absence of critical vulnerabilities and a generally good approach to prepared statements and escaping are strengths, the unaddressed AJAX handlers and unsanitized taint flows represent immediate and significant risks that require urgent attention.
Key Concerns
- High number of unprotected AJAX handlers
- High severity unsanitized taint flows
- Unpatched CVE
- Missing nonce checks on AJAX
- Low capability checks coverage
EasyTest – Simplify A/B Testing Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
EasyTest <= 1.0.1 - Missing Authorization
Convert Pro <= 1.7.5 - Missing Authorization
EasyTest – Simplify A/B Testing Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
EasyTest – Simplify A/B Testing Attack Surface
AJAX Handlers 8
WordPress Hooks 20
Maintenance & Trust
EasyTest – Simplify A/B Testing Maintenance & Trust
Maintenance Signals
Community Trust
EasyTest – Simplify A/B Testing Alternatives
Unbounce Landing Pages
unbounce
Unbounce is the most powerful standalone landing page builder available.
Personizely — A/B Testing, Personalization, Popups & CRO
personizely
Personizely is a Conversion Optimization Toolkit that helps you boost engagement and sales through A/B testing, website personalization, and popups.
Sigmize: A/B Testing, Session Recordings, Heatmaps & Revenue Tracking for WooCommerce, SureCart & EDD
sigmize
Powerful A/B testing for WordPress with heatmaps, session replays, and e-commerce tracking for WooCommerce, SureCart, and EDD.
PageTest.ai – AI-Powered A/B and Multivariate Testing for WordPress
pagetest-ai
Run AI-powered A/B and multivariate tests on your WordPress site—no coding needed. Optimize conversions by finding your best content.
A/B See
ab-see
WordPress A/B testing in two shortcodes.
EasyTest – Simplify A/B Testing Developer Profile
4 plugins · 21K total installs
How We Detect EasyTest – Simplify A/B Testing
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/convertpro/assets/css/style.css/wp-content/plugins/convertpro/assets/js/frontent-script.js/wp-content/plugins/convertpro/assets/js/frontent-script.jsconvertpro/assets/css/style.css?ver=convertpro/assets/js/frontent-script.js?ver=HTML / DOM Fingerprints
cp-elements-previewcp-frontend-editorcp-modal-open<!-- ConvertPro -->data-cp-iddata-cp-namedata-cp-typeconvertpro_object[convertpro[cp_modal[cp_popup[cp_form