Convertux Connector Security & Risk Analysis

wordpress.org/plugins/convertux-connector

Convert your visitors in intelligent way. Get more sales & subscribers with beautiful sticky bars, lightboxes, full page modals, chat-like modals, …

10 active installs v1.0.1 PHP + WP 4.1.0+ Updated Jul 8, 2021
convertuxexit-intentpop-uppop-upspopups
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Convertux Connector Safe to Use in 2026?

Generally Safe

Score 85/100

Convertux Connector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The convertux-connector plugin version 1.0.1 demonstrates a generally strong security posture with no recorded vulnerabilities or critical code signals. The absence of dangerous functions, raw SQL queries, and file operations are positive indicators. The plugin also incorporates a nonce check, which is a good practice for protecting against CSRF attacks. However, the analysis does reveal some areas for improvement. Specifically, the presence of two taint flows with unsanitized paths, while not flagged as critical or high severity, suggests a potential for data manipulation if these paths are ever exposed to user input. Furthermore, the lack of capability checks on any entry points, including the identified shortcode, is a significant concern. This means that any user, regardless of their role or permissions, could potentially interact with the plugin's functionality, opening the door for unauthorized access or abuse if the shortcode's functionality is sensitive.

While the plugin has no recorded vulnerability history, this doesn't guarantee future safety. The current lack of security issues might be due to the plugin's limited functionality, limited adoption, or simply good fortune to date. The presence of unsanitized paths and the complete absence of capability checks are the most significant weaknesses. The plugin should ideally implement capability checks for all its entry points to ensure that only authorized users can trigger its functionality. Additionally, the identified taint flows need to be thoroughly reviewed and sanitized to mitigate any potential risks, even if they are not currently categorized as high severity.

Key Concerns

  • No capability checks on entry points
  • Unsanitized paths in taint flows
  • Low percentage of properly escaped output
Vulnerabilities
None known

Convertux Connector Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Convertux Connector Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
6 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

75% escaped8 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
convertux_page (convertux.php:68)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Convertux Connector Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[convertuxarea] convertux.php:179
WordPress Hooks 9
actionwp_enqueue_scriptsconvertux.php:26
filterscript_loader_tagconvertux.php:34
actionactivated_pluginconvertux.php:43
actionadmin_noticesconvertux.php:66
actionadmin_menuconvertux.php:106
actionadmin_enqueue_scriptsconvertux.php:121
actionrest_api_initconvertux.php:138
actionsend_headersconvertux.php:146
actionwp_headconvertux.php:170
Maintenance & Trust

Convertux Connector Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedJul 8, 2021
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Convertux Connector Developer Profile

Convertux

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Convertux Connector

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/convertux-connector/css/app.css
Script Paths
https://cdn.convertux.com/js/loader.js
Version Parameters
convertux-connector/css/app.css?ver=1.0.0

HTML / DOM Fingerprints

Data Attributes
id="app-convertux-script"data-uuid
JS Globals
window.convertux_post_data
REST Endpoints
/wp-json/convertux/v1/tags/wp-json/convertux/v1/types/wp-json/convertux/v1/categories
Shortcode Output
<div id=
FAQ

Frequently Asked Questions about Convertux Connector