CustomerLabs Conversion Tracking for WooCommerce Security & Risk Analysis

wordpress.org/plugins/customerlabs-actionrecorder

WooCommerce conversion tracking for Google Ads, Meta & GA4. Automatic events, enhanced conversions. CustomerLabs CDP - no code!

100 active installs v2.1.1 PHP 7.0+ WP 5.0+ Updated Nov 29, 2025
conversion-trackingmeta-conversions-apiwoocommerce-conversion-trackingwoocommerce-ga4woocommerce-google-ads
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is CustomerLabs Conversion Tracking for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

CustomerLabs Conversion Tracking for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The customerlabs-actionrecorder plugin, version 2.1.1, exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The plugin has no recorded CVEs, indicating a history of responsible security management or a lack of discovered vulnerabilities. The static analysis further reinforces this, showing a complete absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests. Crucially, all identified entry points (AJAX handlers) appear to have authorization checks in place, which is a significant mitigating factor against common WordPress attack vectors. The high percentage of properly escaped output (91%) is also a positive sign, reducing the risk of cross-site scripting (XSS) vulnerabilities.

However, there are a few areas that warrant minor attention. While the plugin has only 4 AJAX handlers and 0 REST API routes, shortcodes, or cron events, the presence of 4 AJAX handlers means there are 4 potential entry points into the plugin's logic. Although the analysis states 0 unprotected entry points, the actual implementation of these checks should be carefully reviewed. Furthermore, the limited number of nonce checks (2) and capability checks (1) for the identified entry points might suggest an opportunity for improvement, especially if the complexity of these handlers increases in future versions. The total absence of taint analysis results could mean the analysis tool was not configured for it or that there were genuinely no identifiable unsanitized flows. Regardless, a complete lack of taint analysis findings is often a positive indicator in itself.

In conclusion, customerlabs-actionrecorder v2.1.1 appears to be a secure plugin with a strong emphasis on preventing common vulnerabilities. Its lack of historical vulnerabilities and robust implementation of security checks on its entry points are commendable. The minor deductions relate to the absolute count of security checks and the potential for future growth in the attack surface. Overall, the risk associated with this plugin is low.

Key Concerns

  • Limited nonce/capability checks for entry points
Vulnerabilities
None known

CustomerLabs Conversion Tracking for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

CustomerLabs Conversion Tracking for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
43 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

91% escaped47 total outputs
Attack Surface

CustomerLabs Conversion Tracking for WooCommerce Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_cltracker_unset_cookieclass-cltracker-cookie.php:174
noprivwp_ajax_cltracker_unset_cookieclass-cltracker-cookie.php:175
authwp_ajax_cltracker_set1pd_cookieclass-cltracker-cookie.php:176
noprivwp_ajax_cltracker_set1pd_cookieclass-cltracker-cookie.php:177
WordPress Hooks 15
actionadmin_menuActionRecorder.php:223
filterplugin_action_linksActionRecorder.php:225
actionadmin_initActionRecorder.php:227
actionwp_headActionRecorder.php:407
actionwp_footerActionRecorder.php:408
actionlogin_headActionRecorder.php:409
actionlogin_footerActionRecorder.php:410
actionwp_loginActionRecorder.php:411
actionuser_registerActionRecorder.php:412
filtercltracker_get_current_user_identifyActionRecorder.php:580
filtercltracker_get_current_user_identifyActionRecorder.php:596
actionplugins_loadedActionRecorder.php:719
actionwoocommerce_add_to_cartintegrations\ecommerce\woocommerce.php:44
actionwoocommerce_remove_cart_itemintegrations\ecommerce\woocommerce.php:45
actionplugins_loadedintegrations\ecommerce\woocommerce.php:497
Maintenance & Trust

CustomerLabs Conversion Tracking for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 29, 2025
PHP min version7.0
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

CustomerLabs Conversion Tracking for WooCommerce Developer Profile

clabsvishnuprasad

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CustomerLabs Conversion Tracking for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/customerlabs-actionrecorder/js/cltracker.min.js/wp-content/plugins/customerlabs-actionrecorder/js/ecommerce.min.js/wp-content/plugins/customerlabs-actionrecorder/css/cltracker.css
Script Paths
/wp-content/plugins/customerlabs-actionrecorder/js/cltracker.min.js/wp-content/plugins/customerlabs-actionrecorder/js/ecommerce.min.js
Version Parameters
customerlabs-actionrecorder/js/cltracker.min.js?ver=customerlabs-actionrecorder/js/ecommerce.min.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Global site tag (gtag.js) - Google Analytics --><!-- End Global site tag (gtag.js) - Google Analytics --><!-- START CustomerLabs Action Recorder --><!-- END CustomerLabs Action Recorder -->+2 more
Data Attributes
data-cl-tracker-settings
JS Globals
clTracker.init
FAQ

Frequently Asked Questions about CustomerLabs Conversion Tracking for WooCommerce