Daisycon Pixel for WooCommerce Security & Risk Analysis

wordpress.org/plugins/daisycon-woocommerce-pixel

Adding Daisycon conversion pixel to WooCommerce

200 active installs v3.0.2 PHP 7.0+ WP 4.8+ Updated Jun 25, 2025
conversion-pixeldaisycondaisycon-woocommerce-pixelpixelwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Daisycon Pixel for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Daisycon Pixel for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The "daisycon-woocommerce-pixel" plugin v3.0.2 exhibits a concerning security posture due to a significant number of unprotected entry points into the WordPress application. The analysis reveals 3 total entry points, with all 3 lacking proper authentication or permission checks. This means any unauthenticated user could potentially interact with these functions, leading to unexpected behavior or information disclosure. While the plugin demonstrates good practices in other areas, such as using prepared statements for most SQL queries (64%) and properly escaping a high percentage of output (91%), these strengths are overshadowed by the critical issue of unprotected entry points.

The code analysis also indicates 2 file operations and 6 external HTTP requests, which, when combined with unprotected entry points, could pose a risk if these operations are mishandled or exposed to malicious input. However, the taint analysis found no critical or high severity unsanitized paths, and there is no recorded vulnerability history for this plugin, which suggests that actively exploited vulnerabilities have not been identified. This lack of a vulnerability history is a positive sign, but it does not negate the immediate risks posed by the identified unprotected entry points.

In conclusion, while the plugin shows positive signs in its handling of SQL queries and output escaping, the presence of multiple unprotected AJAX handlers and a REST API route represents a substantial security weakness. The absence of known vulnerabilities is encouraging, but the plugin's attack surface is currently too exposed. A significant update is recommended to implement proper authentication and capability checks for all identified entry points to mitigate the risk of unauthorized access and potential exploitation.

Key Concerns

  • Unprotected AJAX handlers
  • Unprotected REST API route
  • SQL queries not always prepared
  • Some output not properly escaped
Vulnerabilities
None known

Daisycon Pixel for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Daisycon Pixel for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
7 prepared
Unescaped Output
11
113 escaped
Nonce Checks
6
Capability Checks
1
File Operations
2
External Requests
6
Bundled Libraries
0

SQL Query Safety

64% prepared11 total queries

Output Escaping

91% escaped124 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<class-daisycon-woocommerce-admin> (admin\class-daisycon-woocommerce-admin.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

Daisycon Pixel for WooCommerce Attack Surface

Entry Points3
Unprotected3

AJAX Handlers 2

authwp_ajax_load_matching_domainsincludes\class-daisycon-woocommerce.php:165
authwp_ajax_deactivate_storeincludes\class-daisycon-woocommerce.php:168

REST API Routes 1

GET/wp-json/daisycon-woocommerce/v2/verify-hmac/(?P<hmac>[^/]+)daisycon-woocommerce.php:247
WordPress Hooks 16
actionplugins_loadeddaisycon-woocommerce.php:86
filterplugin_action_linksdaisycon-woocommerce.php:97
actionrest_api_initdaisycon-woocommerce.php:244
actionadmin_enqueue_scriptsincludes\class-daisycon-woocommerce.php:122
actionadmin_enqueue_scriptsincludes\class-daisycon-woocommerce.php:123
actionwoocommerce_product_options_general_product_dataincludes\class-daisycon-woocommerce.php:124
actionwoocommerce_process_product_metaincludes\class-daisycon-woocommerce.php:125
actionwoocommerce_product_quick_edit_endincludes\class-daisycon-woocommerce.php:126
actionwoocommerce_product_quick_edit_saveincludes\class-daisycon-woocommerce.php:127
actionmanage_product_posts_custom_columnincludes\class-daisycon-woocommerce.php:128
actionadmin_initincludes\class-daisycon-woocommerce.php:134
actionadmin_menuincludes\class-daisycon-woocommerce.php:135
actionadmin_noticesincludes\class-daisycon-woocommerce.php:136
actionupdate_optionincludes\class-daisycon-woocommerce.php:137
actionwp_headincludes\class-daisycon-woocommerce.php:151
actionwoocommerce_thankyouincludes\class-daisycon-woocommerce.php:153
Maintenance & Trust

Daisycon Pixel for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 25, 2025
PHP min version7.0
Downloads9K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

Daisycon Pixel for WooCommerce Developer Profile

Daisycon

2 plugins · 600 total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
85 days
View full developer profile
Detection Fingerprints

How We Detect Daisycon Pixel for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/daisycon-woocommerce-pixel/build/frontend.js/wp-content/plugins/daisycon-woocommerce-pixel/build/backend.js/wp-content/plugins/daisycon-woocommerce-pixel/build/vendors.js/wp-content/plugins/daisycon-woocommerce-pixel/build/admin.js
Script Paths
/wp-content/plugins/daisycon-woocommerce-pixel/build/frontend.js/wp-content/plugins/daisycon-woocommerce-pixel/build/backend.js/wp-content/plugins/daisycon-woocommerce-pixel/build/vendors.js/wp-content/plugins/daisycon-woocommerce-pixel/build/admin.js
Version Parameters
daisycon-woocommerce-pixel/build/frontend.js?ver=daisycon-woocommerce-pixel/build/backend.js?ver=daisycon-woocommerce-pixel/build/vendors.js?ver=daisycon-woocommerce-pixel/build/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
daisycon_pixel_trackingdaisycon_tracking_id_placeholder
HTML Comments
Daisycon Pixel for WooCommerceDaisycon Pixel for WooCommerce - SettingsDaisycon Pixel for WooCommerce - Advanced SettingsDaisycon Pixel for WooCommerce - Tracking+1 more
Data Attributes
data-daisycon-order-iddata-daisycon-order-totaldata-daisycon-order-currencydata-daisycon-customer-iddata-daisycon-product-iddata-daisycon-product-name+5 more
JS Globals
daisycon_pixel_data
REST Endpoints
/wp-json/daisycon-woocommerce/v2/verify-hmac
FAQ

Frequently Asked Questions about Daisycon Pixel for WooCommerce