Easy WooCommerce Tracking Code Free Security & Risk Analysis

wordpress.org/plugins/easy-woocommerce-tracking-code-free

Con Easy WooCommerce Tracking Code Free è possibile inserire all'interno di un ordinativo WooCommerce, il numero di tracking code.

20 active installs v1.2.4 PHP + WP 3.5+ Updated Mar 5, 2026
spedizionespedizionitracking-code-woocommercewoocommerce-trackingwoocommerce-tracking-code
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Easy WooCommerce Tracking Code Free Safe to Use in 2026?

Generally Safe

Score 100/100

Easy WooCommerce Tracking Code Free has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "easy-woocommerce-tracking-code-free" plugin v1.2.4 exhibits a generally positive security posture based on the provided static analysis. There are no identified CVEs or past vulnerabilities, indicating a history of secure development or diligent patching. The attack surface is notably clean, with zero AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication or permission checks. This significantly reduces the potential entry points for attackers.

However, the static analysis does reveal some areas for concern. The plugin utilizes two SQL queries without prepared statements, which could be a vector for SQL injection if the data used in these queries is not rigorously sanitized and validated. While no taint analysis flagged critical or high-severity issues, the presence of raw SQL is a persistent risk. Furthermore, only 62% of output escaping is proper, leaving a portion of the output potentially vulnerable to cross-site scripting (XSS) attacks. The plugin also makes an external HTTP request, which, if not handled securely, could be exploited for various attacks. The lack of capability checks on all entry points, although the entry points themselves are zero, is a minor concern regarding broader WordPress security best practices.

In conclusion, the plugin benefits from a very small attack surface and no historical vulnerabilities. The primary weaknesses lie in the implementation of its SQL queries and output escaping, along with the external HTTP request. Addressing these specific code-level issues would further strengthen its security. The overall security is good, but the potential for SQL injection and XSS due to unhandled data remains the most significant risk.

Key Concerns

  • SQL queries without prepared statements
  • Low percentage of properly escaped output
  • External HTTP requests
Vulnerabilities
None known

Easy WooCommerce Tracking Code Free Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Easy WooCommerce Tracking Code Free Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
33
54 escaped
Nonce Checks
5
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

PHPMailer

SQL Query Safety

0% prepared2 total queries

Output Escaping

62% escaped87 total outputs
Data Flows
All sanitized

Data Flow Analysis

8 flows
easy_woocommerce_tracking_code_send (templates\email-send-settings.php:5)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Easy WooCommerce Tracking Code Free Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionadmin_print_scriptseasy-woocommerce-tracking-code-free.php:87
actionadmin_menueasy-woocommerce-tracking-code-free.php:161
actionplugins_loadedincludes\class-easy-woocommerce-tracking-code-free.php:142
actionadmin_enqueue_scriptsincludes\class-easy-woocommerce-tracking-code-free.php:157
actionadmin_enqueue_scriptsincludes\class-easy-woocommerce-tracking-code-free.php:158
actionwp_enqueue_scriptsincludes\class-easy-woocommerce-tracking-code-free.php:173
actionwp_enqueue_scriptsincludes\class-easy-woocommerce-tracking-code-free.php:174
filtermanage_edit-shop_order_columnsmetaboxes\order-columns.php:6
filtermanage_edit-shop_order_columnsmetaboxes\order-columns.php:17
actionmanage_shop_order_posts_custom_columnmetaboxes\order-columns.php:35
actionadd_meta_boxesmetaboxes\order-meta-box.php:5
actionwoocommerce_process_shop_order_metametaboxes\order-meta-box.php:98
actionadd_couriertemplates\couriers-settings.php:86
actionadd_email_send_settingstemplates\email-send-settings.php:150
actionadd_email_text_settingstemplates\email-text-settings.php:154
actionadd_general_settingstemplates\general-settings.php:125
Maintenance & Trust

Easy WooCommerce Tracking Code Free Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 5, 2026
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs20
Developer Profile

Easy WooCommerce Tracking Code Free Developer Profile

cosmocode

2 plugins · 120 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Easy WooCommerce Tracking Code Free

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easy-woocommerce-tracking-code-free/assets/css/tracking-code-admin.css/wp-content/plugins/easy-woocommerce-tracking-code-free/assets/js/tracking-code-admin.js
Script Paths
/wp-content/plugins/easy-woocommerce-tracking-code-free/assets/js/tracking-code-admin.js
Version Parameters
easy-woocommerce-tracking-code-free/assets/css/tracking-code-admin.css?ver=easy-woocommerce-tracking-code-free/assets/js/tracking-code-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
tracking-code-courier-wrapper
HTML Comments
<!-- Tracking Code Meta Box --><!-- Tracking Code Admin Area --><!-- Tracking Code Settings Page --><!-- Tracking Code Email Settings Page -->
Data Attributes
data-tracking-code-id
FAQ

Frequently Asked Questions about Easy WooCommerce Tracking Code Free