EBOD Tracking Security & Risk Analysis

wordpress.org/plugins/ebod-tracking

The EBOD (Engage-Benefit-On-Demand) WordPress plugin allows you to seamlessly integrate EBOD's engagement-driven rewards system into your WordPre …

0 active installs v1.2.0 PHP 7.4+ WP 5.9+ Updated Dec 1, 2023
ebodengagementloyaltyrewardstoken
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is EBOD Tracking Safe to Use in 2026?

Generally Safe

Score 85/100

EBOD Tracking has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "ebod-tracking" v1.2.0 plugin exhibits a generally strong security posture. The absence of any identified vulnerabilities in its history and the lack of critical or high-severity code signals during static analysis are positive indicators. Specifically, the complete absence of dangerous functions, SQL queries without prepared statements, and improperly escaped output suggests careful development practices in these common vulnerability areas. Furthermore, the plugin does not appear to use bundled libraries, mitigating risks associated with outdated dependencies.

However, several areas present potential concerns that warrant attention. The plugin has zero nonce checks and zero capability checks, which is a significant weakness, especially considering it makes external HTTP requests. While the current attack surface appears minimal (0 entry points without authentication), this could change with future updates. The absence of taint analysis results is also noteworthy; while it might indicate no complex data flows, it could also mean the analysis was not performed comprehensively enough to uncover potential issues with user-supplied data interacting with external requests. The external HTTP requests themselves, without clear authentication or sanitization mechanisms detailed in the analysis, represent a potential vector for the plugin to be influenced by malicious external sources or to leak sensitive information.

In conclusion, "ebod-tracking" v1.2.0 demonstrates good adherence to secure coding principles regarding SQL and output handling. Its clean vulnerability history is a significant strength. However, the complete lack of nonce and capability checks, combined with external HTTP requests, introduces notable security risks that should be addressed to further harden the plugin.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
  • External HTTP requests made
  • No taint analysis results available
Vulnerabilities
None known

EBOD Tracking Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

EBOD Tracking Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

EBOD Tracking Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
12 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped12 total outputs
Attack Surface

EBOD Tracking Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionplugins_loadedincludes\class-ebod.php:142
actionadmin_enqueue_scriptsincludes\class-ebod.php:157
actionadmin_enqueue_scriptsincludes\class-ebod.php:158
actionadmin_menuincludes\class-ebod.php:159
actionadmin_initincludes\class-ebod.php:160
actionwp_enqueue_scriptsincludes\class-ebod.php:174
actionwp_enqueue_scriptsincludes\class-ebod.php:175
actionwoocommerce_order_status_completedincludes\class-ebod.php:178
Maintenance & Trust

EBOD Tracking Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedDec 1, 2023
PHP min version7.4
Downloads850

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

EBOD Tracking Developer Profile

EBOD Digital

2 plugins · 0 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect EBOD Tracking

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ebod-tracking/admin/css/ebod-admin.css/wp-content/plugins/ebod-tracking/admin/js/ebod-admin.js
Script Paths
/wp-content/plugins/ebod-tracking/admin/js/ebod-admin.js
Version Parameters
ebod-tracking/admin/css/ebod-admin.css?ver=ebod-tracking/admin/js/ebod-admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
name="ebod_settings[ebod_apitoken_field]"
FAQ

Frequently Asked Questions about EBOD Tracking