Embed Code for WooCommerce Security & Risk Analysis

wordpress.org/plugins/embed-code-for-woo

A lightweight plugin to embed tracking codes, scripts, pixels etc. on WooCommerce pages.

0 active installs v0.0.1 PHP 5.2.4+ WP 4.0+ Updated May 29, 2020
codeembedpixelscripttracking
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Embed Code for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Embed Code for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "embed-code-for-woo" v0.0.1 plugin exhibits a concerning security posture primarily due to a complete lack of output escaping. While the static analysis indicates no direct vulnerabilities such as dangerous functions, SQL injection risks, or tainted data flows, the absence of proper output escaping is a significant weakness. This means that any data rendered by the plugin, even if it's seemingly benign, could potentially be manipulated to inject malicious code like JavaScript, leading to Cross-Site Scripting (XSS) vulnerabilities. The plugin's limited attack surface and perfect score for prepared SQL statements are positive aspects, but they are overshadowed by the critical issue of unescaped output. Furthermore, the absence of any recorded vulnerability history, while seemingly good, offers no reassurance about the plugin's long-term security or the diligence of its maintenance. In conclusion, the plugin has a fundamental flaw that exposes it to XSS attacks, despite other seemingly secure coding practices and a clean historical record. This plugin should be considered high risk until the output escaping issue is addressed.

Key Concerns

  • All output is unescaped
  • No capability checks on entry points
  • No nonce checks on AJAX handlers
Vulnerabilities
None known

Embed Code for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Embed Code for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped12 total outputs
Attack Surface

Embed Code for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuwoocommerce-embed-code-settings.php:8
actionadmin_initwoocommerce-embed-code-settings.php:16
actionwp_headwoocommerce-embed-code.php:30
actionwp_footerwoocommerce-embed-code.php:34
Maintenance & Trust

Embed Code for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedMay 29, 2020
PHP min version5.2.4
Downloads951

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Embed Code for WooCommerce Developer Profile

SiD

3 plugins · 2K total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Embed Code for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Embed Code for WooCommerce