
Conversios: Google Analytics (GA4), Google Ads, Conversion and Analytics Tracking for Multi-Channels Security & Risk Analysis
wordpress.org/plugins/enhanced-e-commerce-for-woocommerce-storeTrack GA4 Analytics, Google Ads, Microsoft Ads, & Conversion with server-side tracking (CAPI) & product feed to improve ROAS, reports for WooCommerce.
Is Conversios: Google Analytics (GA4), Google Ads, Conversion and Analytics Tracking for Multi-Channels Safe to Use in 2026?
Generally Safe
Score 88/100Conversios: Google Analytics (GA4), Google Ads, Conversion and Analytics Tracking for Multi-Channels has a strong security track record. Known vulnerabilities have been patched promptly.
The "enhanced-e-commerce-for-woocommerce-store" plugin version 7.2.15 exhibits a mixed security posture. While it demonstrates strong adherence to secure coding practices with a high percentage of properly escaped output and prepared SQL statements, several areas raise significant concerns. The presence of a single AJAX handler without authentication checks presents a direct entry point for unauthorized actions, a critical oversight. Furthermore, the taint analysis revealing a high-severity flow with unsanitized paths indicates a potential for vulnerabilities that could be exploited to compromise data or system integrity. The plugin's history of 10 known CVEs, including several high-severity ones, although currently unpatched, points to a recurring pattern of security weaknesses, particularly in authorization, SQL injection, XSS, and CSRF. This suggests a need for more robust security review throughout the development lifecycle.
Despite these concerning findings, the plugin does implement nonce checks on a substantial number of its entry points and utilizes capability checks, which are positive security measures. The relatively low number of unprotected entry points compared to the total attack surface is also a favorable aspect. However, the identified vulnerabilities in the taint analysis and the historical data of past exploitable issues, particularly the high number of high and medium severity CVEs, outweigh these strengths, demanding careful attention from users and developers alike to mitigate potential risks.
Key Concerns
- AJAX handler without authentication check
- High severity taint flow with unsanitized paths
- Vulnerability history: 3 high severity CVEs
- Vulnerability history: 7 medium severity CVEs
- Bundled library: DataTables (potential version issues)
- Bundled library: Select2 (potential version issues)
Conversios: Google Analytics (GA4), Google Ads, Conversion and Analytics Tracking for Multi-Channels Security Vulnerabilities
CVEs by Year
Severity Breakdown
10 total CVEs
Conversios.io <= 7.2.13 - Missing Authorization
Conversios.io <= 7.2.3 - Missing Authorization
Conversios.io - All-in-one Google Analytics, Pixels and Product Feed Manager for WooCommerce <= 7.1.0 - Reflected Cross-Site Scripting
Conversios.io <= 6.9.1 - Reflected Cross-Site Scripting
Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce <= 7.0.7 - Authenticated (Subscriber+) SQL Injection
Conversios <= 7.0.7 - Authenticated (Subscriber+) SQL Injection via ee_syncProductCategory
Conversios.io <= 6.5.0 - Missing Authorization
Conversios.io <= 6.5.3 - Reflected Cross-Site Scripting
All-in-one Google Analytics, Pixels and Product Feed Manager for WooCommerce <= 5.2.3 - Cross-Site Request Forgery
Conversios.io - Google Analytics and Google Shopping plugin for WooCommerce <= 4.6.1 Authenticated SQL Injection
Conversios: Google Analytics (GA4), Google Ads, Conversion and Analytics Tracking for Multi-Channels Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Conversios: Google Analytics (GA4), Google Ads, Conversion and Analytics Tracking for Multi-Channels Attack Surface
AJAX Handlers 43
WordPress Hooks 79
Maintenance & Trust
Conversios: Google Analytics (GA4), Google Ads, Conversion and Analytics Tracking for Multi-Channels Maintenance & Trust
Maintenance Signals
Community Trust
Conversios: Google Analytics (GA4), Google Ads, Conversion and Analytics Tracking for Multi-Channels Alternatives
Pixel Manager for WooCommerce – Conversion Tracking, Google Ads, GA4, TikTok, Dynamic Remarketing
woocommerce-google-adwords-conversion-tracking-tag
Conversion tracking for WooCommerce. Google Ads, GA4, Meta/Facebook Pixel, TikTok & more. Recover 30% more conversions with server-side tracking!
Pixel Tag Manager for WooCommerce – Google Analytics 4, Google Ads, and More Pixels
pixel-manager-for-woocommerce
Pixel Tag Manager for WooCommerce is a powerful plugin to monitor eCommerce events with seamless integration. Track Google Analytics 4, Google Ads, Bi …
Pixelavo – Server Side Tracking & Pixel + AI Ads Tools
pixelavo
Add pixel tracking to your WordPress site with Conversions API, server-side tracking, AI ad copy generation, and AI marketing consultant.
CustomerLabs Conversion Tracking for WooCommerce
customerlabs-actionrecorder
WooCommerce conversion tracking for Google Ads, Meta & GA4. Automatic events, enhanced conversions. CustomerLabs CDP - no code!
TrackSharp: Server-Side GA4 Tracking + Attribution Audit for WooCommerce
tracksharp
Secure server-side GA4 tracking for WooCommerce + a built-in Audit Dashboard to detect Google Ads & Meta attribution risks.
Conversios: Google Analytics (GA4), Google Ads, Conversion and Analytics Tracking for Multi-Channels Developer Profile
1 plugin · 10K total installs
How We Detect Conversios: Google Analytics (GA4), Google Ads, Conversion and Analytics Tracking for Multi-Channels
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/enhanced-e-commerce-for-woocommerce-store/assets/css/custom.css/wp-content/plugins/enhanced-e-commerce-for-woocommerce-store/assets/css/style.css/wp-content/plugins/enhanced-e-commerce-for-woocommerce-store/assets/images/tvc-icon.svg/wp-content/plugins/enhanced-e-commerce-for-woocommerce-store/assets/js/admin-scripts.js/wp-content/plugins/enhanced-e-commerce-for-woocommerce-store/assets/js/frontend-scripts.js/wp-content/plugins/enhanced-e-commerce-for-woocommerce-store/assets/js/ga4-frontend-script.js/wp-content/plugins/enhanced-e-commerce-for-woocommerce-store/assets/js/script.jsConversios.io - All-in-one Google Analytics, Pixels and Product Feed Manager for WooCommerce/wp-content/plugins/enhanced-e-commerce-for-woocommerce-store/assets/js/admin-scripts.js/wp-content/plugins/enhanced-e-commerce-for-woocommerce-store/assets/js/frontend-scripts.js/wp-content/plugins/enhanced-e-commerce-for-woocommerce-store/assets/js/ga4-frontend-script.js/wp-content/plugins/enhanced-e-commerce-for-woocommerce-store/assets/js/script.jsenhanced-e-commerce-for-woocommerce-store/assets/css/custom.css?ver=enhanced-e-commerce-for-woocommerce-store/assets/css/style.css?ver=enhanced-e-commerce-for-woocommerce-store/assets/js/admin-scripts.js?ver=enhanced-e-commerce-for-woocommerce-store/assets/js/frontend-scripts.js?ver=enhanced-e-commerce-for-woocommerce-store/assets/js/ga4-frontend-script.js?ver=enhanced-e-commerce-for-woocommerce-store/assets/js/script.js?ver=HTML / DOM Fingerprints
conversios-dashbordconversios-iconconversios-icon-bigconversios-layout<!-- plugin: enhanced-e-commerce-for-woocommerce-store --><!-- Default WooCommerce plugin -->data-tvc-settingsconversios_dataeec_ga4_settingseec_gtag_paramsgtag_report_conversion/wp-json/conversios/v1/get_product_id_data/wp-json/conversios/v1/get_all_product_data/wp-json/conversios/v1/get_settings