Everlytic for WooCommerce Security & Risk Analysis

wordpress.org/plugins/everlytic

Connect your store to Everlytic for E-Commerce

30 active installs v1.8.4 PHP 7.0+ WP 4.9+ Updated Jul 23, 2025
ecommerceemailevelyticworkflows
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Everlytic for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Everlytic for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The "everlytic" plugin version 1.8.4 presents a mixed security posture. On the positive side, it has no recorded vulnerability history, suggesting a generally stable codebase or good patching practices in the past. The static analysis also shows a high percentage of properly escaped outputs and a reasonable usage of prepared statements for SQL queries. However, significant security concerns arise from the attack surface analysis. The plugin exposes a single AJAX handler that lacks any authentication checks, making it a direct entry point for unauthenticated users. Furthermore, the taint analysis reveals two flows with high severity, indicating potential vulnerabilities where unsanitized data could lead to security issues, although their exact nature is not detailed in the provided data. The absence of nonce checks on the unprotected AJAX handler exacerbates this risk.

Key Concerns

  • Unprotected AJAX handler
  • High severity taint flows
  • Missing nonce checks on AJAX
  • SQL queries not fully prepared
Vulnerabilities
None known

Everlytic for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Everlytic for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
10
5 prepared
Unescaped Output
1
7 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
7
Bundled Libraries
0

SQL Query Safety

33% prepared15 total queries

Output Escaping

88% escaped8 total outputs
Data Flows
6 unsanitized

Data Flow Analysis

6 flows6 with unsanitized paths
hydrate (src\Events\AbandonedCart\EvAbandonedCartHydrator.php:15)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Everlytic for WooCommerce Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_update_syncsrc\EverlyticWoocommerce.php:157
WordPress Hooks 19
actionwoocommerce_add_to_cartsrc\Events\AbandonedCart\EvCartLogger.php:22
actionwoocommerce_cart_item_removedsrc\Events\AbandonedCart\EvCartLogger.php:23
actionwoocommerce_after_cart_item_quantity_updatesrc\Events\AbandonedCart\EvCartLogger.php:24
actionwoocommerce_thankyousrc\Events\AbandonedCart\EvCartLogger.php:25
actioninitsrc\EverlyticWoocommerce.php:154
actionwoocommerce_before_single_productsrc\EverlyticWoocommerce.php:155
actionwoocommerce_order_status_completedsrc\EverlyticWoocommerce.php:156
actioninitsrc\EverlyticWoocommerce.php:158
actionev_user_sync_schedulersrc\EverlyticWoocommerce.php:159
actioninitsrc\EverlyticWoocommerce.php:160
actionev_abandoned_cart_schedulersrc\EverlyticWoocommerce.php:161
actiontemplate_redirectsrc\EverlyticWoocommerce.php:162
actiontemplate_redirectsrc\EverlyticWoocommerce.php:163
actionrest_api_initsrc\EverlyticWoocommerce.php:164
actionwpsrc\EverlyticWoocommerce.php:165
filterwoocommerce_product_data_store_cpt_get_products_querysrc\EverlyticWoocommerce.php:166
actionwoocommerce_created_customersrc\EverlyticWoocommerce.php:167
actionadmin_menusrc\Settings\EvSettings.php:7
actionadmin_enqueue_scriptssrc\Settings\EvSettings.php:8
Maintenance & Trust

Everlytic for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 23, 2025
PHP min version7.0
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Everlytic for WooCommerce Developer Profile

ade1705

1 plugin · 30 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Everlytic for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/everlytic/public/css/ev-bootstrap.min.css/wp-content/plugins/everlytic/public/css/ev-style.css

HTML / DOM Fingerprints

CSS Classes
evConnectedMessagebg-dangerbg-evcheck-contact-sync
Data Attributes
id="evRefreshConnection"id="evSendSampleAbandonedCart"id="evConnectedButton"id="evLoadingMessage"
JS Globals
checkConnectionhandleConnectionStatussendSampleAbandonedCart
REST Endpoints
/everlytic/v1/ping
FAQ

Frequently Asked Questions about Everlytic for WooCommerce