Pixel Cat – Conversion Pixel Manager Security & Risk Analysis

wordpress.org/plugins/facebook-conversion-pixel

Add Meta & Facebook Pixel, Google Analytics (GA4) and any header script to your site. Everything you need to track users, ads, events & conversions.

40K active installs v3.3.0 PHP + WP 4.0+ Updated Jan 28, 2026
capiconversions-apicustom-audiencesfacebook-pixelmeta-pixel
96
A · Safe
CVEs total4
Unpatched0
Last CVESep 23, 2024
Safety Verdict

Is Pixel Cat – Conversion Pixel Manager Safe to Use in 2026?

Generally Safe

Score 96/100

Pixel Cat – Conversion Pixel Manager has a strong security track record. Known vulnerabilities have been patched promptly.

4 known CVEsLast CVE: Sep 23, 2024Updated 2mo ago
Risk Assessment

The "facebook-conversion-pixel" plugin v3.3.0 exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and performing numerous nonce and capability checks, significant concerns arise from its attack surface and output escaping. The presence of 11 AJAX handlers, with two lacking authentication checks, presents a direct pathway for potential unauthorized actions. Furthermore, the low rate of properly escaped output (33%) suggests a high susceptibility to Cross-Site Scripting (XSS) vulnerabilities, where user-supplied data might be directly rendered in the browser without adequate sanitization. The vulnerability history, with 4 known CVEs including one high and three medium severity, reinforces these concerns. The common vulnerability types identified (XSS and CSRF) align with the risks suggested by the code analysis, particularly the unescaped output and unprotected AJAX endpoints. Although there are currently no unpatched vulnerabilities, the history of past issues indicates a recurring pattern of security weaknesses that require ongoing vigilance and prompt patching.

Overall, the plugin has some strong security foundations, particularly in data handling with prepared statements. However, the unprotected entry points and insufficient output escaping create notable risks. The past vulnerability history, especially the prevalence of XSS and CSRF, strongly suggests that these areas remain points of concern. The plugin is not inherently insecure, but it requires careful monitoring and prompt updates to address the identified weaknesses and prevent future exploitation. The presence of bundled libraries like Select2, while not explicitly flagged as problematic here, should also be a point of consideration for potential outdated versions or vulnerabilities within those components in a more in-depth analysis.

Key Concerns

  • Unprotected AJAX handlers
  • Low rate of properly escaped output
  • High severity vulnerability in history
  • Medium severity vulnerabilities in history (3)
  • Bundled library (Select2)
Vulnerabilities
4

Pixel Cat – Conversion Pixel Manager Security Vulnerabilities

CVEs by Year

3 CVEs in 2021
2021
1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

High
1
Medium
3

4 total CVEs

CVE-2024-8544medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Pixel Cat – Conversion Pixel Manager <= 3.0.5 - Reflected Cross-Site Scripting

Sep 23, 2024 Patched in 3.0.6 (1d)
WF-98be1eb8-ee7d-4a39-b70f-5037b651ba96-facebook-conversion-pixelmedium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Pixel Cat – Conversion Pixel Manager <= 2.6.3 - Reflected Cross-Site Scripting

Nov 18, 2021 Patched in 2.6.4 (796d)
CVE-2021-24972medium · 4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Pixel Cat Lite <= 2.6.2 - Admin+ Stored Cross-Site Scripting

Nov 15, 2021 Patched in 2.6.3 (799d)
CVE-2021-24922high · 8.8Cross-Site Request Forgery (CSRF)

Pixel Cat – Conversion Pixel Manager <= 2.6.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Nov 15, 2021 Patched in 2.6.2 (799d)
Code Analysis
Analyzed Mar 16, 2026

Pixel Cat – Conversion Pixel Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
225
112 escaped
Nonce Checks
7
Capability Checks
2
File Operations
0
External Requests
5
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

33% escaped337 total outputs
Attack Surface
2 unprotected

Pixel Cat – Conversion Pixel Manager Attack Surface

Entry Points11
Unprotected2

AJAX Handlers 11

authwp_ajax_fca_pc_woo_ajax_add_to_cartincludes\api.php:56
noprivwp_ajax_fca_pc_woo_ajax_add_to_cartincludes\api.php:57
authwp_ajax_fca_pc_capi_eventincludes\api.php:85
noprivwp_ajax_fca_pc_capi_eventincludes\api.php:86
authwp_ajax_fca_pc_tiktok_api_eventincludes\api.php:185
noprivwp_ajax_fca_pc_tiktok_api_eventincludes\api.php:186
authwp_ajax_fca_pc_snapchat_api_eventincludes\api.php:266
noprivwp_ajax_fca_pc_snapchat_api_eventincludes\api.php:267
authwp_ajax_fca_pc_pinterest_api_eventincludes\api.php:381
noprivwp_ajax_fca_pc_pinterest_api_eventincludes\api.php:382
authwp_ajax_fca_pc_uninstallincludes\notices\notices.php:182
WordPress Hooks 39
actioninitfacebook-conversion-pixel.php:117
actioninitfacebook-conversion-pixel.php:140
actionadmin_noticesfacebook-conversion-pixel.php:190
actiondeactivated_pluginfacebook-conversion-pixel.php:206
actionadmin_initfacebook-conversion-pixel.php:258
actionadmin_menuincludes\editor\editor.php:20
actionwp_headincludes\functions.php:144
actionamp_post_template_footerincludes\integrations\amp.php:16
actionamp_endincludes\integrations\amp.php:19
actionfca_pc_start_pixel_outputincludes\integrations\edd-events-ga.php:23
actionfca_pc_start_pixel_outputincludes\integrations\edd-events-ga.php:30
actionedd_complete_purchaseincludes\integrations\edd-events-ga.php:41
actionfca_pc_start_pixel_outputincludes\integrations\edd-events.php:26
actionfca_pc_start_pixel_outputincludes\integrations\edd-events.php:44
actionfca_pc_start_pixel_outputincludes\integrations\edd-events.php:51
actionedd_complete_purchaseincludes\integrations\edd-events.php:80
actioninitincludes\integrations\edd-feed.php:124
filterfeed_content_typeincludes\integrations\edd-feed.php:132
actionfca_pc_start_pixel_outputincludes\integrations\ept.php:6
actionfca_pc_start_pixel_outputincludes\integrations\landingpagecat.php:6
actionfca_pc_start_pixel_outputincludes\integrations\optincat.php:6
actionfca_pc_start_pixel_outputincludes\integrations\quizcat.php:6
actionfca_pc_start_pixel_outputincludes\integrations\woo-events-ga.php:28
actionwoocommerce_add_to_cartincludes\integrations\woo-events-ga.php:54
actionfca_pc_start_pixel_outputincludes\integrations\woo-events-ga.php:116
actionfca_pc_start_pixel_outputincludes\integrations\woo-events-ga.php:205
actionfca_pc_start_pixel_outputincludes\integrations\woo-events.php:26
actionwoocommerce_add_to_cartincludes\integrations\woo-events.php:50
actionfca_pc_start_pixel_outputincludes\integrations\woo-events.php:97
actionfca_pc_start_pixel_outputincludes\integrations\woo-events.php:172
actionfca_pc_start_pixel_outputincludes\integrations\woo-events.php:192
actioninitincludes\integrations\woo-feed.php:203
filterfeed_content_typeincludes\integrations\woo-feed.php:211
actionadmin_menuincludes\notices\notices.php:15
actionadmin_noticesincludes\notices\notices.php:102
actionfca_pc_schedule_review_noticeincludes\notices\notices.php:108
actionadmin_enqueue_scriptsincludes\notices\notices.php:148
actionadmin_menuincludes\notices\notices.php:195
actionadmin_footerincludes\notices\notices.php:225

Scheduled Events 2

fca_pc_schedule_review_notice
fca_pc_schedule_review_notice
Maintenance & Trust

Pixel Cat – Conversion Pixel Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 28, 2026
PHP min version
Downloads1.3M

Community Trust

Rating78/100
Number of ratings40
Active installs40K
Developer Profile

Pixel Cat – Conversion Pixel Manager Developer Profile

fatcatapps

13 plugins · 67K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
242 days
View full developer profile
Detection Fingerprints

How We Detect Pixel Cat – Conversion Pixel Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/facebook-conversion-pixel/pixel-cat.js/wp-content/plugins/facebook-conversion-pixel/pixel-cat.min.js
Script Paths
/wp-content/plugins/facebook-conversion-pixel/pixel-cat.js/wp-content/plugins/facebook-conversion-pixel/pixel-cat.min.js
Version Parameters
facebook-conversion-pixel/pixel-cat.js?ver=facebook-conversion-pixel/pixel-cat.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
fca-pc-setup-notice
JS Globals
fca_pc_client_jsfca_pc_settings_pagefca_pc_dismiss_upgrade_infofca_pc_after_upgrade_info
FAQ

Frequently Asked Questions about Pixel Cat – Conversion Pixel Manager