Firevert – Sale booster for WooCommerce Security & Risk Analysis

wordpress.org/plugins/firevert

Boost your WooCommerce sales with smart, customizable promotional widgets.

10 active installs v1.0.3 PHP 7.4+ WP 6.0+ Updated Unknown
countdownpromotionsalessocial-proofwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Firevert – Sale booster for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Firevert – Sale booster for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "firevert" plugin v1.0.3 exhibits a concerning security posture due to a significant attack surface exposed without proper authorization checks. While the plugin demonstrates good practices in output escaping and largely utilizes prepared statements for SQL queries, the fact that all 7 identified REST API routes lack permission callbacks is a critical flaw. This means any unauthenticated user could potentially interact with these endpoints, leading to unintended behavior or data exposure. The absence of taint analysis findings and a clean vulnerability history are positive indicators, suggesting no known critical vulnerabilities and likely sound internal code logic. However, the large number of unprotected entry points overshadows these strengths.

Key Concerns

  • REST API routes without permission callbacks
  • All entry points unprotected
  • SQL queries not always prepared
Vulnerabilities
None known

Firevert – Sale booster for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Firevert – Sale booster for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
4 prepared
Unescaped Output
0
308 escaped
Nonce Checks
5
Capability Checks
8
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

67% prepared6 total queries

Output Escaping

100% escaped308 total outputs
Attack Surface
7 unprotected

Firevert – Sale booster for WooCommerce Attack Surface

Entry Points7
Unprotected7

REST API Routes 7

GET/wp-json/firevert/v1/core/product_categoriessrc\Core\Api\Controller\ProductCategoriesController.php:76
GET/wp-json/firevert/v1/core/productssrc\Core\Api\Controller\ProductsController.php:79
GET/wp-json/firevert/v1/power-widget/mainsrc\Modules\PowerWidget\Api\RenderController.php:55
GET/wp-json/firevert/v1/power-widget/main/productssrc\Modules\PowerWidget\Api\RenderController.php:65
GET/wp-json/firevert/v1/promo-time-widget/mainsrc\Modules\PromoTimeWidget\Api\RenderController.php:55
GET/wp-json/firevert/v1/spectator-views/pingsrc\Modules\SpectatorViews\Api\Controller\PingController.php:56
GET/wp-json/firevert/v1/spectator-views/mainsrc\Modules\SpectatorViews\Api\Controller\RenderController.php:58
WordPress Hooks 55
actionrest_api_initsrc\Core\Api\Controller\ProductCategoriesController.php:67
actionrest_api_initsrc\Core\Api\Controller\ProductsController.php:68
actioninitsrc\Core\Hooks\Admin\AdminCptHook.php:31
actionadmin_initsrc\Core\Hooks\Admin\AdminInitHook.php:28
actionadmin_menusrc\Core\Hooks\Admin\AdminMenuHook.php:43
actionadmin_noticessrc\Core\Hooks\Admin\AdminNoticeHook.php:27
actionsave_post_productsrc\Core\Hooks\Admin\ProductCacheInvalidationHook.php:28
actiondeleted_postsrc\Core\Hooks\Admin\ProductCacheInvalidationHook.php:29
actioncreate_product_catsrc\Core\Hooks\Admin\ProductCategoriesCacheInvalidationHook.php:28
actionedited_product_catsrc\Core\Hooks\Admin\ProductCategoriesCacheInvalidationHook.php:29
actiondelete_product_catsrc\Core\Hooks\Admin\ProductCategoriesCacheInvalidationHook.php:30
actionadmin_enqueue_scriptssrc\Core\Hooks\AssetsHook.php:43
actionwp_enqueue_scriptssrc\Core\Hooks\AssetsHook.php:44
actioninitsrc\Core\ModuleManager.php:70
actionrest_api_initsrc\Modules\PowerWidget\Api\RenderController.php:46
actioninitsrc\Modules\PowerWidget\Hooks\Admin\AdminCptHook.php:33
actionadmin_enqueue_scriptssrc\Modules\PowerWidget\Hooks\Admin\AdminMediaHook.php:28
actionadmin_post_firevert_save_power_widgetsrc\Modules\PowerWidget\Hooks\Admin\AdminSaveHook.php:31
actionsave_post_productsrc\Modules\PowerWidget\Hooks\Admin\ProductCacheInvalidationHook.php:29
actiondeleted_postsrc\Modules\PowerWidget\Hooks\Admin\ProductCacheInvalidationHook.php:30
actionrest_api_initsrc\Modules\PromoTimeWidget\Api\RenderController.php:46
actioninitsrc\Modules\PromoTimeWidget\Hooks\Admin\AdminCptHook.php:33
actionadmin_post_firevert_save_promo_time_widgetsrc\Modules\PromoTimeWidget\Hooks\Admin\AdminSaveHook.php:31
actionwpsrc\Modules\PromoTimeWidget\Hooks\Frontend\FrontendRenderHook.php:44
actionwoocommerce_after_add_to_cart_buttonsrc\Modules\PromoTimeWidget\Hooks\Frontend\FrontendRenderHook.php:61
actionwoocommerce_before_add_to_cart_formsrc\Modules\PromoTimeWidget\Hooks\Frontend\FrontendRenderHook.php:65
actionwoocommerce_before_variations_formsrc\Modules\PromoTimeWidget\Hooks\Frontend\FrontendRenderHook.php:69
actionwoocommerce_before_add_to_cart_buttonsrc\Modules\PromoTimeWidget\Hooks\Frontend\FrontendRenderHook.php:73
actionwoocommerce_before_single_variationsrc\Modules\PromoTimeWidget\Hooks\Frontend\FrontendRenderHook.php:77
actionwoocommerce_before_add_to_cart_quantitysrc\Modules\PromoTimeWidget\Hooks\Frontend\FrontendRenderHook.php:81
actionwoocommerce_after_add_to_cart_quantitysrc\Modules\PromoTimeWidget\Hooks\Frontend\FrontendRenderHook.php:85
actionwoocommerce_after_variations_formsrc\Modules\PromoTimeWidget\Hooks\Frontend\FrontendRenderHook.php:89
actionwoocommerce_after_add_to_cart_formsrc\Modules\PromoTimeWidget\Hooks\Frontend\FrontendRenderHook.php:93
actionwoocommerce_product_meta_startsrc\Modules\PromoTimeWidget\Hooks\Frontend\FrontendRenderHook.php:97
actionwoocommerce_product_meta_endsrc\Modules\PromoTimeWidget\Hooks\Frontend\FrontendRenderHook.php:101
actionwoocommerce_after_single_product_summarysrc\Modules\PromoTimeWidget\Hooks\Frontend\FrontendRenderHook.php:105
actionrest_api_initsrc\Modules\SpectatorViews\Api\Controller\PingController.php:47
actionrest_api_initsrc\Modules\SpectatorViews\Api\Controller\RenderController.php:49
actioninitsrc\Modules\SpectatorViews\Hooks\Admin\AdminCptHook.php:33
actionadmin_post_firevert_save_spectator_viewssrc\Modules\SpectatorViews\Hooks\Admin\AdminSaveHook.php:31
actionwpsrc\Modules\SpectatorViews\Hooks\Frontend\FrontendRenderHook.php:44
actionwoocommerce_after_add_to_cart_buttonsrc\Modules\SpectatorViews\Hooks\Frontend\FrontendRenderHook.php:61
actionwoocommerce_before_add_to_cart_formsrc\Modules\SpectatorViews\Hooks\Frontend\FrontendRenderHook.php:65
actionwoocommerce_before_variations_formsrc\Modules\SpectatorViews\Hooks\Frontend\FrontendRenderHook.php:69
actionwoocommerce_before_add_to_cart_buttonsrc\Modules\SpectatorViews\Hooks\Frontend\FrontendRenderHook.php:73
actionwoocommerce_before_single_variationsrc\Modules\SpectatorViews\Hooks\Frontend\FrontendRenderHook.php:77
actionwoocommerce_before_add_to_cart_quantitysrc\Modules\SpectatorViews\Hooks\Frontend\FrontendRenderHook.php:81
actionwoocommerce_after_add_to_cart_quantitysrc\Modules\SpectatorViews\Hooks\Frontend\FrontendRenderHook.php:85
actionwoocommerce_after_variations_formsrc\Modules\SpectatorViews\Hooks\Frontend\FrontendRenderHook.php:89
actionwoocommerce_after_add_to_cart_formsrc\Modules\SpectatorViews\Hooks\Frontend\FrontendRenderHook.php:93
actionwoocommerce_product_meta_startsrc\Modules\SpectatorViews\Hooks\Frontend\FrontendRenderHook.php:97
actionwoocommerce_product_meta_endsrc\Modules\SpectatorViews\Hooks\Frontend\FrontendRenderHook.php:101
actionwoocommerce_after_single_product_summarysrc\Modules\SpectatorViews\Hooks\Frontend\FrontendRenderHook.php:105
actiontemplate_redirectsrc\Modules\SpectatorViews\Hooks\Frontend\FrontendSpectatorTrackingHook.php:43
actionadmin_noticessystem.php:188
Maintenance & Trust

Firevert – Sale booster for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.4
Downloads474

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Firevert – Sale booster for WooCommerce Developer Profile

ilabs

7 plugins · 17K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Firevert – Sale booster for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/firevert/css/admin.min.css/wp-content/plugins/firevert/js/admin.min.js/wp-content/plugins/firevert/css/frontend.min.css/wp-content/plugins/firevert/js/frontend.min.js
Script Paths
/wp-content/plugins/firevert/js/admin.min.js/wp-content/plugins/firevert/js/frontend.min.js
Version Parameters
firevert/css/admin.min.css?ver=firevert/js/admin.min.js?ver=firevert/css/frontend.min.css?ver=firevert/js/frontend.min.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Firevert – Sale booster for WooCommerce