FlexOffers Conversion Tracking Security & Risk Analysis

wordpress.org/plugins/flexoffers-conversion-tracking

FlexOffers is a recognized leader in performance-based marketing. We employ a “one-roof” approach that enables us to work with over 10K advertisers ac …

10 active installs v1.0.8 PHP 8.3+ WP 6.3.2+ Updated Feb 12, 2026
advertiseraffiliateflexofferspublishertracking
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FlexOffers Conversion Tracking Safe to Use in 2026?

Generally Safe

Score 100/100

FlexOffers Conversion Tracking has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The flexoffers-conversion-tracking v1.0.8 plugin demonstrates a generally good security posture in several key areas. It exhibits excellent practices by utilizing prepared statements for all SQL queries and ensuring that all output is properly escaped. The absence of dangerous functions, file operations, and known vulnerabilities in its history are also positive indicators. However, a significant concern arises from the presence of one unprotected REST API route. This single entry point, lacking any permission callbacks, presents a direct pathway for unauthorized access or manipulation if not properly secured at the server level. The static analysis also highlights a total of one unprotected entry point across all categories, specifically attributed to this REST API route. While the absence of critical taint flows and documented CVEs is reassuring, this single unprotected API endpoint represents a notable weakness that could be exploited by attackers to interact with the plugin's functionality without proper authentication or authorization.

Key Concerns

  • Unprotected REST API route
Vulnerabilities
None known

FlexOffers Conversion Tracking Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

FlexOffers Conversion Tracking Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
36 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
6
Bundled Libraries
0

Output Escaping

100% escaped36 total outputs
Attack Surface
1 unprotected

FlexOffers Conversion Tracking Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

GET/wp-json/flextrack-api/v1/order/(?P<id>\d+)flextrack-functions.php:59
WordPress Hooks 7
actionadmin_menuflextrack-functions.php:8
actionadmin_enqueue_scriptsflextrack-functions.php:28
actionrest_api_initflextrack-functions.php:56
actioninitflextrack-functions.php:102
actionwp_headflextrack-functions.php:104
actionwoocommerce_thankyouflextrack-functions.php:106
filterplugin_action_linksflextrack-functions.php:114
Maintenance & Trust

FlexOffers Conversion Tracking Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 12, 2026
PHP min version8.3
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

FlexOffers Conversion Tracking Developer Profile

flexshop

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect FlexOffers Conversion Tracking

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/flexoffers-conversion-tracking/includes/js/flextrack.bootstrap.min.js/wp-content/plugins/flexoffers-conversion-tracking/includes/js/flextrack.bootstrap.bundle.min.js/wp-content/plugins/flexoffers-conversion-tracking/includes/css/flextrack-style.css/wp-content/plugins/flexoffers-conversion-tracking/includes/css/flextrack.bootstrap.min.css
Script Paths
/wp-content/plugins/flexoffers-conversion-tracking/public/flextrack-flexOffers.js
Version Parameters
flextrack-bootstrap-min-js?ver=flextrack-bootstrap-bundle-min-js?ver=flextrack-style-css?ver=flextrack.bootstrap.min.css?ver=flextrack-flexOffers.js?ADVID=

HTML / DOM Fingerprints

CSS Classes
flextrack-order-idflextrack-currencyflextrack-commission-id
Data Attributes
flextrack-order-idflextrack-currencyflextrack-commission-id
JS Globals
FLEXTRACK_API_URLFLEXTRACK_ADVERTISER_PRO_URL
REST Endpoints
/wp-json/flextrack-api/v1/order/
FAQ

Frequently Asked Questions about FlexOffers Conversion Tracking