Instant Conversion Analytics – User Analytics Directly Inside Emails Sent From Your Website Security & Risk Analysis

wordpress.org/plugins/instant-conversion-analytics

This plugin adds user's analytics in emails sent from Contact Form 7, Ninja Forms, WPForms, and WooCommerce.

10 active installs v1.4.3 PHP 5.6+ WP 5.4+ Updated Nov 30, 2024
contact-form-7ninja-formsuser-trackingwoocommercewpforms
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Instant Conversion Analytics – User Analytics Directly Inside Emails Sent From Your Website Safe to Use in 2026?

Generally Safe

Score 92/100

Instant Conversion Analytics – User Analytics Directly Inside Emails Sent From Your Website has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The static analysis of "instant-conversion-analytics" v1.4.3 reveals a plugin with a seemingly minimal attack surface. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits potential entry points for attackers. Furthermore, the code signals indicate no dangerous functions, all SQL queries are properly prepared, and there are no file operations or external HTTP requests. This suggests a generally good security posture in these critical areas.

However, a notable concern is the output escaping. With 56% of outputs properly escaped out of a total of 9, there's a significant portion that remains unescaped. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully when displayed. The absence of nonce checks and capability checks on entry points, while the attack surface is currently zero, represents a potential weakness if new entry points are introduced without proper security controls. The plugin also has no recorded vulnerability history, which is a positive indicator, but it's important to remember that past security performance does not guarantee future immunity.

In conclusion, "instant-conversion-analytics" v1.4.3 demonstrates strengths in areas like SQL sanitization and a lack of dangerous functions. The absence of external dependencies and file operations is also a positive. The primary weakness identified is the moderate rate of unescaped output, which warrants attention. The lack of security checks on potential entry points, though currently not exploitable due to their absence, is a latent risk.

Key Concerns

  • Unescaped output on 4 out of 9 outputs
Vulnerabilities
None known

Instant Conversion Analytics – User Analytics Directly Inside Emails Sent From Your Website Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Instant Conversion Analytics – User Analytics Directly Inside Emails Sent From Your Website Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

56% escaped9 total outputs
Attack Surface

Instant Conversion Analytics – User Analytics Directly Inside Emails Sent From Your Website Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionadmin_initica.php:14
actionadmin_menuica.php:15
actionwp_enqueue_scriptsica.php:16
filterplugin_action_linksica.php:19
filterscript_loader_tagica.php:20
actionadmin_initica.php:75
filterplugin_row_metaica.php:96
filterwpcf7_special_mail_tagsincludes\integrations.php:13
actionwpcf7_before_send_mailincludes\integrations.php:36
filterninja_forms_action_email_messageincludes\integrations.php:52
actionwoocommerce_checkout_update_order_metaincludes\integrations.php:64
actionwoocommerce_email_customer_detailsincludes\integrations.php:78
actionwoocommerce_email_footer_textincludes\integrations.php:100
filterwpforms_smart_tagsincludes\integrations.php:108
filterwpforms_smart_tag_processincludes\integrations.php:123
filterwpforms_email_messageincludes\integrations.php:139
Maintenance & Trust

Instant Conversion Analytics – User Analytics Directly Inside Emails Sent From Your Website Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 30, 2024
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Instant Conversion Analytics – User Analytics Directly Inside Emails Sent From Your Website Developer Profile

Daniel Chase

1 plugin · 10 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Instant Conversion Analytics – User Analytics Directly Inside Emails Sent From Your Website

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/instant-conversion-analytics/js/ica.min.js
Script Paths
/wp-content/plugins/instant-conversion-analytics/js/ica.min.js
Version Parameters
instant-conversion-analytics/js/ica.min.js?ver=instant-conversion-analytics

HTML / DOM Fingerprints

HTML Comments
Instant Conversion AnalyticsUpdated in Version 1.4.1Prevent Direct AccessThe Plugin Core+1 more
Data Attributes
ica_cookie_value
JS Globals
Instant_Conversion_Analytics
FAQ

Frequently Asked Questions about Instant Conversion Analytics – User Analytics Directly Inside Emails Sent From Your Website