Logic Hop ConvertKit Add-on Security & Risk Analysis

wordpress.org/plugins/logic-hop-convertkit-add-on

The Logic Hop ConvertKit Add-on brings the power of personalization to WordPress with ConvertKit.

0 active installs v3.0.2 PHP 5.6+ WP 4.8.0+ Updated Unknown
convertkitlogic-hoppersonalizationpersonalized-contentpersonalized-marketing
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Logic Hop ConvertKit Add-on Safe to Use in 2026?

Generally Safe

Score 100/100

Logic Hop ConvertKit Add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "logic-hop-convertkit-add-on" plugin v3.0.2 exhibits a generally good security posture, with several positive indicators. The absence of known vulnerabilities, critical or high taint flows, and SQL queries without prepared statements are strong points. Furthermore, the plugin demonstrates good practices in output escaping for most of its outputs. The limited attack surface, with only one shortcode and no unprotected entry points, is also a positive sign.

However, there are areas for concern. The analysis reveals a lack of capability checks and nonce checks, which are crucial for securing WordPress actions against unauthorized access and CSRF attacks. The presence of unsanitized paths in taint flows, even if not categorized as critical or high, indicates a potential risk for path traversal or file manipulation vulnerabilities. The plugin also makes a significant number of external HTTP requests, which could be a vector for various attacks if not handled securely. The vulnerability history being clean is positive, but it does not negate the risks identified in the static analysis, especially given the missing security checks.

In conclusion, while the plugin has a clean history and some good coding practices, the absence of critical security mechanisms like capability and nonce checks, coupled with unsanitized paths, presents a tangible risk. The plugin is recommended for use with caution, and further investigation into the external HTTP requests and taint flows would be prudent.

Key Concerns

  • No capability checks found
  • No nonce checks found
  • 2 flows with unsanitized paths
  • 9 external HTTP requests
  • 2 out of 11 outputs not properly escaped
Vulnerabilities
None known

Logic Hop ConvertKit Add-on Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Logic Hop ConvertKit Add-on Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
9
Bundled Libraries
0

Output Escaping

91% escaped11 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
data_check (includes\convertkit.php:97)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Logic Hop ConvertKit Add-on Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[logichop_data_ck] logichop_convertkit.php:568
WordPress Hooks 23
actionadmin_noticeslogichop_convertkit.php:16
actionlogichop_admin_noticelogichop_convertkit.php:73
actionlogichop_initialize_core_data_checklogichop_convertkit.php:101
actionlogichop_data_retrievelogichop_convertkit.php:102
actionlogichop_check_track_eventlogichop_convertkit.php:103
filterlogichop_data_object_createlogichop_convertkit.php:104
filterlogichop_condition_default_getlogichop_convertkit.php:105
filterlogichop_client_meta_integrationslogichop_convertkit.php:106
filterlogichop_settings_registerlogichop_convertkit.php:107
filterlogichop_settings_validatelogichop_convertkit.php:108
filterlogichop_editor_shortcode_variableslogichop_convertkit.php:109
filterlogichop_gutenberg_variableslogichop_convertkit.php:110
actionlogichop_configure_metaboxeslogichop_convertkit.php:111
actionlogichop_event_savelogichop_convertkit.php:112
filterlogichop_condition_builder_varslogichop_convertkit.php:113
actionlogichop_admin_enqueue_styleslogichop_convertkit.php:114
actionlogichop_admin_enqueue_scriptslogichop_convertkit.php:115
actionlogichop_public_enqueue_scriptslogichop_convertkit.php:116
actionlogichop_admin_menu_pageslogichop_convertkit.php:117
actionlogichop_admin_settings_tabslogichop_convertkit.php:118
actionlogichop_admin_settings_pagelogichop_convertkit.php:119
actionlogichop_register_shortcodeslogichop_convertkit.php:120
actionlogichop_integration_initlogichop_convertkit.php:123
Maintenance & Trust

Logic Hop ConvertKit Add-on Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedUnknown
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Logic Hop ConvertKit Add-on Developer Profile

Logic Hop

12 plugins · 190 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Logic Hop ConvertKit Add-on

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/logic-hop-convertkit-add-on/assets/css/logichop-convertkit-admin.css/wp-content/plugins/logic-hop-convertkit-add-on/assets/css/logichop-convertkit-public.css/wp-content/plugins/logic-hop-convertkit-add-on/assets/js/logichop-convertkit-admin.js/wp-content/plugins/logic-hop-convertkit-add-on/assets/js/logichop-convertkit-public.js
Script Paths
/wp-content/plugins/logic-hop-convertkit-add-on/assets/js/logichop-convertkit-admin.js/wp-content/plugins/logic-hop-convertkit-add-on/assets/js/logichop-convertkit-public.js
Version Parameters
logic-hop-convertkit-add-on/assets/css/logichop-convertkit-admin.css?ver=logic-hop-convertkit-add-on/assets/css/logichop-convertkit-public.css?ver=logic-hop-convertkit-add-on/assets/js/logichop-convertkit-admin.js?ver=logic-hop-convertkit-add-on/assets/js/logichop-convertkit-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
logichop-convertkit-adminlogichop-convertkit-public
HTML Comments
<!-- The Logic Hop ConvertKit Add-on requires the Logic Hop plugin. Please download and activate the Logic Hop plugin. --><!-- The Logic Hop ConvertKit Add-on requires a Logic Hop License Key or Data Plan. -->
JS Globals
logichop_convertkit_admin_paramslogichop_convertkit_public_params
FAQ

Frequently Asked Questions about Logic Hop ConvertKit Add-on