
Logic Hop ConvertKit Add-on Security & Risk Analysis
wordpress.org/plugins/logic-hop-convertkit-add-onThe Logic Hop ConvertKit Add-on brings the power of personalization to WordPress with ConvertKit.
Is Logic Hop ConvertKit Add-on Safe to Use in 2026?
Generally Safe
Score 100/100Logic Hop ConvertKit Add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "logic-hop-convertkit-add-on" plugin v3.0.2 exhibits a generally good security posture, with several positive indicators. The absence of known vulnerabilities, critical or high taint flows, and SQL queries without prepared statements are strong points. Furthermore, the plugin demonstrates good practices in output escaping for most of its outputs. The limited attack surface, with only one shortcode and no unprotected entry points, is also a positive sign.
However, there are areas for concern. The analysis reveals a lack of capability checks and nonce checks, which are crucial for securing WordPress actions against unauthorized access and CSRF attacks. The presence of unsanitized paths in taint flows, even if not categorized as critical or high, indicates a potential risk for path traversal or file manipulation vulnerabilities. The plugin also makes a significant number of external HTTP requests, which could be a vector for various attacks if not handled securely. The vulnerability history being clean is positive, but it does not negate the risks identified in the static analysis, especially given the missing security checks.
In conclusion, while the plugin has a clean history and some good coding practices, the absence of critical security mechanisms like capability and nonce checks, coupled with unsanitized paths, presents a tangible risk. The plugin is recommended for use with caution, and further investigation into the external HTTP requests and taint flows would be prudent.
Key Concerns
- No capability checks found
- No nonce checks found
- 2 flows with unsanitized paths
- 9 external HTTP requests
- 2 out of 11 outputs not properly escaped
Logic Hop ConvertKit Add-on Security Vulnerabilities
Logic Hop ConvertKit Add-on Code Analysis
Output Escaping
Data Flow Analysis
Logic Hop ConvertKit Add-on Attack Surface
Shortcodes 1
WordPress Hooks 23
Maintenance & Trust
Logic Hop ConvertKit Add-on Maintenance & Trust
Maintenance Signals
Community Trust
Logic Hop ConvertKit Add-on Alternatives
Logic Hop Google Analytics Add-on
logic-hop-google-analytics-add-on
Add powerful Event Tracking to WordPress with the Logic Hop Google Analytics Add-on.
Logic Hop Drip Add-on
logic-hop-drip-add-on
The Logic Hop Drip Add-on brings the power of personalization to WordPress with Drip.
Logic Hop Personalization for Elementor Add-on
logic-hop-personalization-for-elementor-add-on
The Logic Hop for Elementor brings the power of personalization to WordPress and makes it easy to personalize using Elementor.
Logic Hop Personalization for Divi Add-on
logic-hop-personalization-for-divi-add-on
The Logic Hop for Divi brings the power of personalization to WordPress and makes it easy to personalize using Divi.
Logic Hop Personalization for Gravity Forms Add-on
logic-hop-personalization-for-gravity-forms-add-on
The Logic Hop Personalization for Gravity Forms Add-on brings the power of personalization to WordPress with Gravity Forms.
Logic Hop ConvertKit Add-on Developer Profile
12 plugins · 190 total installs
How We Detect Logic Hop ConvertKit Add-on
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/logic-hop-convertkit-add-on/assets/css/logichop-convertkit-admin.css/wp-content/plugins/logic-hop-convertkit-add-on/assets/css/logichop-convertkit-public.css/wp-content/plugins/logic-hop-convertkit-add-on/assets/js/logichop-convertkit-admin.js/wp-content/plugins/logic-hop-convertkit-add-on/assets/js/logichop-convertkit-public.js/wp-content/plugins/logic-hop-convertkit-add-on/assets/js/logichop-convertkit-admin.js/wp-content/plugins/logic-hop-convertkit-add-on/assets/js/logichop-convertkit-public.jslogic-hop-convertkit-add-on/assets/css/logichop-convertkit-admin.css?ver=logic-hop-convertkit-add-on/assets/css/logichop-convertkit-public.css?ver=logic-hop-convertkit-add-on/assets/js/logichop-convertkit-admin.js?ver=logic-hop-convertkit-add-on/assets/js/logichop-convertkit-public.js?ver=HTML / DOM Fingerprints
logichop-convertkit-adminlogichop-convertkit-public<!-- The Logic Hop ConvertKit Add-on requires the Logic Hop plugin. Please download and activate the Logic Hop plugin. --><!-- The Logic Hop ConvertKit Add-on requires a Logic Hop License Key or Data Plan. -->logichop_convertkit_admin_paramslogichop_convertkit_public_params