Markeaze for WooCommerce Security & Risk Analysis

wordpress.org/plugins/markeaze

Live chat by Markeaze is an all-in-one communication solution designed specifically for the needs of online stores.

0 active installs v1.0.1 PHP 5.2+ WP 4.2.0+ Updated Oct 27, 2020
e-commerceemail-campaignsmarkeazewidgetswoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Markeaze for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Markeaze for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The markeaze plugin v1.0.1 exhibits a generally positive security posture, with no known past vulnerabilities and a clean taint analysis. The static code analysis reveals good practices in several areas, notably the complete absence of raw SQL queries and the use of prepared statements for all database interactions. File operations and external HTTP requests are also absent, reducing potential attack vectors. The presence of a nonce check is a positive indicator of security awareness. However, concerns arise from the presence of the `unserialize` function without explicit context for its usage, which can be a significant security risk if used with untrusted input. Furthermore, a notable percentage of output (55%) is not properly escaped, presenting a cross-site scripting (XSS) vulnerability risk. The complete lack of capability checks on any entry points is a major weakness, as it implies that any user, regardless of their role, could potentially interact with the plugin's functionalities, opening the door to privilege escalation or unauthorized actions.

Key Concerns

  • Unescaped output detected
  • Dangerous function 'unserialize' present
  • No capability checks on entry points
Vulnerabilities
None known

Markeaze for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Markeaze for WooCommerce Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
6
5 escaped
Nonce Checks
1
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$sessionCartValue = unserialize($wc->session->get('markeaze_cart_value', ''));includes\Markeaze.class.php:425

Output Escaping

45% escaped11 total outputs
Attack Surface

Markeaze for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_menuincludes\Markeaze.class.php:51
actionwp_headincludes\Markeaze.class.php:54
actionwoocommerce_before_single_productincludes\Markeaze.class.php:55
actionwoocommerce_cart_updatedincludes\Markeaze.class.php:58
actionwoocommerce_checkout_order_processedincludes\Markeaze.class.php:59
actionwoocommerce_order_status_changedincludes\Markeaze.class.php:60
actionwp_trash_postincludes\Markeaze.class.php:61
actionadmin_initincludes\Markeaze.class.php:81
actioninitmarkeaze.php:38
actionactivated_pluginmarkeaze.php:39
Maintenance & Trust

Markeaze for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedOct 27, 2020
PHP min version5.2
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Markeaze for WooCommerce Developer Profile

Markeaze

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Markeaze for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/markeaze/assets/icon.svg
Script Paths
https://cdn.jsdelivr.net/gh/markeaze/markeaze-js-tracker@latest/dist/mkz.js
Version Parameters
markeaze/style.css?ver=markeaze/script.js?ver=

HTML / DOM Fingerprints

HTML Comments
Copyright 2020 MarkeazeCopyright (c) Markeaze Inc. https://markeaze.comThis file is part of the markeaze-for-woocommerce plugin created by Markeaze.
Data Attributes
data-mkz-trackingdata-mkz-tracker
JS Globals
mkz
FAQ

Frequently Asked Questions about Markeaze for WooCommerce