
Metorik – Reports & Email Automation for WooCommerce Security & Risk Analysis
wordpress.org/plugins/metorik-helperThe Metorik Helper helps provide your WooCommerce store with powerful analytics, reports, and tools.
Is Metorik – Reports & Email Automation for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100Metorik – Reports & Email Automation for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The metorik-helper plugin version 2.0.10 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices with a high percentage of SQL queries using prepared statements and properly escaped output. The absence of dangerous functions and taint flows with critical or high severity suggests a generally well-coded backend. However, significant concerns arise from the attack surface analysis. The plugin exposes one REST API route without any permission callbacks, creating a direct and unprotected entry point for potential attackers. This lack of authorization on a REST API endpoint is a critical weakness that could allow unauthorized actions or data exposure.
The vulnerability history reveals one known medium-severity CVE, which was last patched on 2024-07-10. While currently unpatched CVEs are zero, the presence of a past CSRF vulnerability indicates a recurring area of concern for this plugin. Coupled with the unprotected REST API endpoint, this suggests a need for increased vigilance regarding input validation and access control. In conclusion, while the plugin has strengths in secure coding practices like prepared statements and output escaping, the unprotected REST API route presents a significant and immediate security risk that overshadows these positives. The past vulnerability history, though resolved, warrants attention to ensure similar issues do not re-emerge.
Key Concerns
- REST API route without permission callbacks
- Past medium severity CVE
Metorik – Reports & Email Automation for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Metorik – Reports & Email Automation for WooCommerce <= 1.7.1 - Cross-Site Request Forgery
Metorik – Reports & Email Automation for WooCommerce Release Timeline
Metorik – Reports & Email Automation for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Metorik – Reports & Email Automation for WooCommerce Attack Surface
REST API Routes 1
WordPress Hooks 62
Maintenance & Trust
Metorik – Reports & Email Automation for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Metorik – Reports & Email Automation for WooCommerce Alternatives
MailPoet – Newsletters, Email Marketing, and Automation
mailpoet
Send beautiful newsletters from WordPress. Collect subscribers with signup forms, automate your emails for WooCommerce, blog post notifications & more
Order Export & Order Import for WooCommerce
order-import-export-for-woocommerce
The best order export import plugin for WooCommerce. Easily import and export WooCommerce orders and WooCommerce coupons using CSV.
YayMail – WooCommerce Email Customizer
yaymail
Customize WooCommerce email templates with an advanced drag-and-drop email builder. Works great with 80+ WooCommerce Email Customizer Addons.
Email Customizer for WooCommerce | Drag and Drop Email Templates Builder
email-customizer-for-woocommerce
WooCommerce Email Customizer plugin lets you customize transactional emails using a template builder, adding text, images & more to match your brand
ShopMagic – email automation
shopmagic-for-woocommerce
Flexible email automation and workflows triggered by customer and site events.
Metorik – Reports & Email Automation for WooCommerce Developer Profile
1 plugin · 10K total installs
How We Detect Metorik – Reports & Email Automation for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/metorik-helper/assets/css/metorik.css/wp-content/plugins/metorik-helper/assets/js/metorik.min.js/wp-content/plugins/metorik-helper/assets/js/metorik.min.jsmetorik-css?ver=metorik-js?ver=HTML / DOM Fingerprints
metorik_params/wp-json/metorik_capture_customer_data/wp-json/metorik_email_opt_out/wp-json/metorik_email_opt_in/wp-json/metorik_seen_add_to_cart_form