Metorik – Reports & Email Automation for WooCommerce Security & Risk Analysis

wordpress.org/plugins/metorik-helper

The Metorik Helper helps provide your WooCommerce store with powerful analytics, reports, and tools.

10K active installs v2.0.10 PHP 7.4+ WP 5.0+ Updated Dec 1, 2025
woocommercewoocommerce-cartswoocommerce-emailswoocommerce-exportwoocommerce-reports
99
A · Safe
CVEs total1
Unpatched0
Last CVEJul 10, 2024
Safety Verdict

Is Metorik – Reports & Email Automation for WooCommerce Safe to Use in 2026?

Generally Safe

Score 99/100

Metorik – Reports & Email Automation for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Jul 10, 2024Updated 5mo ago
Risk Assessment

The metorik-helper plugin version 2.0.10 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices with a high percentage of SQL queries using prepared statements and properly escaped output. The absence of dangerous functions and taint flows with critical or high severity suggests a generally well-coded backend. However, significant concerns arise from the attack surface analysis. The plugin exposes one REST API route without any permission callbacks, creating a direct and unprotected entry point for potential attackers. This lack of authorization on a REST API endpoint is a critical weakness that could allow unauthorized actions or data exposure.

The vulnerability history reveals one known medium-severity CVE, which was last patched on 2024-07-10. While currently unpatched CVEs are zero, the presence of a past CSRF vulnerability indicates a recurring area of concern for this plugin. Coupled with the unprotected REST API endpoint, this suggests a need for increased vigilance regarding input validation and access control. In conclusion, while the plugin has strengths in secure coding practices like prepared statements and output escaping, the unprotected REST API route presents a significant and immediate security risk that overshadows these positives. The past vulnerability history, though resolved, warrants attention to ensure similar issues do not re-emerge.

Key Concerns

  • REST API route without permission callbacks
  • Past medium severity CVE
Vulnerabilities
1 published

Metorik – Reports & Email Automation for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-38691medium · 4.3Cross-Site Request Forgery (CSRF)

Metorik – Reports & Email Automation for WooCommerce <= 1.7.1 - Cross-Site Request Forgery

Jul 10, 2024 Patched in 1.7.2 (9d)
Version History

Metorik – Reports & Email Automation for WooCommerce Release Timeline

v2.0.10Current
v2.0.9
v2.0.8
v2.0.7
v2.0.6
v2.0.5
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v2.0.0
v1.7.2
v1.7.11 CVE
v1.7.01 CVE
v1.6.31 CVE
v1.6.21 CVE
v1.6.11 CVE
v1.6.01 CVE
v1.5.21 CVE
v1.5.11 CVE
Code Analysis
Analyzed Mar 16, 2026

Metorik – Reports & Email Automation for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
20 prepared
Unescaped Output
8
48 escaped
Nonce Checks
4
Capability Checks
0
File Operations
1
External Requests
2
Bundled Libraries
0

SQL Query Safety

95% prepared21 total queries

Output Escaping

86% escaped56 total outputs
Attack Surface
1 unprotected

Metorik – Reports & Email Automation for WooCommerce Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

GET/wp-json/metorik/v1/recover-cartinc\cart-recovery.php:32
WordPress Hooks 62
actionadmin_headinc\admin-ui.php:22
actionadd_meta_boxesinc\admin-ui.php:23
filtermanage_users_columnsinc\admin-ui.php:26
filtermanage_users_custom_columninc\admin-ui.php:27
actionrest_api_initinc\api\coupons.php:17
actionrest_api_initinc\api\coupons.php:18
actionrest_api_initinc\api\customers.php:18
actionrest_api_initinc\api\customers.php:19
actionrest_api_initinc\api\customers.php:20
actionrest_api_initinc\api\customers.php:31
actionrest_api_initinc\api\customers.php:32
actionrest_api_initinc\api\metorik.php:13
actionrest_api_initinc\api\metorik.php:14
actionrest_api_initinc\api\metorik.php:15
actionrest_api_initinc\api\metorik.php:16
actionrest_api_initinc\api\orders.php:17
actionrest_api_initinc\api\orders.php:18
actionrest_api_initinc\api\orders.php:19
filterwoocommerce_rest_prepare_shop_orderinc\api\orders.php:23
filterwoocommerce_rest_prepare_shop_order_objectinc\api\orders.php:28
filterwoocommerce_rest_prepare_order_noteinc\api\orders.php:32
actionrest_api_initinc\api\products.php:17
actionrest_api_initinc\api\products.php:18
actionrest_api_initinc\api\refunds.php:17
actionrest_api_initinc\api\subscriptions.php:17
actionrest_api_initinc\api\subscriptions.php:18
filterwoocommerce_rest_prepare_shop_subscriptioninc\api\subscriptions.php:19
actionrest_api_initinc\api.php:14
actionrest_api_initinc\cart-recovery.php:18
actionwoocommerce_cart_loaded_from_sessioninc\cart-recovery.php:19
actionwp_loadedinc\cart-recovery.php:22
actionwoocommerce_add_to_cartinc\cart-recovery.php:23
actionwp_logininc\cart-tracking.php:42
actionwoocommerce_payment_completeinc\cart-tracking.php:45
actionwoocommerce_thankyouinc\cart-tracking.php:46
actionwp_footerinc\cart-tracking.php:49
actionwc_ajax_metorik_seen_add_to_cart_forminc\cart-tracking.php:52
actionwc_ajax_metorik_email_opt_outinc\cart-tracking.php:55
actionwc_ajax_metorik_email_opt_ininc\cart-tracking.php:58
actionwoocommerce_blocks_loadedinc\cart-tracking.php:66
actioninitinc\cart-tracking.php:67
filterwoocommerce_edit_account_form_fieldsinc\cart-tracking.php:71
actionwoocommerce_store_api_checkout_order_processedinc\cart-tracking.php:74
filterwoocommerce_checkout_fieldsinc\cart-tracking.php:82
filterwoocommerce_form_field_emailinc\cart-tracking.php:85
actionwc_ajax_metorik_capture_customer_datainc\cart-tracking.php:88
actionwoocommerce_checkout_order_processedinc\cart-tracking.php:91
actionshutdowninc\cart-tracking.php:195
filterwoocommerce_get_default_value_for_metorik/opt-ininc\cart-tracking.php:439
actionwoocommerce_set_additional_field_valueinc\cart-tracking.php:455
actionrest_api_initinc\import.php:13
filterget_user_metadatainc\import.php:26
filterget_user_metadatainc\import.php:30
actionwoocommerce_checkout_update_order_metainc\source-tracking.php:49
actionwoocommerce_store_api_checkout_order_processedinc\source-tracking.php:52
actionuser_registerinc\source-tracking.php:55
actionplugins_loadedmetorik-helper.php:52
actioninitmetorik-helper.php:53
actionbefore_woocommerce_initmetorik-helper.php:64
actionadmin_noticesmetorik-helper.php:77
actionwp_enqueue_scriptsmetorik-helper.php:90
actionadmin_noticesmetorik-helper.php:92
Maintenance & Trust

Metorik – Reports & Email Automation for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 1, 2025
PHP min version7.4
Downloads208K

Community Trust

Rating100/100
Number of ratings20
Active installs10K
Developer Profile

Metorik – Reports & Email Automation for WooCommerce Developer Profile

Metorik

1 plugin · 10K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
9 days
View full developer profile
Detection Fingerprints

How We Detect Metorik – Reports & Email Automation for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/metorik-helper/assets/css/metorik.css/wp-content/plugins/metorik-helper/assets/js/metorik.min.js
Script Paths
/wp-content/plugins/metorik-helper/assets/js/metorik.min.js
Version Parameters
metorik-css?ver=metorik-js?ver=

HTML / DOM Fingerprints

JS Globals
metorik_params
REST Endpoints
/wp-json/metorik_capture_customer_data/wp-json/metorik_email_opt_out/wp-json/metorik_email_opt_in/wp-json/metorik_seen_add_to_cart_form
FAQ

Frequently Asked Questions about Metorik – Reports & Email Automation for WooCommerce