Metrilo – WooCommerce Growth Platform Security & Risk Analysis

wordpress.org/plugins/metrilo-woocommerce-integration

Ecommerce Analytics and behaviour-driven customer engagement tools for ecommerce brands.

300 active installs v2.0.1 PHP + WP 2.9.2+ Updated Jul 5, 2021
analyticsreportingtrackingwoowoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Metrilo – WooCommerce Growth Platform Safe to Use in 2026?

Generally Safe

Score 85/100

Metrilo – WooCommerce Growth Platform has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The Metrilo WooCommerce Integration plugin version 2.0.1 presents a mixed security posture. While it boasts no known historical vulnerabilities, indicating a generally well-maintained codebase regarding public exploits, its static analysis reveals significant areas of concern. The presence of an unprotected AJAX handler, which is the only identified entry point, is a critical flaw. Furthermore, the complete lack of output escaping for all identified outputs means that any data processed or displayed through these handlers is potentially vulnerable to cross-site scripting (XSS) attacks. The taint analysis, though limited in scope, did identify unsanitized paths, which, in conjunction with the unprotected AJAX handler, could facilitate exploitation. The absence of capability checks and nonce verification on the entry point further exacerbates these risks, allowing any authenticated user, or potentially unauthenticated users depending on WordPress's internal handling, to trigger functionality that might have unintended consequences or expose sensitive data.

Despite the absence of directly exploitable SQL injection risks due to a moderate percentage of prepared statements, the overall lack of robust security controls on its primary interaction point is a major weakness. The plugin's design relies heavily on the hope that its internal logic is secure, which is insufficient without proper input validation, authorization, and output sanitization. The plugin does make external HTTP requests, which, while not inherently a vulnerability, can become a vector if the data sent or received is not properly handled or if the endpoint itself is compromised. In conclusion, while the plugin has a clean vulnerability history, its current static analysis results point to significant, readily exploitable security weaknesses that require immediate attention.

Key Concerns

  • Unprotected AJAX handler
  • 0% output escaping
  • No nonce checks
  • No capability checks
  • Flows with unsanitized paths
Vulnerabilities
None known

Metrilo – WooCommerce Growth Platform Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Metrilo – WooCommerce Growth Platform Release Timeline

v2.0.1Current
v2.0.0
v1.7.22
v1.7.21
v1.7.20
v1.7.19
v1.7.18
v1.7.17
v1.7.16
v1.7.15
v1.7.14
v1.7.13
v1.7.12
v1.7.11
v1.7.10
v1.7.9
v1.7.8
v1.7.7
v1.7.6
v1.7.5
Code Analysis
Analyzed Mar 16, 2026

Metrilo – WooCommerce Growth Platform Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
1 prepared
Unescaped Output
14
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
6
Bundled Libraries
0

SQL Query Safety

33% prepared3 total queries

Output Escaping

0% escaped14 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
check_for_keys (includes\integration.php:226)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Metrilo – WooCommerce Growth Platform Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_metrilo_chunk_syncincludes\integration.php:291
WordPress Hooks 18
actionwoocommerce_initincludes\integration.php:68
actiontemplate_redirectincludes\integration.php:69
actionadmin_noticesincludes\integration.php:230
actionadmin_noticesincludes\integration.php:242
filterwp_headincludes\integration.php:272
filterwp_headincludes\integration.php:273
filterwp_footerincludes\integration.php:274
actionwoocommerce_add_to_cartincludes\integration.php:277
actionwoocommerce_remove_cart_itemincludes\integration.php:278
filterwoocommerce_applied_couponincludes\integration.php:279
actionwoocommerce_checkout_order_processedincludes\integration.php:282
actionwoocommerce_subscriptions_renewal_order_createdincludes\integration.php:285
actionwoocommerce_order_status_changedincludes\integration.php:288
actionadmin_menuincludes\integration.php:293
actionplugins_loadedmetrilo-woocommerce-integration.php:22
filterquery_varsmetrilo-woocommerce-integration.php:23
filterquery_varsmetrilo-woocommerce-integration.php:24
filterwoocommerce_integrationsmetrilo-woocommerce-integration.php:34
Maintenance & Trust

Metrilo – WooCommerce Growth Platform Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedJul 5, 2021
PHP min version
Downloads51K

Community Trust

Rating78/100
Number of ratings10
Active installs300
Developer Profile

Metrilo – WooCommerce Growth Platform Developer Profile

Metrilo

1 plugin · 300 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Metrilo – WooCommerce Growth Platform

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/metrilo-woocommerce-integration/metrilo.js
Version Parameters
metrilo-woocommerce-integration/metrilo.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-metrilo-token
JS Globals
Metrilo
REST Endpoints
/wp-json/metrilo-woo-analytics
FAQ

Frequently Asked Questions about Metrilo – WooCommerce Growth Platform