Synctrack – Sync PayPal Tracking Auto Security & Risk Analysis

wordpress.org/plugins/omega-add-paypal-tracking-for-woocommerce

Synctrack - Sync PayPal Tracking Auto Auto-sync PayPal tracking info & Stripe. Faster PayPal funds release, build trust and avoid disputes

300 active installs v2.0.0 PHP 5.3.0+ WP 3.0.1+ Updated Feb 27, 2025
paypalpaypal-trackingsynctracktracking
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Synctrack – Sync PayPal Tracking Auto Safe to Use in 2026?

Generally Safe

Score 92/100

Synctrack – Sync PayPal Tracking Auto has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

This plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), file operations, and external HTTP requests is commendable. Furthermore, the plugin demonstrates good practice by implementing capability checks on entry points and a nonce check. The limited attack surface, consisting solely of AJAX handlers, is also a positive sign, especially with no unprotected AJAX endpoints identified.

The primary concern arising from the static analysis is the moderate rate of proper output escaping, with only 43% of outputs being correctly escaped. This leaves a potential for cross-site scripting (XSS) vulnerabilities if untrusted data is outputted without sufficient sanitization. The lack of identified taint flows is positive, suggesting no immediately obvious vulnerabilities in how data is processed through the application. The plugin's history of zero known CVEs, with no past vulnerabilities of any severity, further indicates a relatively secure development history and consistent maintenance.

In conclusion, while the plugin demonstrates several key security strengths, the less-than-ideal output escaping warrants attention. This is the most significant area of risk identified. The overall security of the plugin is good, but addressing the output escaping would further enhance its resilience against common web vulnerabilities.

Key Concerns

  • Output escaping is not fully implemented
Vulnerabilities
None known

Synctrack – Sync PayPal Tracking Auto Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Synctrack – Sync PayPal Tracking Auto Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
4
3 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

43% escaped7 total outputs
Attack Surface

Synctrack – Sync PayPal Tracking Auto Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_omega_add_paypal_tracking_ratedincludes\admin\rating.php:60
noprivwp_ajax_omega_add_paypal_tracking_ajax_add_to_cartincludes\ajax.php:3
authwp_ajax_omega_add_paypal_tracking_ajax_add_to_cartincludes\ajax.php:4
WordPress Hooks 8
actionadmin_menuincludes\admin\settings.php:24
actionwp_enqueue_scriptsincludes\enqueue_scripts.php:17
actionrest_api_initincludes\rest-api-endpoints.php:8
actionbefore_woocommerce_initomega-add-paypal-tracking.php:22
actioninitomega-add-paypal-tracking.php:31
actionplugins_loadedomega-add-paypal-tracking.php:40
actionadmin_initomega-add-paypal-tracking.php:47
actionadmin_noticesomega-add-paypal-tracking.php:48
Maintenance & Trust

Synctrack – Sync PayPal Tracking Auto Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 27, 2025
PHP min version5.3.0
Downloads5K

Community Trust

Rating100/100
Number of ratings26
Active installs300
Developer Profile

Synctrack – Sync PayPal Tracking Auto Developer Profile

Omegatheme

3 plugins · 320 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Synctrack – Sync PayPal Tracking Auto

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/omega-add-paypal-tracking-for-woocommerce/assets/js/admin.min.js

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Synctrack – Sync PayPal Tracking Auto