Pixelavo – Server Side Tracking & Pixel + AI Ads Tools Security & Risk Analysis

wordpress.org/plugins/pixelavo

Add pixel tracking to your WordPress site with Conversions API, server-side tracking, AI ad copy generation, and AI marketing consultant.

800 active installs v1.5.3 PHP 7.4+ WP 5.0+ Updated Mar 3, 2026
conversion-trackingfacebook-pixelmeta-pixelserver-side-trackingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Pixelavo – Server Side Tracking & Pixel + AI Ads Tools Safe to Use in 2026?

Generally Safe

Score 100/100

Pixelavo – Server Side Tracking & Pixel + AI Ads Tools has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'pixelavo' plugin v1.5.3 exhibits a generally good security posture with strong adherence to best practices in several key areas. The high percentage of SQL queries using prepared statements and the robust output escaping (94%) are positive indicators. The absence of known vulnerabilities (CVEs) and a clean vulnerability history further contribute to this impression.

However, a significant concern arises from the presence of one AJAX handler that lacks authentication checks. This represents a direct entry point that could be exploited by unauthenticated users, potentially leading to unintended actions or data exposure. Additionally, the taint analysis reveals two flows with unsanitized paths, which, while not classified as critical or high severity in this analysis, warrant careful examination as they could indicate potential weaknesses if exploited in combination with other factors. The plugin's reliance on external HTTP requests (14) also introduces a dependency that could be a vector for supply chain attacks if any of the external services are compromised.

In conclusion, while 'pixelavo' v1.5.3 has several strengths, the unauthenticated AJAX handler is a critical flaw that must be addressed. The unsanitized paths, though not rated as high severity, also present a latent risk. The plugin's clean historical record is a positive sign, but it should not overshadow the immediate risks identified in the current static analysis.

Key Concerns

  • AJAX handler without auth check
  • Flows with unsanitized paths
Vulnerabilities
None known

Pixelavo – Server Side Tracking & Pixel + AI Ads Tools Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Pixelavo – Server Side Tracking & Pixel + AI Ads Tools Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
10 prepared
Unescaped Output
7
107 escaped
Nonce Checks
9
Capability Checks
10
File Operations
0
External Requests
14
Bundled Libraries
0

SQL Query Safety

91% prepared11 total queries

Output Escaping

94% escaped114 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
__construct (admin\class-diagnostic-data.php:81)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Pixelavo – Server Side Tracking & Pixel + AI Ads Tools Attack Surface

Entry Points11
Unprotected1

AJAX Handlers 11

authwp_ajax_pixelavo_diagnostic_dataadmin\class-diagnostic-data.php:97
authwp_ajax_pixelavo_noticesadmin\class-notices.php:53
authwp_ajax_pixelavo_dismiss_security_noticeadmin\settings-panel\includes\classes\Api\Ai\SecurityNotices.php:21
authwp_ajax_pixelavo_eventincludes\pixel-ajax-events-data.php:30
noprivwp_ajax_pixelavo_eventincludes\pixel-ajax-events-data.php:31
authwp_ajax_pixelavo_get_form_titleincludes\pixel-ajax-events-data.php:33
noprivwp_ajax_pixelavo_get_form_titleincludes\pixel-ajax-events-data.php:34
authwp_ajax_pixelavo_edd_ajax_remove_from_cartincludes\pixel-edd-events-data.php:47
noprivwp_ajax_pixelavo_edd_ajax_remove_from_cartincludes\pixel-edd-events-data.php:48
authwp_ajax_pixelavo_ajax_remove_from_cartincludes\pixel-events-data.php:42
noprivwp_ajax_pixelavo_ajax_remove_from_cartincludes\pixel-events-data.php:43
WordPress Hooks 42
actionplugins_loadedadmin\class-diagnostic-data.php:107
actionadmin_headadmin\class-diagnostic-data.php:121
actionadmin_footeradmin\class-diagnostic-data.php:122
actionadmin_noticesadmin\class-notices.php:49
actionpixelavo_admin_noticesadmin\class-notices.php:50
actionpixelavo_admin_sidebar_noticesadmin\class-notices.php:51
actionadmin_footeradmin\class-notices.php:52
actionadmin_menuadmin\settings-panel\includes\classes\Admin\Menu.php:12
actionadmin_footeradmin\settings-panel\includes\classes\Admin\Menu.php:13
actionadmin_enqueue_scriptsadmin\settings-panel\includes\classes\Admin\Menu.php:70
actionpixelavo_admin_noticesadmin\settings-panel\includes\classes\Api\Ai\SecurityNotices.php:20
filterpixelavo_settings_sanitizeadmin\settings-panel\includes\classes\Api\Settings.php:42
filterpixelavo_settings_sanitize_openai_api_keyadmin\settings-panel\includes\classes\Api\Settings.php:43
filterpixelavo_settings_sanitize_gemini_api_keyadmin\settings-panel\includes\classes\Api\Settings.php:44
actionrest_api_initadmin\settings-panel\includes\classes\Api.php:18
actionadmin_enqueue_scriptsadmin\settings-panel\includes\classes\Assets.php:13
actioninitadmin\settings-panel\settings-panel.php:122
actionwp_headincludes\add-pixel.php:31
actionplugins_loadedincludes\base.php:45
actionin_admin_headerincludes\base.php:46
actionwp_enqueue_scriptsincludes\base.php:47
actionadmin_initincludes\base.php:48
actionadmin_initincludes\base.php:49
actionadmin_initincludes\base.php:50
actionadmin_initincludes\base.php:51
actionadmin_initincludes\base.php:52
actionwp_loginincludes\base.php:60
actionuser_registerincludes\base.php:61
actionwp_footerincludes\base.php:132
actionadmin_footerincludes\base.php:329
actioninitincludes\modifier.php:27
actionwp_footerincludes\pixel-custom-events-data.php:30
actionwp_footerincludes\pixel-edd-events-data.php:30
actionwp_footerincludes\pixel-edd-events-data.php:35
actionwp_footerincludes\pixel-edd-events-data.php:40
actioninitincludes\pixel-edd-feed.php:27
filterfeed_content_typeincludes\pixel-edd-feed.php:28
actionwp_footerincludes\pixel-events-data.php:30
actionwp_footerincludes\pixel-events-data.php:34
actionwp_footerincludes\pixel-events-data.php:38
actioninitincludes\pixel-feed.php:27
filterfeed_content_typeincludes\pixel-feed.php:28
Maintenance & Trust

Pixelavo – Server Side Tracking & Pixel + AI Ads Tools Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 3, 2026
PHP min version7.4
Downloads17K

Community Trust

Rating60/100
Number of ratings2
Active installs800
Developer Profile

Pixelavo – Server Side Tracking & Pixel + AI Ads Tools Developer Profile

HasThemes

14 plugins · 16K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
179 days
View full developer profile
Detection Fingerprints

How We Detect Pixelavo – Server Side Tracking & Pixel + AI Ads Tools

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pixelavo/assets/css/style.css/wp-content/plugins/pixelavo/assets/css/frontend.css/wp-content/plugins/pixelavo/assets/js/frontend.js/wp-content/plugins/pixelavo/admin/assets/css/main.css/wp-content/plugins/pixelavo/admin/assets/js/main.js
Script Paths
/wp-content/plugins/pixelavo/assets/js/frontend.js
Version Parameters
pixelavo/assets/css/style.css?ver=pixelavo/assets/css/frontend.css?ver=pixelavo/assets/js/frontend.js?ver=pixelavo/admin/assets/css/main.css?ver=pixelavo/admin/assets/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
pixelavo-upgrade-pro
Data Attributes
data-url
JS Globals
pixelavoEventsLocalizedDataPixelavoAdmin
REST Endpoints
/wp-json/pixelavo/v1/settings
FAQ

Frequently Asked Questions about Pixelavo – Server Side Tracking & Pixel + AI Ads Tools