ProductFlow – Product Demand Tracker for WooCommerce Security & Risk Analysis

wordpress.org/plugins/product-demand-tracker

With this plugin, you can easily track the number of items added to users' carts and get insights into product demand and trends.

0 active installs v1.0.0 PHP + WP 5.4+ Updated Jun 6, 2023
cart-recoverycart-trackingproduct-demandsales-insightswoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is ProductFlow – Product Demand Tracker for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

ProductFlow – Product Demand Tracker for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The product-demand-tracker v1.0.0 plugin exhibits a generally strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code shows good practices by not utilizing dangerous functions, performing all SQL queries using prepared statements, and demonstrating a high rate of output escaping (88%). The lack of file operations and external HTTP requests further reduces potential exposure. The vulnerability history is also clean, with no recorded CVEs, which is a positive indicator for this version.

However, the analysis does highlight some areas that, while not currently leading to critical vulnerabilities, warrant attention. The fact that there are zero capability checks present on any potential entry points is a significant concern. This means that even if future entry points are introduced, they might not have proper authorization checks, allowing any user to potentially interact with them. The zero taint analysis flows, while good, could also be attributed to the very limited attack surface and might not reflect the security if more complex logic were added.

In conclusion, product-demand-tracker v1.0.0 is currently in a secure state due to its minimal attack surface and good coding practices in SQL and output handling. The primary weakness lies in the complete lack of capability checks, which represents a potential future vulnerability if the plugin's functionality expands. The clean vulnerability history is reassuring but does not negate the need for careful development moving forward, particularly concerning authorization.

Key Concerns

  • No capability checks implemented
  • 25 outputs, 12% not properly escaped
Vulnerabilities
None known

ProductFlow – Product Demand Tracker for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

ProductFlow – Product Demand Tracker for WooCommerce Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

ProductFlow – Product Demand Tracker for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
22 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

88% escaped25 total outputs
Attack Surface

ProductFlow – Product Demand Tracker for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadedincludes/class-product-demand-tracker.php:113
actionadmin_enqueue_scriptsincludes/class-product-demand-tracker.php:127
actionadmin_enqueue_scriptsincludes/class-product-demand-tracker.php:128
actionadmin_menuincludes/class-product-demand-tracker.php:129
Maintenance & Trust

ProductFlow – Product Demand Tracker for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedJun 6, 2023
PHP min version
Downloads608

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

ProductFlow – Product Demand Tracker for WooCommerce Developer Profile

Raihan

4 plugins · 470 total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ProductFlow – Product Demand Tracker for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/product-demand-tracker/css/product-demand-tracker-admin.css/wp-content/plugins/product-demand-tracker/js/product-demand-tracker-admin.js
Script Paths
//cdn.datatables.net/1.13.1/js/jquery.dataTables.min.js
Version Parameters
product-demand-tracker/css/product-demand-tracker-admin.css?ver=product-demand-tracker/js/product-demand-tracker-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
product-demand-tracker-tableproduct-nameproduct-variationvariation-itemsvariation-itemproduct-quantityproduct-user
Data Attributes
data-product_id
FAQ

Frequently Asked Questions about ProductFlow – Product Demand Tracker for WooCommerce