Product View Tracker Security & Risk Analysis
wordpress.org/plugins/product-view-trackerProduct View Tracker Tracker plugin empowers WordPress site owners to effortlessly monitor and showcase the popularity of products.
Is Product View Tracker Safe to Use in 2026?
Generally Safe
Score 92/100Product View Tracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "product-view-tracker" plugin version 1.2.5 exhibits a generally good security posture, with several positive indicators. The absence of known CVEs and a history of no recorded vulnerabilities suggest a stable and well-maintained codebase. The plugin also demonstrates good practices regarding SQL queries, with a high percentage (94%) utilizing prepared statements, and a strong emphasis on output escaping (89%). The limited attack surface with no AJAX handlers, REST API routes, shortcodes, or cron events further contributes to its security.
However, the static analysis does reveal some areas of concern. Specifically, the taint analysis identified 3 flows with unsanitized paths, with 2 classified as high severity. This indicates potential vulnerabilities where user-supplied input might not be adequately validated or sanitized before being used in sensitive operations, despite the lack of direct file operations or external HTTP requests. The presence of only one nonce check and one capability check across the entire codebase, given the total number of outputs and potential interactions, could also represent a missed opportunity for more robust access control in certain scenarios.
In conclusion, while the plugin benefits from a clean vulnerability history and good core security practices like prepared statements and output escaping, the high-severity taint flows with unsanitized paths are a significant concern that warrants immediate investigation. The limited number of nonce and capability checks, while not indicative of a direct vulnerability in this version, could be a point of future concern if the plugin's functionality expands. Overall, the plugin is relatively secure but requires attention to the identified taint flow issues.
Key Concerns
- High severity taint flows with unsanitized paths
- Flows with unsanitized paths found
- Low number of nonce and capability checks
Product View Tracker Security Vulnerabilities
Product View Tracker Release Timeline
Product View Tracker Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Product View Tracker Attack Surface
WordPress Hooks 10
Maintenance & Trust
Product View Tracker Maintenance & Trust
Maintenance Signals
Community Trust
Product View Tracker Alternatives
Product View Count
product-view-count
Track and display the number of times a WooCommerce product page is viewed with an advanced React-based analytics dashboard, helping you gain deep ins …
BRK Product View Count for WooCommerce
brk-product-view-count-for-woocommerce
BRK Product View Count for WooCommerce displays real-time or manually configured sales view data on product pages, enhancing customer engagement.
3D Viewer – Display Interactive 3D Models
3d-viewer
3D Viewer lets you embed interactive 3D models and 360 product views on WordPress sites with support for GLB, GLTF, OBJ, STL, FBX, DAE, and BIM.
Page View Count
page-views-count
Places an icon, all time views count and views today count at the bottom of posts, pages and custom post types on any WordPress website.
Wp Post Views – WordPress Post views counter
wp-post-views
Wordpress Post views counter
Product View Tracker Developer Profile
1 plugin · 0 total installs
How We Detect Product View Tracker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/product-view-tracker/css/style.cssproduct-view-tracker/css/style.css?ver=HTML / DOM Fingerprints
wrapwp-list-tablewidefatfixedstriped