Product View Tracker Security & Risk Analysis

wordpress.org/plugins/product-view-tracker

Product View Tracker Tracker plugin empowers WordPress site owners to effortlessly monitor and showcase the popularity of products.

0 active installs v1.2.5 PHP 5.4+ WP 6.0+ Updated Sep 23, 2024
product-viewproduct-view-numberproduct-view-trackerview-countwoocommerce-product-view-tracker
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Product View Tracker Safe to Use in 2026?

Generally Safe

Score 92/100

Product View Tracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "product-view-tracker" plugin version 1.2.5 exhibits a generally good security posture, with several positive indicators. The absence of known CVEs and a history of no recorded vulnerabilities suggest a stable and well-maintained codebase. The plugin also demonstrates good practices regarding SQL queries, with a high percentage (94%) utilizing prepared statements, and a strong emphasis on output escaping (89%). The limited attack surface with no AJAX handlers, REST API routes, shortcodes, or cron events further contributes to its security.

However, the static analysis does reveal some areas of concern. Specifically, the taint analysis identified 3 flows with unsanitized paths, with 2 classified as high severity. This indicates potential vulnerabilities where user-supplied input might not be adequately validated or sanitized before being used in sensitive operations, despite the lack of direct file operations or external HTTP requests. The presence of only one nonce check and one capability check across the entire codebase, given the total number of outputs and potential interactions, could also represent a missed opportunity for more robust access control in certain scenarios.

In conclusion, while the plugin benefits from a clean vulnerability history and good core security practices like prepared statements and output escaping, the high-severity taint flows with unsanitized paths are a significant concern that warrants immediate investigation. The limited number of nonce and capability checks, while not indicative of a direct vulnerability in this version, could be a point of future concern if the plugin's functionality expands. Overall, the plugin is relatively secure but requires attention to the identified taint flow issues.

Key Concerns

  • High severity taint flows with unsanitized paths
  • Flows with unsanitized paths found
  • Low number of nonce and capability checks
Vulnerabilities
None known

Product View Tracker Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Product View Tracker Release Timeline

v1.2.5Current
v1.2.4
Code Analysis
Analyzed Mar 17, 2026

Product View Tracker Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
15 prepared
Unescaped Output
5
39 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

94% prepared16 total queries

Output Escaping

89% escaped44 total outputs
Data Flows · Security
3 unsanitized

Data Flow Analysis

5 flows3 with unsanitized paths
<PVtracker-productViewMarketChannel> (includes\PVtracker-productViewMarketChannel.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Product View Tracker Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_menuincludes\PVtracker-productViewMarketChannel.php:7
actionwpincludes\PVtracker-productViewMarketChannel.php:8
actionwpincludes\Pvtracker-productViewTracker-class.php:16
actionadmin_menuincludes\Pvtracker-productViewTracker-class.php:17
actionwoocommerce_add_to_cartincludes\Pvtracker-productViewTracker-class.php:18
actionadmin_initincludes\PVtracker-settings.php:7
actionadmin_menuincludes\PVtracker-settings.php:8
actionadmin_menuincludes\Pvtracker-todayViewProdcut.php:7
actionadmin_enqueue_scriptsproduct-view-tracker.php:49
actionplugins_loadedproduct-view-tracker.php:81
Maintenance & Trust

Product View Tracker Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedSep 23, 2024
PHP min version5.4
Downloads3K

Community Trust

Rating80/100
Number of ratings1
Active installs0
Developer Profile

Product View Tracker Developer Profile

wahid73

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Product View Tracker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/product-view-tracker/css/style.css
Version Parameters
product-view-tracker/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
wrapwp-list-tablewidefatfixedstriped
FAQ

Frequently Asked Questions about Product View Tracker