Qualetics Security & Risk Analysis

wordpress.org/plugins/qualetics

Qualetics - No Code Analytics & AI for your Wordpress Website

0 active installs v1.0.2 PHP 7.0+ WP 4.6+ Updated Aug 9, 2022
performance-analyticssoftware-quality-analyticsuser-behavior-analyticsuser-engagementwebsite-analytics
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Qualetics Safe to Use in 2026?

Generally Safe

Score 85/100

Qualetics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The Qualetics plugin version 1.0.2 exhibits a generally good security posture, primarily due to the absence of known vulnerabilities and the implementation of secure coding practices. The static analysis reveals a limited attack surface consisting only of two AJAX handlers, both of which appear to be protected by authentication checks (as indicated by 0 unprotected entry points). The plugin also avoids dangerous functions, performs all SQL queries using prepared statements, and has no file operations or external HTTP requests, which are all positive indicators of secure development.

However, there are some areas for improvement. While 100% of SQL queries are prepared, the output escaping is only at 82%, suggesting that approximately 18% of outputs might be vulnerable to cross-site scripting (XSS) if the unsanitized data is user-controlled. The taint analysis reveals one flow with unsanitized paths, and while no critical or high severity issues were identified, this remains a potential concern that warrants further investigation. The absence of capability checks and the sole use of nonce checks (which are present) could be strengthened by implementing capability checks in conjunction with nonces for more robust authorization on AJAX endpoints.

The plugin's vulnerability history is entirely clean, with zero known CVEs. This is an excellent track record and suggests consistent attention to security or a lack of public discovery of vulnerabilities. In conclusion, Qualetics v1.0.2 is a reasonably secure plugin, with its strengths lying in its clean vulnerability history and secure handling of SQL and external requests. The main areas of concern are the moderate output escaping rate and the single unsanitized taint flow, which, while not critical in this analysis, represent potential vectors for attack if not adequately managed.

Key Concerns

  • Output escaping below 100%
  • Flow with unsanitized paths
  • No capability checks on AJAX
Vulnerabilities
None known

Qualetics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Qualetics Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
23
108 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

82% escaped131 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

4 flows1 with unsanitized paths
qlts_track_search (classes\rltqualetics-public.php:436)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Qualetics Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_qlts_get_removed_from_cartclasses\rltqualetics-public.php:30
noprivwp_ajax_qlts_get_removed_from_cartclasses\rltqualetics-public.php:31
WordPress Hooks 14
actionadmin_menuclasses\rltqualetics-admin.php:27
actionadmin_enqueue_scriptsclasses\rltqualetics-admin.php:28
actionwp_enqueue_scriptsclasses\rltqualetics-public.php:18
actionwp_loginclasses\rltqualetics-public.php:19
actionwp_logoutclasses\rltqualetics-public.php:20
actionuser_registerclasses\rltqualetics-public.php:21
actioncomment_postclasses\rltqualetics-public.php:22
actionwp_footerclasses\rltqualetics-public.php:23
actionwoocommerce_add_to_cartclasses\rltqualetics-public.php:24
actionwp_footerclasses\rltqualetics-public.php:25
actionwoocommerce_thankyouclasses\rltqualetics-public.php:26
actionwoocommerce_cart_item_removedclasses\rltqualetics-public.php:28
actionwp_footerclasses\rltqualetics-public.php:29
filterscript_loader_tagclasses\rltqualetics-public.php:33
Maintenance & Trust

Qualetics Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedAug 9, 2022
PHP min version7.0
Downloads1K

Community Trust

Rating100/100
Number of ratings2
Active installs0
Developer Profile

Qualetics Developer Profile

qualetics

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Qualetics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/qualetics/assets/css/qlts-admin.css/wp-content/plugins/qualetics/assets/js/qlts-admin.js

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Qualetics