
ShopMetrics for WooCommerce Security & Risk Analysis
wordpress.org/plugins/shopmetricsEasy and Smart Analytics Dashboard with Automatic Cart Recovery for WooCommerce stores.
Is ShopMetrics for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100ShopMetrics for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'shopmetrics' v1.0.10 plugin exhibits a mixed security posture. On the positive side, the plugin has a clean vulnerability history with no recorded CVEs, which is a strong indicator of good development practices and diligence in addressing security issues. The taint analysis also shows no critical or high severity flows with unsanitized paths, suggesting that common injection vulnerabilities are likely mitigated. However, the static analysis reveals significant areas for concern. The presence of 33 AJAX handlers, with one entirely lacking authentication checks, presents a direct and exploitable attack vector. Furthermore, the static analysis indicates that 100% of SQL queries are executed without prepared statements, a critical deficiency that makes the plugin highly susceptible to SQL injection attacks. While the plugin has a good history and no critical taint flows, these two static analysis findings introduce substantial risks that cannot be overlooked.
Key Concerns
- Unprotected AJAX handler found
- 100% of SQL queries lack prepared statements
ShopMetrics for WooCommerce Security Vulnerabilities
ShopMetrics for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ShopMetrics for WooCommerce Attack Surface
AJAX Handlers 33
WordPress Hooks 48
Maintenance & Trust
ShopMetrics for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
ShopMetrics for WooCommerce Alternatives
Cart Rescue – Abandoned Cart Recovery for WooCommerce
cart-rescue-abandoned-cart-recovery
A complete abandoned cart recovery solution to grow your business. Features a premium UI, email templates, and detailed reports.
CartResQ – Recover Abandoned Carts for WooCommerce
cartresq
Abandoned cart tracking for WooCommerce. Monitor, analyze, and recover lost sales with real-time detection and analytics.
ShopNotify – Personalized Cart Recovery for WooCommerce
shopnotify
Track abandoned carts for logged-in and guest users in WooCommerce, send automated WhatsApp reminders, and gain insights into cart recovery and abando …
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools
woocommerce-jetpack
Supercharge WooCommerce with FREE Abandoned Cart Recovery, Product Variation Swatches, PDF Invoices & 100+ tools. Boost sales & save time.
Abandoned Cart Recovery for WooCommerce
woo-abandoned-cart-recovery
A simple, effective solution to capture abandoned carts and auto-send reminders. Track logs and generate reports on carts, emails, and more
ShopMetrics for WooCommerce Developer Profile
1 plugin · 0 total installs
How We Detect ShopMetrics for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shopmetrics/assets/css/backend.css/wp-content/plugins/shopmetrics/assets/css/frontend.css/wp-content/plugins/shopmetrics/assets/js/backend.js/wp-content/plugins/shopmetrics/assets/js/frontend.jsshopmetrics/assets/css/backend.css?ver=shopmetrics/assets/css/frontend.css?ver=shopmetrics/assets/js/backend.js?ver=shopmetrics/assets/js/frontend.js?ver=HTML / DOM Fingerprints
shopmetrics-widgetshopmetrics-dashboardshopmetrics-settings-pageshopmetrics-notice<!-- ShopMetrics - Start Settings Form --><!-- ShopMetrics - End Settings Form --><!-- ShopMetrics - Start Dashboard Widget --><!-- ShopMetrics - End Dashboard Widget -->data-shopmetrics-iddata-shopmetrics-widget-typedata-shopmetrics-api-keyshopmetrics_ajax_objectshopmetrics_paramsShopMetrics/wp-json/shopmetrics/v1/data/wp-json/shopmetrics/v1/settings[shopmetrics_dashboard][shopmetrics_widget]