Smartarget Social Sales Security & Risk Analysis

wordpress.org/plugins/smartarget-social-sales

Make users think that there are currently ongoing sales.

0 active installs v1.5 PHP 5.2.4+ WP 3.0.1+ Updated Unknown
abandoned-cartabandoned-cart-pluginrecommended-itemssalessocial-proof
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Smartarget Social Sales Safe to Use in 2026?

Generally Safe

Score 100/100

Smartarget Social Sales has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "smartarget-social-sales" v1.5 plugin exhibits a strong static security posture based on the provided analysis. The complete absence of detectable attack surface points like AJAX handlers, REST API routes, shortcodes, and cron events, particularly those lacking authentication checks, is a significant strength. Furthermore, the code demonstrates adherence to secure coding practices by utilizing prepared statements for all SQL queries and ensuring all output is properly escaped. The lack of file operations and external HTTP requests also reduces potential attack vectors.

However, the analysis does reveal some potential areas for concern. The complete absence of nonce checks and capability checks across all code, combined with zero detected entry points, suggests a potential lack of robust access control mechanisms if any hidden entry points were to be discovered. While no taint flows were identified, this could be due to the limited scope of analysis or the plugin's simple functionality.

The plugin's vulnerability history is exceptionally clean, with no recorded CVEs. This indicates a history of either exceptional security diligence or, perhaps, a lack of focused security auditing and widespread use that might expose vulnerabilities. In conclusion, while the plugin appears to follow secure coding fundamentals in its current state and has a spotless history, the absence of access control checks (nonces, capabilities) is a notable weakness that could be exploited if unforeseen entry points exist.

Key Concerns

  • No nonce checks present
  • No capability checks present
Vulnerabilities
None known

Smartarget Social Sales Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Smartarget Social Sales Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped4 total outputs
Attack Surface

Smartarget Social Sales Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionplugins_loadedincludes\class-smartarget-social-proof-sales.php:142
actionadmin_enqueue_scriptsincludes\class-smartarget-social-proof-sales.php:157
actionadmin_enqueue_scriptsincludes\class-smartarget-social-proof-sales.php:158
actionadmin_menuincludes\class-smartarget-social-proof-sales.php:160
actionadmin_initincludes\class-smartarget-social-proof-sales.php:165
actionwp_enqueue_scriptsincludes\class-smartarget-social-proof-sales.php:179
actionwp_enqueue_scriptsincludes\class-smartarget-social-proof-sales.php:180
Maintenance & Trust

Smartarget Social Sales Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version5.2.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Smartarget Social Sales Developer Profile

Erez Hadas-Sonnenschein

21 plugins · 2K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Smartarget Social Sales

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/smartarget-social-sales/admin/css/smartarget-social-proof-sales-admin.css/wp-content/plugins/smartarget-social-sales/admin/js/smartarget-social-proof-sales-admin.js
Script Paths
https://smartarget.online/wp-dashboard/package.jshttps://smartarget.online/loader.js
Version Parameters
smartarget-social-proof-sales/admin/css/smartarget-social-proof-sales-admin.css?ver=smartarget-social-proof-sales/admin/js/smartarget-social-proof-sales-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
smartarget-social-sales-admin-wrap
Data Attributes
data-smartarget-user-id
FAQ

Frequently Asked Questions about Smartarget Social Sales