Snorkel Security & Risk Analysis

wordpress.org/plugins/snorkel

Snorkel combines your sales data and chat transcripts to show you ROI on conversations as well as other crucial sales insights.

0 active installs v1.0 PHP 7.0+ WP 3.0.1+ Updated Unknown
analyticsdatalive-chatolarkolark-live-chat
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Snorkel Safe to Use in 2026?

Generally Safe

Score 100/100

Snorkel has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "snorkel" v1.0 plugin presents a strong initial security posture, with no apparent vulnerabilities identified in the static analysis or its historical record. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and the proper escaping of all output are excellent indicators of secure coding practices. Furthermore, the plugin exhibits a minimal attack surface, with no registered AJAX handlers, REST API routes, shortcodes, or cron events. This lack of entry points significantly reduces the potential for malicious actors to interact with the plugin.

While the code analysis is positive, it's important to note the complete absence of nonce and capability checks. While this is not a direct vulnerability given the current attack surface, it represents a missed opportunity for robust security if the plugin were to evolve and introduce new entry points. The bundling of Guzzle, a third-party library, also warrants attention; while not flagged as an issue here, ensuring this library is kept up-to-date is crucial for maintaining security. Overall, "snorkel" v1.0 appears secure based on the provided data, but the lack of essential security checks suggests a potential weakness if its functionality expands.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Bundled outdated library (Guzzle)
Vulnerabilities
None known

Snorkel Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Snorkel Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

100% escaped5 total outputs
Attack Surface

Snorkel Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
actionplugins_loadedincludes\class-snorkel.php:143
actionadmin_enqueue_scriptsincludes\class-snorkel.php:157
actionadmin_menuincludes\class-snorkel.php:158
actionadmin_initincludes\class-snorkel.php:163
actionupdate_option_snorkelincludes\class-snorkel.php:165
actionwoocommerce_update_productincludes\class-snorkel.php:166
actionwp_enqueue_scriptsincludes\class-snorkel.php:181
actionwoocommerce_add_to_cartincludes\class-snorkel.php:183
actionwoocommerce_update_cartincludes\class-snorkel.php:184
actionwoocommerce_remove_cart_itemincludes\class-snorkel.php:185
actionwoocommerce_restore_cart_itemincludes\class-snorkel.php:186
actionwoocommerce_cart_emptiedincludes\class-snorkel.php:187
actionwoocommerce_new_orderincludes\class-snorkel.php:190
actionwoocommerce_update_orderincludes\class-snorkel.php:191
actionwoocommerce_order_partially_refundedincludes\class-snorkel.php:192
actionwoocommerce_order_refundedincludes\class-snorkel.php:193
actionwoocommerce_order_status_changedincludes\class-snorkel.php:194
actionwoocommerce_payment_completeincludes\class-snorkel.php:195
actionwoocommerce_new_customerincludes\class-snorkel.php:198
actionwoocommerce_update_customerincludes\class-snorkel.php:199
Maintenance & Trust

Snorkel Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedUnknown
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Snorkel Developer Profile

benjaminaschultz

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Snorkel

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/snorkel/css/snorkel-admin.css
Version Parameters
snorkel-admin.css?ver=

HTML / DOM Fingerprints

REST Endpoints
/wp-json/wp/v2/users/wp-json/wp/v2/users/me
FAQ

Frequently Asked Questions about Snorkel