SourceKnowledge Shopping Ads Security & Risk Analysis

wordpress.org/plugins/sourceknowledge-shopping-ads

The official WooCommerce SourceKnowledge Shopping Ads plugin helps store owners integrate WooCommerce with SourceKnowledge and reach in-market shopper …

10 active installs v1.0.8 PHP 7.0+ WP 5.0+ Updated Jul 14, 2021
e-commercesalessellstorewoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SourceKnowledge Shopping Ads Safe to Use in 2026?

Generally Safe

Score 85/100

SourceKnowledge Shopping Ads has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The sourceknowledge-shopping-ads plugin, version 1.0.8, demonstrates a generally good security posture in its static analysis. It boasts zero AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a remarkably small attack surface. The plugin also avoids dangerous functions, performs all SQL queries using prepared statements, and exhibits a high percentage of properly escaped output, indicating strong adherence to secure coding practices. The absence of file operations and its limited external HTTP requests further contribute to its secure design.

However, there are areas that warrant caution. The taint analysis revealed two flows with unsanitized paths, which, while not categorized as critical or high severity in this report, still represent a potential risk for unexpected behavior or data leakage if not handled with extreme care. The complete lack of nonce checks and capability checks on any potential entry points (though none were identified) is a significant concern. If any new entry points are introduced in future updates, they would likely be unprotected, creating vulnerabilities.

The plugin's vulnerability history is a significant strength, showing zero known CVEs and no recorded vulnerabilities. This suggests a history of stable and secure development. Overall, the plugin is built on a foundation of secure practices, but the presence of unsanitized paths in taint analysis and the absence of critical security checks like nonces and capability checks indicate potential weaknesses that could be exploited if new attack vectors are introduced.

Key Concerns

  • Taint flows with unsanitized paths
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

SourceKnowledge Shopping Ads Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

SourceKnowledge Shopping Ads Release Timeline

v1.0.8Current
v1.0.7
v1.0.6
v1.0.5
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

SourceKnowledge Shopping Ads Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
27 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

96% escaped28 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
link_site (includes\class-sokno-shopping-ads-request.php:78)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

SourceKnowledge Shopping Ads Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 18
actionwp_headincludes\class-sokno-shopping-ads-pixel.php:182
actionwp_headincludes\class-sokno-shopping-ads-pixel.php:189
actionpre_get_postsincludes\class-sokno-shopping-ads-pixel.php:190
actionwoocommerce_after_cartincludes\class-sokno-shopping-ads-pixel.php:191
actionwoocommerce_add_to_cartincludes\class-sokno-shopping-ads-pixel.php:192
actionwc_ajax_sokno_inject_add_to_cart_eventincludes\class-sokno-shopping-ads-pixel.php:193
actionwoocommerce_thankyouincludes\class-sokno-shopping-ads-pixel.php:194
actionwoocommerce_payment_completeincludes\class-sokno-shopping-ads-pixel.php:195
filterallowed_redirect_hostsincludes\class-sokno-shopping-ads-request.php:63
actionplugins_loadedincludes\class-sokno-shopping-ads.php:182
actionadmin_noticesincludes\class-sokno-shopping-ads.php:223
actionadmin_enqueue_scriptsincludes\class-sokno-shopping-ads.php:224
actionadmin_initincludes\class-sokno-shopping-ads.php:225
actionwp_enqueue_scriptsincludes\class-sokno-shopping-ads.php:243
actionwp_loadedincludes\class-sokno-shopping-ads.php:245
actionwoocommerce_before_cartincludes\class-sokno-shopping-ads.php:246
filterwoocommerce_integrationsincludes\class-sokno-shopping-ads.php:261
actionplugins_loadedincludes\class-sokno-shopping-ads.php:262
Maintenance & Trust

SourceKnowledge Shopping Ads Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedJul 14, 2021
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

SourceKnowledge Shopping Ads Developer Profile

SourceKnowledge

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SourceKnowledge Shopping Ads

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sourceknowledge-shopping-ads/public/css/sourceknowledge-shopping-ads-public.css/wp-content/plugins/sourceknowledge-shopping-ads/public/js/sourceknowledge-shopping-ads-public.js/wp-content/plugins/sourceknowledge-shopping-ads/admin/css/sokno-shopping-ads-admin.css/wp-content/plugins/sourceknowledge-shopping-ads/admin/js/sokno-shopping-ads-admin.js
Script Paths
/wp-content/plugins/sourceknowledge-shopping-ads/public/js/sourceknowledge-shopping-ads-public.js/wp-content/plugins/sourceknowledge-shopping-ads/admin/js/sokno-shopping-ads-admin.js
Version Parameters
sourceknowledge-shopping-ads/public/css/sourceknowledge-shopping-ads-public.css?ver=sourceknowledge-shopping-ads/public/js/sourceknowledge-shopping-ads-public.js?ver=sourceknowledge-shopping-ads/admin/css/sokno-shopping-ads-admin.css?ver=sourceknowledge-shopping-ads/admin/js/sokno-shopping-ads-admin.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- SourceKnowledge Shopping Ads -->
Data Attributes
data-sokno-link-id
JS Globals
sokno_shopping_ads_public_vars
FAQ

Frequently Asked Questions about SourceKnowledge Shopping Ads