StoreRadar – Analytics for WooCommerce Security & Risk Analysis

wordpress.org/plugins/storeradar-analytics-for-woocommerce

The fast WooCommerce analytics and reporting plugin that turns your store data into actionable insights. Real-time dashboards, WooCommerce reports, an …

0 active installs v1.1.3 PHP 7.4+ WP 5.0+ Updated Feb 26, 2026
product-reportsstock-velocitysubscription-reportswoocommerce-analyticswoocommerce-reports
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is StoreRadar – Analytics for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

StoreRadar – Analytics for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "storeradar-analytics-for-woocommerce" plugin v1.1.3 exhibits a generally strong security posture based on the provided static analysis. The absence of any known CVEs and the consistent use of prepared statements for all SQL queries are significant strengths. Furthermore, the plugin demonstrates good practices by implementing nonce checks and capability checks for a majority of its operations, and the majority of output is properly escaped, mitigating common cross-site scripting (XSS) risks. The limited attack surface and lack of taint flows with unsanitized paths are also positive indicators.

However, there are a few areas that warrant attention. The presence of file operations and external HTTP requests, while only one each, could introduce vulnerabilities if not handled with extreme care regarding input validation and sanitization, even though no specific taint flows were identified. The fact that not 100% of outputs are escaped, while the percentage is high, still leaves a small margin for potential XSS vulnerabilities. The absence of any recorded vulnerabilities in its history is encouraging, suggesting a history of secure development, but it's important to remember that past security does not guarantee future security.

In conclusion, this plugin appears to be developed with security in mind, adhering to many best practices. The reported data indicates a low overall risk. The primary potential concerns, though not explicitly confirmed as vulnerabilities in this analysis, lie in the secure handling of file operations and external requests, and the minor percentage of unescaped output. Continuous vigilance and updates are always recommended for any plugin.

Key Concerns

  • Not all outputs are properly escaped
  • File operations detected
  • External HTTP requests detected
Vulnerabilities
None known

StoreRadar – Analytics for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

StoreRadar – Analytics for WooCommerce Release Timeline

v1.1.3Current
v1.1.2
v1.1.1
v1.1.0
v1.0.16
v1.0.15
v1.0.14
v1.0.13
v1.0.12
v1.0.11
v1.0.10
v1.0.9
v1.0.8
v1.0.7
v1.0.6
v1.0.5
v1.0.4
v1.0.3
v1.0.2
v1.0.1
Code Analysis
Analyzed Apr 16, 2026

StoreRadar – Analytics for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
17 prepared
Unescaped Output
11
52 escaped
Nonce Checks
2
Capability Checks
9
File Operations
1
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared17 total queries

Output Escaping

83% escaped63 total outputs
Attack Surface

StoreRadar – Analytics for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 47
actionadmin_headincludes/admin-ui.php:19
actionadd_meta_boxesincludes/admin-ui.php:20
actionrest_api_initincludes/api/analytics.php:28
actionwc_ajax_storeradar_trackincludes/api/analytics.php:31
actionrest_api_initincludes/api/auth.php:17
actionrest_api_initincludes/api/cart-sync.php:28
actionrest_api_initincludes/api/customers.php:27
actionrest_api_initincludes/api/logs.php:20
actionrest_api_initincludes/api/orders.php:28
actionrest_api_initincludes/api/products.php:33
actionrest_api_initincludes/api/refunds.php:33
actionrest_api_initincludes/api/subscriptions.php:43
actionstoreradar_cart_cleanupincludes/cart-tracker.php:47
actionstoreradar_record_traffic_eventincludes/cart-tracker.php:50
actionstoreradar_process_cart_syncincludes/cart-tracker.php:53
actionwoocommerce_store_api_checkout_order_processedincludes/cart-tracker.php:55
actionwoocommerce_checkout_order_processedincludes/cart-tracker.php:56
actionwp_loginincludes/cart-tracker.php:58
actionwoocommerce_checkout_processincludes/cart-tracker.php:63
actionwoocommerce_store_api_cart_update_customer_from_requestincludes/cart-tracker.php:64
actionwoocommerce_checkout_update_order_reviewincludes/cart-tracker.php:67
actionwoocommerce_after_checkout_validationincludes/cart-tracker.php:68
actionwoocommerce_add_to_cartincludes/cart-tracker.php:70
actionwoocommerce_applied_couponincludes/cart-tracker.php:71
actionwoocommerce_after_calculate_totalsincludes/cart-tracker.php:72
actionwoocommerce_cart_item_removedincludes/cart-tracker.php:74
actionwoocommerce_cart_item_restoredincludes/cart-tracker.php:75
actionwoocommerce_cart_emptiedincludes/cart-tracker.php:76
actionwoocommerce_payment_completeincludes/cart-tracker.php:78
actionwoocommerce_thankyouincludes/cart-tracker.php:79
actionwoocommerce_before_checkout_formincludes/cart-tracker.php:82
actionshutdownincludes/cart-tracker.php:134
actionrest_api_initincludes/storeradar-api.php:17
actionwoocommerce_subscription_status_updatedincludes/subscription-tracker.php:16
actionwoocommerce_subscription_payment_completeincludes/subscription-tracker.php:17
actionwoocommerce_subscription_payment_failedincludes/subscription-tracker.php:18
actionwoocommerce_subscription_renewal_payment_completeincludes/subscription-tracker.php:19
actionwoocommerce_subscription_date_updatedincludes/subscription-tracker.php:20
actionstoreradar_analytics_cleanupincludes/traffic-tracker.php:64
actionplugins_loadedstoreradar.php:39
filtercron_schedulesstoreradar.php:41
actionwp_enqueue_scriptsstoreradar.php:44
actionbefore_woocommerce_initstoreradar.php:60
actionstoreradar_heartbeatstoreradar.php:81
actionadmin_noticesstoreradar.php:83
actionadmin_noticesstoreradar.php:85
actionadmin_noticesstoreradar.php:88

Scheduled Events 4

storeradar_cart_cleanup
storeradar_record_traffic_event
storeradar_analytics_cleanup
storeradar_heartbeat
Maintenance & Trust

StoreRadar – Analytics for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 26, 2026
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

StoreRadar – Analytics for WooCommerce Developer Profile

StoreRadar

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect StoreRadar – Analytics for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/storeradar-analytics-for-woocommerce/assets/js/visitdata.umd.js/wp-content/plugins/storeradar-analytics-for-woocommerce/assets/js/storeradar-tracking.js
Script Paths
assets/js/visitdata.umd.jsassets/js/storeradar-tracking.js
Version Parameters
storeradar-analytics-for-woocommerce/storeradar.php?ver=storeradar-visitdata?ver=storeradar-tracking?ver=

HTML / DOM Fingerprints

Data Attributes
data-storeradar-trackingdata-storeradar-tracking-options
JS Globals
storeradar_tracking_params
FAQ

Frequently Asked Questions about StoreRadar – Analytics for WooCommerce