TrackGenie Security & Risk Analysis

wordpress.org/plugins/trackgenie

Shipment tracking integration with the TrackGenie SaaS platform for WooCommerce stores.

0 active installs v7.4.0 PHP 7.4+ WP 6.2+ Updated Feb 26, 2026
order-trackingshipmentsshippingtrackingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is TrackGenie Safe to Use in 2026?

Generally Safe

Score 100/100

TrackGenie has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin 'trackgenie' v7.4.0 exhibits a strong security posture based on the provided static analysis and vulnerability history. All identified entry points, including AJAX handlers, are protected by nonce and capability checks. The code demonstrates excellent practices with 100% of SQL queries utilizing prepared statements and nearly all output being properly escaped. There are no detected dangerous functions, file operations, or taint flows, indicating a lack of common vulnerability patterns like SQL injection or arbitrary file access within the analyzed code paths. The absence of any recorded CVEs further reinforces its current secure state. However, the presence of three external HTTP requests, while not inherently a vulnerability, represents a potential, albeit low, attack vector if the target endpoints are compromised or misused. The plugin's limited vulnerability history suggests a consistent focus on security by its developers, which is a significant positive indicator.

Key Concerns

  • External HTTP requests present a minor risk
Vulnerabilities
None known

TrackGenie Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

TrackGenie Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
128 escaped
Nonce Checks
11
Capability Checks
14
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

99% escaped129 total outputs
Attack Surface

TrackGenie Attack Surface

Entry Points11
Unprotected0

AJAX Handlers 11

authwp_ajax_trackgenie_start_pairingsrc\class-ajax.php:66
authwp_ajax_trackgenie_check_pairing_statussrc\class-ajax.php:67
authwp_ajax_trackgenie_disconnectsrc\class-ajax.php:68
authwp_ajax_trackgenie_refresh_carrierssrc\class-ajax.php:69
authwp_ajax_trackgenie_save_trackingsrc\class-ajax.php:70
authwp_ajax_trackgenie_refresh_order_tracking_statussrc\class-ajax.php:71
authwp_ajax_trackgenie_bulk_refresh_order_tracking_statusessrc\class-ajax.php:72
authwp_ajax_trackgenie_delete_shipmentsrc\class-ajax.php:73
authwp_ajax_trackgenie_get_order_itemssrc\class-ajax.php:74
authwp_ajax_trackgenie_get_shipment_datasrc\class-ajax.php:75
authwp_ajax_trackgenie_update_shipmentsrc\class-ajax.php:76
WordPress Hooks 13
actionadmin_menusrc\class-admin-settings.php:24
actionload-toplevel_page_trackgenie-settingssrc\class-admin-settings.php:26
filtermanage_woocommerce_page_wc-orders_columnssrc\class-order-list-columns.php:47
actionmanage_woocommerce_page_wc-orders_custom_columnsrc\class-order-list-columns.php:48
filtermanage_edit-shop_order_columnssrc\class-order-list-columns.php:51
actionmanage_shop_order_posts_custom_columnsrc\class-order-list-columns.php:52
actionadd_meta_boxessrc\class-order-metabox.php:22
actiontrackgenie_sync_connection_statussrc\class-pairing.php:33
actionadmin_enqueue_scriptssrc\class-trackgenie-plugin.php:95
actionbefore_woocommerce_inittrackgenie.php:37
actionadmin_noticestrackgenie.php:166
actionadmin_noticestrackgenie.php:172
actionplugins_loadedtrackgenie.php:184

Scheduled Events 1

trackgenie_sync_connection_status
Maintenance & Trust

TrackGenie Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 26, 2026
PHP min version7.4
Downloads156

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

TrackGenie Developer Profile

trackgenie

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TrackGenie

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/trackgenie/assets/css/admin.css/wp-content/plugins/trackgenie/assets/css/frontend.css/wp-content/plugins/trackgenie/assets/js/admin.js/wp-content/plugins/trackgenie/assets/js/frontend.js/wp-content/plugins/trackgenie/assets/js/jquery.twbs.pagination.min.js/wp-content/plugins/trackgenie/assets/js/tracking-widget.js/wp-content/plugins/trackgenie/assets/js/vue.js
Version Parameters
trackgenie/assets/css/admin.css?ver=trackgenie/assets/css/frontend.css?ver=trackgenie/assets/js/admin.js?ver=trackgenie/assets/js/frontend.js?ver=trackgenie/assets/js/jquery.twbs.pagination.min.js?ver=trackgenie/assets/js/tracking-widget.js?ver=trackgenie/assets/js/vue.js?ver=

HTML / DOM Fingerprints

CSS Classes
trackgenie-admin-settingstrackgenie-order-metaboxtrackgenie-tracking-widgettg-settings-sectiontg-settings-fieldtg-order-metabox-wraptg-tracking-info
HTML Comments
<!-- TrackGenie Admin Settings --><!-- TrackGenie Order Metabox --><!-- TrackGenie Tracking Widget -->
Data Attributes
data-trackgenie-order-iddata-trackgenie-tracking-urldata-trackgenie-carrierdata-trackgenie-tracking-number
JS Globals
trackgenie_admin_paramstrackgenie_frontend_paramsTrackGenieApp
REST Endpoints
/wp-json/trackgenie/v1/settings/wp-json/trackgenie/v1/shipment/track
Shortcode Output
[trackgenie_tracking_widget]
FAQ

Frequently Asked Questions about TrackGenie