TradeTracker Connect Security & Risk Analysis
wordpress.org/plugins/tradetracker-connectTradeTracker Connect enables Merchants using WooCommerce to start selling products or services using TradeTracker's Affiliate Marketing Network.
Is TradeTracker Connect Safe to Use in 2026?
Generally Safe
Score 100/100TradeTracker Connect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tradetracker-connect" plugin v2.2.12 exhibits a generally good security posture based on the static analysis. There are no reported vulnerabilities (CVEs) in its history, and the code analysis shows no dangerous functions, a strong adherence to prepared statements for SQL queries, and a high percentage of properly escaped output. The absence of critical or high-severity taint flows is also a positive indicator. However, there are areas that warrant attention and potential risk.
The presence of two flows with "unsanitized paths" in the taint analysis, even without a critical or high severity classification, suggests a potential for path traversal vulnerabilities if these paths are used in file operations without proper sanitization or validation. While the plugin performs file operations and has nonce and capability checks, the "unsanitized paths" are a specific concern that should be investigated further. The limited attack surface and absence of unprotected entry points are strong mitigating factors, but the identified taint flows represent the most concrete area of concern from the static analysis.
Overall, the plugin appears to be developed with security in mind, given its clean vulnerability history and robust use of prepared statements and output escaping. The lack of recorded vulnerabilities suggests a diligent approach to security. The primary weakness lies in the identified "unsanitized paths" within the taint analysis, which, while not currently categorized as critical, could become a vector for attack if exploited. Addressing these specific taint flows should be a priority to further strengthen the plugin's security.
Key Concerns
- Taint flow with unsanitized paths
- File operations detected
- Cron events detected
TradeTracker Connect Security Vulnerabilities
TradeTracker Connect Code Analysis
Output Escaping
Data Flow Analysis
TradeTracker Connect Attack Surface
WordPress Hooks 18
Scheduled Events 2
Maintenance & Trust
TradeTracker Connect Maintenance & Trust
Maintenance Signals
Community Trust
TradeTracker Connect Alternatives
Webshop NL Connect
webshop-nl-connect
A WooCommerce integration plugin for external order tracking, product feed generation.
Advanced Shipment Tracking for WooCommerce
woo-advanced-shipment-tracking
Add shipment tracking info to WooCommerce orders, send tracking numbers to customers via email, and let them track deliveries from My Account.
Pixel Manager for WooCommerce – Conversion Tracking, Google Ads, GA4, TikTok, Dynamic Remarketing
woocommerce-google-adwords-conversion-tracking-tag
Conversion tracking for WooCommerce. Google Ads, GA4, Meta/Facebook Pixel, TikTok & more. Recover 30% more conversions with server-side tracking!
Conversios: Google Analytics (GA4), Google Ads, Conversion and Analytics Tracking for Multi-Channels
enhanced-e-commerce-for-woocommerce-store
Track GA4 Analytics, Google Ads, Microsoft Ads, & Conversion with server-side tracking (CAPI) & product feed to improve ROAS, reports for WooCommerce.
Orders Tracking for WooCommerce
woo-orders-tracking
Easily import/manage your tracking numbers, add tracking numbers to PayPal and send email notifications to customers.
TradeTracker Connect Developer Profile
1 plugin · 200 total installs
How We Detect TradeTracker Connect
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tradetracker-connect/admin/css/tradetracker-connect-admin.css/wp-content/plugins/tradetracker-connect/admin/js/tradetracker-connect-admin.js/wp-content/plugins/tradetracker-connect/admin/js/tradetracker-connect-admin.jstradetracker-connect-admin.css?ver=tradetracker-connect-admin.js?ver=HTML / DOM Fingerprints
data-tradetracker-nonce="tradetracker_connect_nonce"Tradetracker