Wask Marketing Security & Risk Analysis

wordpress.org/plugins/wask-marketing

Manage your Facebook, Google assets and facebook pixel, facebook audience easily.

10 active installs v1.23 PHP + WP 4.7+ Updated Oct 7, 2022
facebook-adsfacebook-pixelgoogle-analyticinstagram-adsremarketing-audience
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Wask Marketing Safe to Use in 2026?

Generally Safe

Score 85/100

Wask Marketing has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "wask-marketing" plugin v1.23 exhibits a concerning security posture due to a significant number of unprotected AJAX handlers and a lack of capability checks. The static analysis reveals that all 5 AJAX handlers are exposed without authentication, creating a substantial attack surface that could be exploited by unauthenticated users. Furthermore, the plugin's SQL queries are not using prepared statements, which is a significant risk for SQL injection vulnerabilities, especially when combined with the lack of input sanitization indicated by the taint analysis.

The taint analysis shows 6 out of 8 flows with unsanitized paths, suggesting potential issues with how data is handled within the plugin. While there are no known CVEs or recorded vulnerabilities for this plugin, this lack of history does not negate the immediate risks identified in the static analysis. The plugin's strengths lie in its lack of dangerous functions and file operations, and the presence of some output escaping. However, these are overshadowed by the critical security concerns related to unprotected entry points and insecure data handling practices.

Overall, "wask-marketing" v1.23 presents a high risk due to its easily exploitable AJAX endpoints and potential for SQL injection. The absence of proper authorization and sanitization on these critical entry points, coupled with the use of raw SQL queries, makes it a prime target for malicious actors. The plugin needs significant improvements in its authentication, authorization, and data sanitization mechanisms to be considered secure.

Key Concerns

  • 5 AJAX handlers without auth checks
  • 6 Flows with unsanitized paths
  • 1 SQL query using 0% prepared statements
  • 31% properly escaped output
  • 0 Capability checks
  • 2 Nonce checks (out of 5 entry points)
Vulnerabilities
None known

Wask Marketing Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Wask Marketing Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
47
21 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
10
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

31% escaped68 total outputs
Data Flows
6 unsanitized

Data Flow Analysis

8 flows6 with unsanitized paths
<audience_list> (views\audience_list.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
5 unprotected

Wask Marketing Attack Surface

Entry Points5
Unprotected5

AJAX Handlers 5

authwp_ajax_add_facebook_pixelwask-marketing.php:28
authwp_ajax_remove_facebook_pixelwask-marketing.php:29
authwp_ajax_create_custom_audiencewask-marketing.php:30
authwp_ajax_create_lookalike_audiencewask-marketing.php:31
authwp_ajax_delete_audiencewask-marketing.php:32
WordPress Hooks 3
actionadmin_menuwask-marketing.php:25
actionadmin_enqueue_scriptswask-marketing.php:26
actionwp_headwask-marketing.php:27
Maintenance & Trust

Wask Marketing Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedOct 7, 2022
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Wask Marketing Developer Profile

waskdeveloper

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Wask Marketing

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wask-marketing/assets/css/admin.css/wp-content/plugins/wask-marketing/assets/css/sweetalert2.css/wp-content/plugins/wask-marketing/assets/js/sweetalert2.js/wp-content/plugins/wask-marketing/assets/js/facebook_countries.js
Script Paths
/wp-content/plugins/wask-marketing/assets/js/sweetalert2.js/wp-content/plugins/wask-marketing/assets/js/facebook_countries.js

HTML / DOM Fingerprints

JS Globals
wask_ajax_object
REST Endpoints
/wp-json/wask/v1/settings/wp-json/wask/v1/save-settings/wp-json/wask/v1/create-custom-audience/wp-json/wask/v1/create-lookalike-audience
FAQ

Frequently Asked Questions about Wask Marketing