Conversion Tracking for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woocommerce-conversion-trackingAdds various conversion tracking codes to cart, checkout, registration success and product page on WooCommerce
Is Conversion Tracking for WooCommerce Safe to Use in 2026?
Generally Safe
Score 98/100Conversion Tracking for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "woocommerce-conversion-tracking" plugin version 2.1.5 presents a mixed security posture. On the positive side, it demonstrates good practices in several areas, including the absence of dangerous functions, 100% of SQL queries utilizing prepared statements, and a robust number of nonce and capability checks. File operations and bundled libraries are also absent, which can reduce the attack surface in those categories. However, there are notable concerns. The presence of an AJAX handler without authentication checks is a significant risk, creating a direct entry point for unauthenticated actions. While taint analysis shows no current critical or high severity flows, the historically high number of reported CVEs (4 total) with a significant portion being medium or high severity (1 high, 3 medium) is a strong indicator of past security weaknesses. Common vulnerability types like missing authorization and cross-site scripting further reinforce the need for caution. Despite the current lack of critical vulnerabilities and good practices in certain code aspects, the plugin's history of past vulnerabilities and the identified unprotected AJAX handler warrant careful consideration and vigilance.
Key Concerns
- Unprotected AJAX handler found
- High number of past vulnerabilities (4 total)
- Past high severity vulnerabilities (1 high, 3 medium)
- Past vulnerabilities include missing authorization and XSS
- Output escaping not fully implemented (78%)
Conversion Tracking for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
WooCommerce Conversion Tracking <= 2.0.11 - Missing Authorization via wcct_install_happy_addons
WooCommerce Conversion Tracking <= 2.0.11 - Missing Authorization
Appsero <= 1.2.1 - Missing Authorization
WooCommerce Conversion Tracking <= 2.0.4 - Cross-Site Request Forgery and Cross-Site Scripting
Conversion Tracking for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Conversion Tracking for WooCommerce Attack Surface
AJAX Handlers 4
WordPress Hooks 46
Maintenance & Trust
Conversion Tracking for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Conversion Tracking for WooCommerce Alternatives
Conversion Tracking for WooCommerce
conversion-tracking-for-woocommerce
Outputs WooCommerce variables on the cart, checkout, and order confirmation pages as a global named WCPAYLOAD to make integration with analytics and c …
Pythia for Woocommerce
pythia-for-woocommerce
Pythia for Woocommerce is a Tracking Tool solution built on WooCommerce.
Klarna for WooCommerce
klarna-payments-for-woocommerce
Grow your business for increased sales and enhanced shopping experiences at no extra costs.
Kustom Checkout for WooCommerce
klarna-checkout-for-woocommerce
The leading checkout in the Nordics, built for higher conversion and returning shoppers. Easy to integrate, supports Klarna and all popular payment me …
Japanized for WooCommerce
woocommerce-for-japan
Essential Japanese localization toolkit for WooCommerce - adds address formats, payment methods, delivery scheduling, and legal compliance.
Conversion Tracking for WooCommerce Developer Profile
20 plugins · 113K total installs
How We Detect Conversion Tracking for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woocommerce-conversion-tracking/assets/css/frontend.css/wp-content/plugins/woocommerce-conversion-tracking/assets/js/frontend.js/wp-content/plugins/woocommerce-conversion-tracking/assets/js/frontend.jswoocommerce-conversion-tracking/assets/css/frontend.css?ver=woocommerce-conversion-tracking/assets/js/frontend.js?ver=HTML / DOM Fingerprints
<!-- weDevs Conversion Tracking --><!-- End weDevs Conversion Tracking --><!-- weDevs Conversion Tracking Hook --><!-- End weDevs Conversion Tracking Hook -->+2 moredata-wcct-settingswcct_params