
Rejoiner for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woocommerce-rejoinerCreate a seamless customer journey across email, SMS & direct mail.
Is Rejoiner for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Rejoiner for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "woocommerce-rejoiner" v2.4.7 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates strong adherence to secure coding practices regarding SQL queries, all of which are properly prepared, and all output is correctly escaped, indicating protection against common injection and XSS vulnerabilities. There are no recorded vulnerabilities in its history, suggesting a generally well-maintained codebase.
However, significant concerns arise from the identified attack surface. The plugin exposes two AJAX handlers, and critically, both lack authentication checks. This directly translates to an unprotected entry point, posing a substantial risk for unauthorized access or manipulation. The absence of nonce checks on these AJAX actions further exacerbates this vulnerability, making it easier for attackers to initiate actions without proper validation. While taint analysis shows no critical or high severity flows, the unprotected AJAX endpoints are a prime target for exploitation, potentially allowing for actions that, while not directly leading to critical data breaches in this specific analysis, could still be abused for denial-of-service or unauthorized operations.
In conclusion, the plugin's strengths lie in its robust handling of database queries and output sanitization. However, the lack of authentication on its AJAX endpoints represents a significant security weakness that outweighs these positive aspects. The absence of historical vulnerabilities is encouraging but does not negate the immediate risk posed by the current unprotected attack vectors. Remediation of these unprotected AJAX handlers is strongly recommended.
Key Concerns
- Unprotected AJAX handlers
- Missing nonce checks on AJAX
Rejoiner for WooCommerce Security Vulnerabilities
Rejoiner for WooCommerce Code Analysis
Output Escaping
Rejoiner for WooCommerce Attack Surface
AJAX Handlers 2
WordPress Hooks 19
Maintenance & Trust
Rejoiner for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Rejoiner for WooCommerce Alternatives
CartStack for WooCommerce
cartstack-for-woocommerce
CartStack is the leading abandoned cart & customer recovery software for the WooCommerce platform.
Campaigner Email Marketing
campaigner-email-marketing
An easy-to-use email marketing plugin to recover abandoned carts, notify customers about back-in-stock items, and grow your contact list.
Cart Rescue – Abandoned Cart Recovery for WooCommerce
cart-rescue-abandoned-cart-recovery
A complete abandoned cart recovery solution to grow your business. Features a premium UI, email templates, and detailed reports.
Add-On for Gravity Forms + Rejoiner
gf-rejoiner
This plugin allows you to connect your forms created in Gravity Forms to the Rejoiner email platform.
MailerLite – WooCommerce integration
woo-mailerlite
Powerful e-commerce email marketing tools that are easy to use. Grow your store with automated emails, pop-ups, product blocks, sales tracking + more.
Rejoiner for WooCommerce Developer Profile
5 plugins · 150 total installs
How We Detect Rejoiner for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woocommerce-rejoiner/assets/css/woocommerce-rejoiner.css/wp-content/plugins/woocommerce-rejoiner/assets/js/woocommerce-rejoiner.jshttps://cdn.rejoiner.com/js/v4/rj2.lib.jswoocommerce-rejoiner/assets/css/woocommerce-rejoiner.css?ver=woocommerce-rejoiner/assets/js/woocommerce-rejoiner.js?ver=HTML / DOM Fingerprints
data-rejoiner-iddata-rejoiner-domaindata-rejoiner-api-keywindow.Rejoiner