Rejoiner for WooCommerce Security & Risk Analysis

wordpress.org/plugins/woocommerce-rejoiner

Create a seamless customer journey across email, SMS & direct mail.

10 active installs v2.4.7 PHP + WP 6.6+ Updated Oct 20, 2025
abandoned-cartcart-abandonment-emailecommerceemail-marketingremarketing
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Rejoiner for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Rejoiner for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "woocommerce-rejoiner" v2.4.7 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates strong adherence to secure coding practices regarding SQL queries, all of which are properly prepared, and all output is correctly escaped, indicating protection against common injection and XSS vulnerabilities. There are no recorded vulnerabilities in its history, suggesting a generally well-maintained codebase.

However, significant concerns arise from the identified attack surface. The plugin exposes two AJAX handlers, and critically, both lack authentication checks. This directly translates to an unprotected entry point, posing a substantial risk for unauthorized access or manipulation. The absence of nonce checks on these AJAX actions further exacerbates this vulnerability, making it easier for attackers to initiate actions without proper validation. While taint analysis shows no critical or high severity flows, the unprotected AJAX endpoints are a prime target for exploitation, potentially allowing for actions that, while not directly leading to critical data breaches in this specific analysis, could still be abused for denial-of-service or unauthorized operations.

In conclusion, the plugin's strengths lie in its robust handling of database queries and output sanitization. However, the lack of authentication on its AJAX endpoints represents a significant security weakness that outweighs these positive aspects. The absence of historical vulnerabilities is encouraging but does not negate the immediate risk posed by the current unprotected attack vectors. Remediation of these unprotected AJAX handlers is strongly recommended.

Key Concerns

  • Unprotected AJAX handlers
  • Missing nonce checks on AJAX
Vulnerabilities
None known

Rejoiner for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Rejoiner for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
22 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
5
Bundled Libraries
0

Output Escaping

100% escaped22 total outputs
Attack Surface
2 unprotected

Rejoiner for WooCommerce Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_rejoiner_syncincludes\class-wc-rejoiner.php:81
noprivwp_ajax_rejoiner_syncincludes\class-wc-rejoiner.php:82
WordPress Hooks 19
actionwoocommerce_update_options_integration_wc_rejoinerincludes\class-wc-rejoiner.php:68
actionwp_loadedincludes\class-wc-rejoiner.php:69
actionwp_footerincludes\class-wc-rejoiner.php:72
actionwoocommerce_payment_completeincludes\class-wc-rejoiner.php:75
actionwoocommerce_thankyouincludes\class-wc-rejoiner.php:78
filterwoocommerce_checkout_fieldsincludes\class-wc-rejoiner.php:88
actionwoocommerce_checkout_order_processedincludes\class-wc-rejoiner.php:89
actionwoocommerce_register_formincludes\class-wc-rejoiner.php:93
actionwoocommerce_created_customerincludes\class-wc-rejoiner.php:94
actionwoocommerce_edit_account_form_startincludes\class-wc-rejoiner.php:98
actionwoocommerce_save_account_detailsincludes\class-wc-rejoiner.php:99
filterrejoiner_returnurlincludes\class-wc-rejoiner.php:105
filterwc_rejoiner_cart_item_namesample-functions.php:5
filterwc_rejoiner_cart_item_variantsample-functions.php:15
filterwc_rejoiner_thumb_sizesample-functions.php:26
filterwc_rejoiner_cart_item_attributessample-functions.php:36
filterrejoiner_sessionmetadatasample-functions.php:58
filterwc_rejoiner_optin_list_idsample-functions.php:70
filterwoocommerce_integrationswoocommerce-rejoiner.php:26
Maintenance & Trust

Rejoiner for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 20, 2025
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings4
Active installs10
Developer Profile

Rejoiner for WooCommerce Developer Profile

Jackson Whelan

5 plugins · 150 total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Rejoiner for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woocommerce-rejoiner/assets/css/woocommerce-rejoiner.css/wp-content/plugins/woocommerce-rejoiner/assets/js/woocommerce-rejoiner.js
Script Paths
https://cdn.rejoiner.com/js/v4/rj2.lib.js
Version Parameters
woocommerce-rejoiner/assets/css/woocommerce-rejoiner.css?ver=woocommerce-rejoiner/assets/js/woocommerce-rejoiner.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-rejoiner-iddata-rejoiner-domaindata-rejoiner-api-key
JS Globals
window.Rejoiner
FAQ

Frequently Asked Questions about Rejoiner for WooCommerce