Woopra Analytics Plugin Security & Risk Analysis

wordpress.org/plugins/woopra

Track who is on your website, what pages they're browsing, actions they're taking, articles they're reading and more.

1K active installs v3.3.2 PHP 7.4+ WP 2.7.0+ Updated Jul 23, 2025
analyticsfunnelsreal-timestatisticsstats
97
A · Safe
CVEs total2
Unpatched0
Last CVEOct 7, 2013
Safety Verdict

Is Woopra Analytics Plugin Safe to Use in 2026?

Generally Safe

Score 97/100

Woopra Analytics Plugin has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Oct 7, 2013Updated 8mo ago
Risk Assessment

The Woopra plugin version 3.3.2 presents a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and having no reported unpatched CVEs. The absence of dangerous functions and raw SQL queries are also strengths. However, significant concerns arise from the static analysis. A critical issue is the presence of an unprotected AJAX handler, which represents a direct entry point into the plugin's functionality without any authentication or capability checks, making it a prime target for unauthorized actions. Furthermore, a substantial portion (75%) of output is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is displayed without adequate sanitization. The plugin's history of critical and high severity vulnerabilities, specifically code injection and unrestricted file uploads, although dated, indicates a past propensity for severe security flaws, suggesting that even without current unpatched issues, a cautious approach is warranted.

While the plugin has addressed its past vulnerabilities and utilizes secure database practices, the uncovered unprotected AJAX endpoint and the high rate of unescaped output are critical security weaknesses in the current version. The historical prevalence of severe vulnerabilities should not be overlooked. Therefore, the overall risk is elevated due to these immediate exploitable conditions and the plugin's past security record, despite its strengths in other areas.

Key Concerns

  • Unprotected AJAX handler
  • High percentage of unescaped output
  • No nonce checks on AJAX handlers
  • Historical critical CVEs
  • Historical high severity CVEs
Vulnerabilities
2

Woopra Analytics Plugin Security Vulnerabilities

CVEs by Year

1 CVE in 2009
2009
1 CVE in 2013
2013
Patched Has unpatched

Severity Breakdown

Critical
1
High
1

2 total CVEs

WF-a22932d8-14d4-43a1-86ba-7afadc0bec1a-woopracritical · 9.8Improper Control of Generation of Code ('Code Injection')

Woopra Analytics Plugin < 1.4.3.2 - Remote Code Execution

Oct 7, 2013 Patched in 1.4.3.2 (3760d)
CVE-2009-4140high · 8.8Unrestricted Upload of File with Dangerous Type

Various Affected Software (Various Versions) - Arbitrary File Upload

Oct 21, 2009 Patched in 1.4.3.2 (5207d)
Code Analysis
Analyzed Mar 16, 2026

Woopra Analytics Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
4 escaped
Nonce Checks
0
Capability Checks
3
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

25% escaped16 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
woopra_http_request (woopra-php-sdk\woopra_tracker.php:218)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Woopra Analytics Plugin Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_wooprainc\admin.php:80
WordPress Hooks 22
actioninitinc\admin.php:67
actionadmin_enqueue_scriptsinc\admin.php:76
actionadmin_menuinc\admin.php:77
actionadmin_menuinc\admin.php:83
actionadmin_initinc\admin.php:84
actioninitinc\events.php:129
actioninitinc\frontend.php:33
actionwoopra_identifyinc\frontend.php:42
actionwoopra_trackinc\frontend.php:43
actioninitinc\frontend.php:47
actioncomment_postinc\frontend.php:67
actionuser_registerinc\frontend.php:70
actionwoocommerce_cart_loaded_from_sessioninc\frontend.php:88
actionwoocommerce_after_cart_item_quantity_updateinc\frontend.php:89
actionwoocommerce_before_cart_item_quantity_zeroinc\frontend.php:90
actionwoocommerce_add_to_cartinc\frontend.php:91
actionwoocommerce_cart_item_removedinc\frontend.php:92
actionwoocommerce_checkout_order_processedinc\frontend.php:95
actionwoocommerce_applied_couponinc\frontend.php:98
actionadmin_headinc\frontend.php:374
actionwp_headinc\frontend.php:376
actionwp_headinc\frontend.php:378
Maintenance & Trust

Woopra Analytics Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 23, 2025
PHP min version7.4
Downloads215K

Community Trust

Rating74/100
Number of ratings6
Active installs1K
Developer Profile

Woopra Analytics Plugin Developer Profile

eliekhoury

1 plugin · 1K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
4484 days
View full developer profile
Detection Fingerprints

How We Detect Woopra Analytics Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woopra/css/woopra-admin.css/wp-content/plugins/woopra/css/woopra-frontend.css/wp-content/plugins/woopra/js/woopra-admin.js/wp-content/plugins/woopra/js/woopra-frontend.js/wp-content/plugins/woopra/js/woopra-admin-settings.js
Script Paths
/wp-content/plugins/woopra/js/woopra-admin.js/wp-content/plugins/woopra/js/woopra-frontend.js/wp-content/plugins/woopra/js/woopra-admin-settings.js/wp-content/plugins/woopra/woopra-php-sdk/woopra_tracker.php
Version Parameters
woopra/css/woopra-admin.css?ver=woopra/css/woopra-frontend.css?ver=woopra/js/woopra-admin.js?ver=woopra/js/woopra-frontend.js?ver=woopra/js/woopra-admin-settings.js?ver=

HTML / DOM Fingerprints

CSS Classes
woopra-admin-pagewoopra-settings-sectionwoopra-event-list
HTML Comments
<!-- BEGIN Woopra Tracking Code --><!-- END Woopra Tracking Code --><!-- Woopra Admin Options --><!-- Woopra Event Settings -->
Data Attributes
data-woopra-tracking-iddata-woopra-eventdata-woopra-label
JS Globals
WoopraAdminWoopraFrontendwoopra_tracker
FAQ

Frequently Asked Questions about Woopra Analytics Plugin