WP Centrico Security & Risk Analysis

wordpress.org/plugins/wp-centrico

This plugin allows you to manage the subscription to centrico, your users will be registered in centrico and will receive your newsletter.

10 active installs v1.1.6 PHP + WP 5.0.0+ Updated Jan 25, 2024
contacts-managementcrmemail-marketinggestione-contattisms-marketing
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Centrico Safe to Use in 2026?

Generally Safe

Score 85/100

WP Centrico has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The wp-centrico plugin v1.1.6 exhibits a mixed security posture, with some positive indicators but significant areas of concern. While the plugin has a small attack surface and no known CVEs, the static analysis reveals several weaknesses. The most concerning is the taint analysis, which identified 2 high-severity flows with unsanitized paths, indicating a potential for vulnerabilities if these flows are exploitable. Furthermore, a low percentage of output is properly escaped (29%), suggesting a risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce and capability checks on all entry points is a critical oversight, especially given the potential for malicious input via the identified taint flows.

The lack of vulnerability history is a positive sign, suggesting that the plugin has not been a frequent target or source of security issues. However, this should not overshadow the risks identified in the code analysis. The plugin has strengths in its limited attack surface and the use of prepared statements for a majority of its SQL queries. Nevertheless, the identified taint flows and inadequate output escaping present tangible security risks that need to be addressed. A balance of strengths and weaknesses means the plugin is not inherently insecure but requires immediate attention to its identified vulnerabilities to improve its overall security.

Key Concerns

  • High severity taint flows with unsanitized paths
  • Low percentage of properly escaped output
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

WP Centrico Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WP Centrico Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
5 prepared
Unescaped Output
36
15 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

63% prepared8 total queries

Output Escaping

29% escaped51 total outputs
Data Flows
5 unsanitized

Data Flow Analysis

5 flows5 with unsanitized paths
save_options (includes\woocommerce\view\settings.php:167)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP Centrico Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[centrico] includes\centrico-form.php:87
WordPress Hooks 6
actionadmin_menuincludes\centrico-settings.php:3
actionwidgets_initincludes\centrico-widget.php:139
actionwp_enqueue_scriptswp-centrico.php:18
actionwoocommerce_after_checkout_billing_formwp-centrico.php:80
actionwoocommerce_checkout_order_processedwp-centrico.php:81
actionwoocommerce_thankyouwp-centrico.php:82
Maintenance & Trust

WP Centrico Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedJan 25, 2024
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WP Centrico Developer Profile

ado2000

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Centrico

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-centrico/js/script.js

HTML / DOM Fingerprints

CSS Classes
Centrico_widget
Data Attributes
disabledInput
JS Globals
Centrico_Widget
Shortcode Output
[centrico]
FAQ

Frequently Asked Questions about WP Centrico