WUOZ Connect Security & Risk Analysis

wordpress.org/plugins/wuoz-connect

A Plugin to connect WUOZ with WordPress and Woocommerce website.

0 active installs v1.0.0 PHP 7.4+ WP 5.0+ Updated Feb 25, 2026
automationmarketingpixeltrackingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WUOZ Connect Safe to Use in 2026?

Generally Safe

Score 100/100

WUOZ Connect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "wuoz-connect" v1.0.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates strong practices by utilizing prepared statements for all SQL queries, avoiding dangerous functions, and having no recorded vulnerabilities or taint analysis issues. The presence of nonce and capability checks on most entry points is also a good sign. However, there are notable concerns, primarily stemming from the attack surface. Two out of nine total entry points, specifically AJAX handlers, lack authentication checks. This could allow unauthenticated users to trigger these functions, potentially leading to unintended behavior or even exploitation if the functions themselves have exploitable logic.

While the vulnerability history is clean, indicating a lack of publicly known issues, this should not lead to complacency. The presence of unprotected AJAX endpoints represents a potential attack vector that could be leveraged by an attacker if the underlying functionality is susceptible. The 53% proper output escaping rate for 133 total outputs is also a concern; a significant number of outputs are not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is reflected directly in the output.

In conclusion, "wuoz-connect" v1.0.0 has strengths in its database interaction and lack of known vulnerabilities. However, the unprotected AJAX handlers and the moderate rate of unescaped output present clear security weaknesses that require immediate attention. Addressing these specific issues would significantly improve the plugin's overall security.

Key Concerns

  • AJAX handlers without auth checks
  • Moderate output escaping (53% proper)
Vulnerabilities
None known

WUOZ Connect Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WUOZ Connect Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
63
70 escaped
Nonce Checks
5
Capability Checks
4
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

53% escaped133 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
connect_api_key (inc\settings\settings.php:61)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

WUOZ Connect Attack Surface

Entry Points9
Unprotected2

AJAX Handlers 5

authwp_ajax_wuoz_single_product_viewinc\ajax\wuoz-single-product-view.php:9
noprivwp_ajax_wuoz_single_product_viewinc\ajax\wuoz-single-product-view.php:10
authwp_ajax_wuoz_toggle_meta_eventinc\ajax\wuoz-toogle-meta-tracking.php:9
authwp_ajax_wuoz_wztm_fp_eventsinc\ajax\wuoz-wztm-fp-events.php:11
noprivwp_ajax_wuoz_wztm_fp_eventsinc\ajax\wuoz-wztm-fp-events.php:12

REST API Routes 4

post/wp-json/wuoz/v1/disconnectinc\rest-api\v1\disconnect.php:8
post/wp-json/wuoz/v1/livechatinc\rest-api\v1\livechat.php:8
post/wp-json/wuoz/v1/meta-pixelinc\rest-api\v1\meta-pixel.php:8
post/wp-json/wuoz/v1/snippetinc\rest-api\v1\snippets.php:8
WordPress Hooks 17
actionwpinc\cron\abandoned-cart.php:18
filtercron_schedulesinc\cron\abandoned-cart.php:19
actionwp_footerinc\meta-pixel-detect\detect.php:8
actionrest_api_initinc\rest-api\BaseEndpoint.php:11
actionwp_enqueue_scriptsinc\scripts\scripts.php:9
actionadmin_menuinc\settings\settings.php:14
actionadmin_initinc\settings\settings.php:15
actionadmin_initinc\settings\settings.php:16
actionadmin_initinc\settings\settings.php:17
actionadmin_initinc\settings\settings.php:18
actionadmin_enqueue_scriptsinc\settings\settings.php:19
actionwoocommerce_cart_updatedinc\woocommerce\track-abandoned.php:9
actionwoocommerce_product_set_stock_statusinc\woocommerce\track-stock-status.php:10
actionwoocommerce_add_to_cartinc\woocommerce\wztm-backend.php:13
actionwoocommerce_checkout_order_processedinc\woocommerce\wztm-backend.php:14
actionwp_enqueue_scriptsinc\wztm-firstparty.php:9
actionwp_enqueue_scriptswuoz-connect.php:22
Maintenance & Trust

WUOZ Connect Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 25, 2026
PHP min version7.4
Downloads109

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

WUOZ Connect Developer Profile

Wuoz

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WUOZ Connect

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wuoz-connect/static/scripts.js/wp-content/plugins/wuoz-connect/static/utm-propagation.js/wp-content/plugins/wuoz-connect/static/tailwind.min.js/wp-content/plugins/wuoz-connect/static/lucide.min.js/wp-content/plugins/wuoz-connect/static/admin.js/wp-content/plugins/wuoz-connect/static/img/img.png
Script Paths
wuoz-snippet-/js/livechat-widget.js/snippet.js?id=
Version Parameters
wuoz-script?ver=wuoz-admin?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- phpcs:ignore --><!-- phpcs:ignore WordPress.Security.NonceVerification.Recommended --><!-- phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -->
Data Attributes
data-post-id
JS Globals
window.WuozChatwindow.wuozAdmin
FAQ

Frequently Asked Questions about WUOZ Connect