zenloop for WooCommerce – Net Promoter Score (NPS) platform Security & Risk Analysis

wordpress.org/plugins/zenloop-woocommerce-nps-platform

zenloop for WooCommerce is the official zenloop.com plugin. It connects zenloop’s Net Promoter Score (NPS) platform with your WooCommerce shop.

10 active installs v3.1 PHP 7.0+ WP 5.6+ Updated Apr 5, 2023
feedbacknet-promoter-scorenpssurveys
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is zenloop for WooCommerce – Net Promoter Score (NPS) platform Safe to Use in 2026?

Generally Safe

Score 85/100

zenloop for WooCommerce – Net Promoter Score (NPS) platform has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The zenloop-woocommerce-nps-platform plugin v3.1 exhibits a generally strong security posture based on the provided static analysis. The absence of identified dangerous functions, raw SQL queries, file operations, and taint flows indicates a proactive approach to secure coding practices. The plugin also has no recorded vulnerabilities, which is a significant positive sign. However, there are areas for improvement. The lack of nonce checks and capability checks on identified entry points, such as the single cron event, presents a potential concern. While the attack surface is currently small and all entry points are protected from a high-level perspective (0 unprotected), the absence of specific security checks means that if an attacker were to find a way to trigger the cron event, there are no built-in mechanisms to verify the legitimacy of the request. Additionally, the 67% proper output escaping, while not terrible, suggests that a third of the outputs are not being sanitized, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in those outputs. The external HTTP requests, while not inherently risky, should be monitored for potential vulnerabilities in the external services they communicate with.

Key Concerns

  • Missing nonce checks on cron events
  • Missing capability checks on cron events
  • Unescaped output (33% of outputs)
Vulnerabilities
None known

zenloop for WooCommerce – Net Promoter Score (NPS) platform Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

zenloop for WooCommerce – Net Promoter Score (NPS) platform Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

67% escaped15 total outputs
Attack Surface

zenloop for WooCommerce – Net Promoter Score (NPS) platform Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_menuclass-wc-zenloop-options.php:14
actionadmin_initclass-wc-zenloop-options.php:15
actioninitwoocommerce-zenloop.php:38
actionplugins_loadedwoocommerce-zenloop.php:42
actionwc_zenloop_importerwoocommerce-zenloop.php:57
actionwoocommerce_after_template_partwoocommerce-zenloop.php:76
actionwoocommerce_before_template_partwoocommerce-zenloop.php:81

Scheduled Events 1

wc_zenloop_importer
Maintenance & Trust

zenloop for WooCommerce – Net Promoter Score (NPS) platform Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedApr 5, 2023
PHP min version7.0
Downloads3K

Community Trust

Rating100/100
Number of ratings4
Active installs10
Developer Profile

zenloop for WooCommerce – Net Promoter Score (NPS) platform Developer Profile

zenloop

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect zenloop for WooCommerce – Net Promoter Score (NPS) platform

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zenloop-woocommerce-nps-platform/css/zenloop.css/wp-content/plugins/zenloop-woocommerce-nps-platform/js/zenloop.js
Script Paths
https://zenloop-website-overlay-production.s3.amazonaws.com/loader/zenloop.load.min.js
Version Parameters
ver=3.1

HTML / DOM Fingerprints

CSS Classes
zl-widget-container
Data Attributes
data-zl-survey-iddata-zl-widget-wrapperdata-zl-website-id
JS Globals
Zenloop
FAQ

Frequently Asked Questions about zenloop for WooCommerce – Net Promoter Score (NPS) platform