WooCommerce: Store & POS Security & Privacy Scorecard
Android
Usage patterns and in-app behavior are tracked by Firebase, Google Analytics, and Automattic's own analytics service. Store activity data may also reach Sentry for crash reporting. Payment interactions involve the Stripe Terminal SDK, and support requests pass through Zendesk.
Best for
WooCommerce store owners comfortable with analytics
Findings
- 0 critical
- 0 high
- 0 medium
- 0 low
- 0 info
1 issue identified across security and privacy analysis.
Top security issues
- Hardcoded OAuth Client Secret in BuildConfig
- Cleartext Traffic Allowed in Network Configuration
- Selective Encryption Pattern (Most Data Unencrypted)
Top privacy issues
- No User Consent for Analytics Tracking (GDPR Violation)
- PII Tracked in Analytics Events Without Consent
- Sentry Crash Reports Include PII
Full analysis
WooCommerce: Store & POS
Version: 23.5 (703)
Scan Date: 2026-01-21
Package: com.woocommerce.android
What This Means for You
Usage patterns and in-app behavior are tracked by Firebase, Google Analytics, and Automattic's own analytics service. Store activity data may also reach Sentry for crash reporting. Payment interactions involve the Stripe Terminal SDK, and support requests pass through Zendesk.
Recommendation: Use With Caution
Best For: WooCommerce store owners comfortable with analytics
Key Findings
Data Security - 7 findings (2 critical, 3 high, 2 medium)
Network Security - 3 findings (1 critical, 2 medium)
Code Safety - 0 findings
Privacy - 4 findings (2 critical, 1 high, 1 medium)
Privacy Concerns
What Data is Collected
Store management activity, browsing and navigation patterns, device identifiers, and crash diagnostics are gathered during normal use. Multiple analytics pipelines receive this data concurrently.
Third-Party Data Sharing
- Firebase Analytics - behavioral analytics and usage tracking
- Google Analytics - usage tracking
- Automattic Tracks - analytics by the app developer
- Sentry - crash and error reporting
- Zendesk - customer support interactions
- Stripe Terminal SDK - payment processing
Understanding the Scores
| Category | Score |
|---|---|
| Security | 45/100 |
| Privacy | 30/100 |
| Data Security | 40/100 |
| Network Security | 50/100 |
| Code Safety | 75/100 |
| Data Collection | 35/100 |
| Data Sharing | 40/100 |
| User Control | 25/100 |
Positive Security Features
- No notable positive security practices were identified.
Areas for Improvement
- Store and behavioral data reaches multiple third-party analytics providers at once, with no opt-out available from within the app.
- Payment and business data flows through third-party services with limited transparency about how long that data is retained or how it is used downstream.
- Users have little control over what is collected or shared: the app offers minimal privacy settings to adjust data collection scope.
About This Analysis
Scores reflect security and privacy practices observed in the app's code and configuration at the time of analysis.
App Details
- App: WooCommerce: Store & POS
- Package ID: com.woocommerce.android
- Version: 23.5 (703)
- Scan Date: 2026-01-21
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #3 (current) | 38/100 | |
| #1 | 42/100 |