Advanced ActiveCampaign Site Tracking Security & Risk Analysis

wordpress.org/plugins/advanced-activecampaign-site-tracking

Adds ActiveCampaign Site Tracking Code and links to users email if logged in.

20 active installs v1.1.0 PHP + WP 3.0.1+ Updated Jun 18, 2018
activecampaignanalyticsmarketing-automationtracking
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Advanced ActiveCampaign Site Tracking Safe to Use in 2026?

Generally Safe

Score 85/100

Advanced ActiveCampaign Site Tracking has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The 'advanced-activecampaign-site-tracking' plugin v1.1.0 exhibits a strong security posture based on the provided static analysis. The absence of known vulnerabilities and CVEs is a significant positive indicator, suggesting a well-maintained and secure codebase. The static analysis reveals a minimal attack surface with no AJAX handlers, REST API routes, shortcodes, or cron events exposed, and importantly, none of these entry points are found to be unprotected. Furthermore, the plugin avoids dangerous functions, has no file operations, and does not make external HTTP requests. The use of prepared statements for all SQL queries is excellent practice, and the lack of taint analysis findings further reinforces its security.

However, there are areas for improvement. While the plugin has few output operations, only 50% are properly escaped, which presents a potential risk for cross-site scripting (XSS) vulnerabilities if the unescaped data is rendered in a user-facing context. Additionally, the complete lack of nonce checks and capability checks across any potential entry points (even though the attack surface is currently zero) suggests that if the plugin were to introduce such features in the future, it might do so without essential security mechanisms. The absence of any recorded vulnerabilities in its history is a strong point, but the limited static analysis data makes it difficult to definitively assess its long-term security without further insight into its development practices and more comprehensive code review.

Key Concerns

  • Half of output operations are not properly escaped
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Advanced ActiveCampaign Site Tracking Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Advanced ActiveCampaign Site Tracking Release Timeline

v1.1.0Current
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Advanced ActiveCampaign Site Tracking Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped4 total outputs
Attack Surface

Advanced ActiveCampaign Site Tracking Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menuadvanced-ac-tracking.php:26
actionadmin_initadvanced-ac-tracking.php:27
filterwp_footeradvanced-ac-tracking.php:163
Maintenance & Trust

Advanced ActiveCampaign Site Tracking Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedJun 18, 2018
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

Advanced ActiveCampaign Site Tracking Developer Profile

Daniel McClure

2 plugins · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Advanced ActiveCampaign Site Tracking

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/advanced-activecampaign-site-tracking/advanced-ac-tracking.php

HTML / DOM Fingerprints

HTML Comments
<!-- Please add your ActiveCampaign Account ID to enable Site Tracking -->
JS Globals
trackByDefaultacEnableTrackingacTrackVisit
FAQ

Frequently Asked Questions about Advanced ActiveCampaign Site Tracking