AdWords Conversion Tracking Code Security & Risk Analysis

wordpress.org/plugins/adwords-conversion-tracking-code

Easiest way to add AdWords Conversion Tracking Code to your site.

1K active installs v1.0 PHP + WP 3.0.1+ Updated Nov 28, 2017
adsadsensecustom-adwidgetwidgets
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEDec 31, 2025
Safety Verdict

Is AdWords Conversion Tracking Code Safe to Use in 2026?

Use With Caution

Score 63/100

AdWords Conversion Tracking Code has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Dec 31, 2025Updated 8yr ago
Risk Assessment

The 'adwords-conversion-tracking-code' v1.0 plugin exhibits a mixed security posture. While the static analysis reveals a seemingly small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected, this may be misleading due to the lack of critical security checks. The most significant concern stems from the complete lack of output escaping, with 100% of identified outputs being improperly handled. This presents a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the website. Furthermore, the plugin has a known medium-severity vulnerability that remains unpatched, historically related to XSS. This suggests a pattern of vulnerabilities that require immediate attention. While the use of prepared statements for SQL queries and the presence of nonce checks are positive signs, they are overshadowed by the critical lack of output sanitization and the unpatched historical vulnerability.

Key Concerns

  • Unpatched Medium CVE
  • 100% Unescaped Output
  • No Capability Checks
Vulnerabilities
1

AdWords Conversion Tracking Code Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-62118medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

AdWords Conversion Tracking Code <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 31, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

AdWords Conversion Tracking Code Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
0 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped6 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
actcSettingsPage (adwords-conversion-tracking-code.php:72)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

AdWords Conversion Tracking Code Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuadwords-conversion-tracking-code.php:28
actionwp_footeradwords-conversion-tracking-code.php:164
actionsave_postadwords-conversion-tracking-code.php:165
actionplugins_loadedadwords-conversion-tracking-code.php:167
Maintenance & Trust

AdWords Conversion Tracking Code Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedNov 28, 2017
PHP min version
Downloads27K

Community Trust

Rating100/100
Number of ratings1
Active installs1K
Developer Profile

AdWords Conversion Tracking Code Developer Profile

kcseopro

2 plugins · 31K total installs

87
trust score
Avg Security Score
81/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect AdWords Conversion Tracking Code

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
name="actc_adtc"name="actc_adtc_value"name="actc_nonce"id="tlp-adtc-settings"id="tlpSaveButton"
FAQ

Frequently Asked Questions about AdWords Conversion Tracking Code