AVAK Form Tracking Listener Security & Risk Analysis

wordpress.org/plugins/avak-form-tracking-listener

Track form submissions, errors, and abandonment across popular form plugins with GTM and GA4 integration.

0 active installs v2.0.1 PHP 7.4+ WP 5.0+ Updated Mar 4, 2026
analyticscontact-form-7form-trackingga4google-tag-manager
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AVAK Form Tracking Listener Safe to Use in 2026?

Generally Safe

Score 100/100

AVAK Form Tracking Listener has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "avak-form-tracking-listener" v2.0.1 plugin exhibits a strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface, and importantly, all identified entry points appear to have proper authorization checks, which is excellent practice. The code analysis further indicates good security hygiene, with no dangerous functions identified, all SQL queries using prepared statements, and a high percentage of output being properly escaped. The lack of file operations and external HTTP requests also reduces potential attack vectors. The vulnerability history being clear of any recorded CVEs or past issues is a significant positive indicator of the plugin's stability and security focus.

While the static analysis presents a very positive picture, there are a couple of areas for consideration that prevent a perfect score. The complete absence of nonce checks, combined with the sole capability check, suggests that while some form of authorization is present, the implementation might be relying solely on that single capability check across all functionalities. Depending on the complexity of the plugin's operations, a more granular approach with nonce checks for sensitive operations, particularly if any data is being submitted or processed, could further harden the plugin. However, given the limited attack surface and the positive indicators, the overall risk is assessed as very low.

Key Concerns

  • No nonce checks implemented
Vulnerabilities
None known

AVAK Form Tracking Listener Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

AVAK Form Tracking Listener Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
20 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

83% escaped24 total outputs
Attack Surface

AVAK Form Tracking Listener Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
actionplugins_loadedavak-form-tracking-listener.php:76
actionwp_enqueue_scriptsavak-form-tracking-listener.php:77
actionadmin_enqueue_scriptsavak-form-tracking-listener.php:78
actionadmin_menuincludes\class-admin-settings.php:55
actionadmin_initincludes\class-admin-settings.php:56
actionwp_footerincludes\class-datalayer-handler.php:34
actionwp_headincludes\class-datalayer-handler.php:82
actionwpcf7_mail_sentincludes\class-form-listeners.php:85
actionwpcf7_spamincludes\class-form-listeners.php:86
actionwpcf7_mail_failedincludes\class-form-listeners.php:87
actionwpforms_process_completeincludes\class-form-listeners.php:148
actiongform_after_submissionincludes\class-form-listeners.php:176
actionninja_forms_after_submissionincludes\class-form-listeners.php:202
actionwp_footerincludes\class-form-listeners.php:230
actionwp_footerincludes\class-form-listeners.php:303
Maintenance & Trust

AVAK Form Tracking Listener Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 4, 2026
PHP min version7.4
Downloads191

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

AVAK Form Tracking Listener Developer Profile

ajayrajbanshi

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AVAK Form Tracking Listener

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/avak-form-tracking-listener/assets/js/form-tracking.js/wp-content/plugins/avak-form-tracking-listener/assets/js/form-abandonment.js/wp-content/plugins/avak-form-tracking-listener/assets/css/admin.css/wp-content/plugins/avak-form-tracking-listener/assets/js/admin.js
Script Paths
/wp-content/plugins/avak-form-tracking-listener/assets/js/form-tracking.js/wp-content/plugins/avak-form-tracking-listener/assets/js/form-abandonment.js/wp-content/plugins/avak-form-tracking-listener/assets/js/admin.js
Version Parameters
avak-form-tracking-listener/assets/js/form-tracking.js?ver=avak-form-tracking-listener/assets/js/form-abandonment.js?ver=avak-form-tracking-listener/assets/css/admin.css?ver=avak-form-tracking-listener/assets/js/admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-avak-form-tracking-settings
JS Globals
window.dataLayerwindow.avakFormTracking
FAQ

Frequently Asked Questions about AVAK Form Tracking Listener