Awesome Tracker Security & Risk Analysis
wordpress.org/plugins/awesome-trackerTrack your users' navigation server-side. Also, you can track your WordPress API calls.
Is Awesome Tracker Safe to Use in 2026?
Generally Safe
Score 85/100Awesome Tracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "awesome-tracker" plugin v1.1.0 exhibits a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities (CVEs) and a relatively small attack surface with zero identified unprotected entry points like AJAX handlers, REST API routes, shortcodes, or cron events. The majority of its SQL queries (84%) are prepared, and it leverages bundled libraries like jQuery, which is common practice. However, there are notable areas of concern.
The static analysis reveals the presence of the dangerous `unserialize` function, which is a significant risk if the data being unserialized is not strictly controlled and sanitized. Furthermore, the taint analysis identified flows with unsanitized paths, including one of high severity, indicating potential issues where user-supplied input might be processed in an unsafe manner, potentially leading to path traversal or other file system vulnerabilities. The plugin also has a concerning 0% nonce checks, which are crucial for preventing CSRF attacks, especially if any of its (currently unlisted) internal operations could be triggered by user interaction. The output escaping is also only 59% properly escaped, leaving room for potential XSS vulnerabilities.
While the lack of historical CVEs is reassuring, it doesn't negate the risks identified in the current code. The presence of `unserialize` and high-severity taint flows, combined with a complete absence of nonce checks and suboptimal output escaping, suggests that the plugin is not following best security practices in several critical areas. Therefore, while the plugin appears to have a clean history, the code analysis reveals potential weaknesses that warrant attention and remediation to improve its overall security.
Key Concerns
- Presence of 'unserialize' function
- High severity taint flow identified
- Flows with unsanitized paths
- 0% nonce checks
- Output escaping only 59% proper
- File operations present
Awesome Tracker Security Vulnerabilities
Awesome Tracker Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Awesome Tracker Attack Surface
WordPress Hooks 10
Maintenance & Trust
Awesome Tracker Maintenance & Trust
Maintenance Signals
Community Trust
Awesome Tracker Alternatives
GA Google Analytics – Connect Google Analytics to WordPress
ga-google-analytics
Adds Google Analytics tracking code to your WordPress site. Supports many tracking features.
Metricool
metricool
Metricool is the first tool designed to measure #Blog impact and #SocialMedia activity.
SlimStat Analytics
wp-slimstat
The leading web analytics plugin for WordPress
Connect Matomo – Analytics Dashboard for WordPress
wp-piwik
Adds Matomo (former Piwik) statistics to your WordPress dashboard and is also able to add the Matomo Tracking Code to your blog.
Pixel Manager for WooCommerce – Conversion Tracking, Google Ads, GA4, TikTok, Dynamic Remarketing
woocommerce-google-adwords-conversion-tracking-tag
Conversion tracking for WooCommerce. Google Ads, GA4, Meta/Facebook Pixel, TikTok & more. Recover 30% more conversions with server-side tracking!
Awesome Tracker Developer Profile
1 plugin · 0 total installs
How We Detect Awesome Tracker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/awesome-tracker/css/admin.css/wp-content/plugins/awesome-tracker/js/dist/blocks.build.js/wp-content/plugins/awesome-tracker/js/dist/blocks.editor.build.css/wp-content/plugins/awesome-tracker/js/external/chosen/chosen.jquery.min.js/wp-content/plugins/awesome-tracker/js/external/chosen/chosen.min.css/wp-content/plugins/awesome-tracker/js/admin.js/wp-content/plugins/awesome-tracker/js/dist/blocks.build.js/wp-content/plugins/awesome-tracker/js/admin.js/wp-content/plugins/awesome-tracker/js/external/chosen/chosen.jquery.min.jsawesome-tracker/css/admin.css?ver=awesome-tracker/js/dist/blocks.build.js?ver=awesome-tracker/js/dist/blocks.editor.build.css?ver=awesome-tracker/js/external/chosen/chosen.jquery.min.js?ver=awesome-tracker/js/external/chosen/chosen.min.css?ver=awesome-tracker/js/admin.js?ver=HTML / DOM Fingerprints
window.atGlobalwindow.atRoutesGlobalwindow.atSettingsGlobalwindow.ati18n/wp-json/awesome-tracker