BaseCloud UTM Tracker Security & Risk Analysis
wordpress.org/plugins/basecloud-utm-trackerAdvanced UTM tracking with automated webhook injection for Gravity Forms, Elementor, WPForms, and Contact Form 7.
Is BaseCloud UTM Tracker Safe to Use in 2026?
Generally Safe
Score 100/100BaseCloud UTM Tracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The basecloud-utm-tracker v3.0.3 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL query handling, exclusively using prepared statements. The absence of known historical vulnerabilities also suggests a generally stable development history. However, there are significant concerns related to its attack surface. The plugin has 5 AJAX handlers, with one that lacks any authentication checks. This unprotected entry point is a critical security weakness that could allow unauthorized users to trigger actions within the plugin. Additionally, the static analysis shows a concerning rate of improperly escaped output (42%), which, while not directly linked to critical taint flows in this analysis, could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled correctly before being displayed.
Key Concerns
- Unprotected AJAX handler
- Significant amount of unescaped output
- Use of dangerous function (system)
BaseCloud UTM Tracker Security Vulnerabilities
BaseCloud UTM Tracker Release Timeline
BaseCloud UTM Tracker Code Analysis
Dangerous Functions Found
Output Escaping
BaseCloud UTM Tracker Attack Surface
AJAX Handlers 5
WordPress Hooks 12
Maintenance & Trust
BaseCloud UTM Tracker Maintenance & Trust
Maintenance Signals
Community Trust
BaseCloud UTM Tracker Alternatives
MZ UTM Tracker for Gravity Form
mondoloz-utm-tracker-for-gravity-forms
Automatically captures UTM parameters from URLs and populates corresponding Gravity Forms fields for advanced lead tracking.
UTM Tracker for Gravity Forms
utm-tracker-for-gravity-forms
A lightweight UTM tracking enhancer for Gravity Forms. Stores UTM parameters for 90 days and auto-fills form fields automatically.
Multi-Page Campaign Tracking
mdi-persist-query-string
Persist query string parameters across page visits for tracking and analytics purposes.
HubSpot All-In-One Marketing – Forms, Popups, Live Chat
leadin
The CRM, Sales, and Marketing WordPress plugin to grow your business better. Capture and engage web visitors with free live chat, forms, CRM, email ma …
CallTrackingMetrics
call-tracking-metrics
CallTrackingMetrics integrates with your WordPress site to provide powerful call tracking and attribution.
BaseCloud UTM Tracker Developer Profile
3 plugins · 80 total installs
How We Detect BaseCloud UTM Tracker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/basecloud-utm-tracker/admin/css/settings.css/wp-content/plugins/basecloud-utm-tracker/admin/js/settings.jsHTML / DOM Fingerprints
basecloud-utm-tracker-settingsbasecloud_utm_params/wp-json/basecloud-utm-tracker/v1/settings