BaseCloud UTM Tracker Security & Risk Analysis
wordpress.org/plugins/basecloud-utm-trackerAdvanced UTM tracking with automated webhook injection for Gravity Forms, Elementor, WPForms, and Contact Form 7.
Is BaseCloud UTM Tracker Safe to Use in 2026?
Generally Safe
Score 100/100BaseCloud UTM Tracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The basecloud-utm-tracker v3.0.3 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL query handling, exclusively using prepared statements. The absence of known historical vulnerabilities also suggests a generally stable development history. However, there are significant concerns related to its attack surface. The plugin has 5 AJAX handlers, with one that lacks any authentication checks. This unprotected entry point is a critical security weakness that could allow unauthorized users to trigger actions within the plugin. Additionally, the static analysis shows a concerning rate of improperly escaped output (42%), which, while not directly linked to critical taint flows in this analysis, could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled correctly before being displayed.
Key Concerns
- Unprotected AJAX handler
- Significant amount of unescaped output
- Use of dangerous function (system)
BaseCloud UTM Tracker Security Vulnerabilities
BaseCloud UTM Tracker Code Analysis
Dangerous Functions Found
Output Escaping
BaseCloud UTM Tracker Attack Surface
AJAX Handlers 5
WordPress Hooks 12
Maintenance & Trust
BaseCloud UTM Tracker Maintenance & Trust
Maintenance Signals
Community Trust
BaseCloud UTM Tracker Alternatives
MZ UTM Tracker for Gravity Form
mondoloz-utm-tracker-for-gravity-forms
Automatically captures UTM parameters from URLs and populates corresponding Gravity Forms fields for advanced lead tracking.
UTM Tracker for Gravity Forms
utm-tracker-for-gravity-forms
A lightweight UTM tracking enhancer for Gravity Forms. Stores UTM parameters for 90 days and auto-fills form fields automatically.
MDI Persist Query String
mdi-persist-query-string
Persist query string parameters across page visits for tracking and analytics purposes.
HubSpot All-In-One Marketing – Forms, Popups, Live Chat
leadin
The CRM, Sales, and Marketing WordPress plugin to grow your business better. Capture and engage web visitors with free live chat, forms, CRM, email ma …
CallTrackingMetrics
call-tracking-metrics
CallTrackingMetrics integrates with your WordPress site to provide powerful call tracking and attribution.
BaseCloud UTM Tracker Developer Profile
2 plugins · 50 total installs
How We Detect BaseCloud UTM Tracker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/basecloud-utm-tracker/admin/css/settings.css/wp-content/plugins/basecloud-utm-tracker/admin/js/settings.jsHTML / DOM Fingerprints
basecloud-utm-tracker-settingsbasecloud_utm_params/wp-json/basecloud-utm-tracker/v1/settings