
ClickTrail – UTM, Click ID & Ad Tracking (with Consent) Security & Risk Analysis
wordpress.org/plugins/click-trail-handlerConsent-aware attribution for WooCommerce, WordPress forms, and event flows. Capture UTMs and click IDs across conversion paths.
Is ClickTrail – UTM, Click ID & Ad Tracking (with Consent) Safe to Use in 2026?
Generally Safe
Score 100/100ClickTrail – UTM, Click ID & Ad Tracking (with Consent) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'click-trail-handler' plugin exhibits a mixed security posture. While it demonstrates strong adherence to secure coding practices in areas like output escaping (98%) and the use of prepared statements in SQL queries (83%), a significant concern arises from its extensive attack surface lacking proper authorization checks. With 14 AJAX handlers, 13 of which do not have authentication checks, there's a substantial risk of unauthorized actions being performed by unauthenticated users. The presence of one unsanitized path flow, though not classified as critical or high, warrants attention as it could potentially lead to path traversal vulnerabilities if exploited in conjunction with other weaknesses. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator of past security diligence or simply a lack of discovered vulnerabilities. However, the high number of unprotected AJAX endpoints remains a primary security concern that needs to be addressed to improve the overall security of the plugin.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
ClickTrail – UTM, Click ID & Ad Tracking (with Consent) Security Vulnerabilities
ClickTrail – UTM, Click ID & Ad Tracking (with Consent) Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ClickTrail – UTM, Click ID & Ad Tracking (with Consent) Attack Surface
AJAX Handlers 14
WordPress Hooks 58
Scheduled Events 1
Maintenance & Trust
ClickTrail – UTM, Click ID & Ad Tracking (with Consent) Maintenance & Trust
Maintenance Signals
Community Trust
ClickTrail – UTM, Click ID & Ad Tracking (with Consent) Alternatives
SouqMetrics Attribution
souqmetrics-attribution-for-woo
Capture marketing attribution data (UTMs and click IDs) and attach it to WooCommerce orders.
WooCommerce Analytics
woocommerce-analytics
Boost sales and maximize ROI with WooCommerce Analytics. Access order attribution data to optimize performance and drive business growth effectively.
Tag Pilot FREE – Google Tag Manager Integration for WooCommerce
gtm-ecommerce-woo
Complete GTM plugin for WooCommerce (Consent Mode v2 and Server-Side). Ready for GA4 and FB Pixel. Product feed for Google Merchant Center.
UTM for Woocommerce
utm-for-woocommerce
Simply track UTM & CLID parameters in Woocommerce orders.
Pixelavo – Server Side Tracking & Pixel + AI Ads Tools
pixelavo
Add pixel tracking to your WordPress site with Conversions API, server-side tracking, AI ad copy generation, and AI marketing consultant.
ClickTrail – UTM, Click ID & Ad Tracking (with Consent) Developer Profile
2 plugins · 10 total installs
How We Detect ClickTrail – UTM, Click ID & Ad Tracking (with Consent)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/click-trail-handler/includes/assets/css/clicutcl-admin.css/wp-content/plugins/click-trail-handler/includes/assets/js/clicutcl-admin.js/wp-content/plugins/click-trail-handler/includes/assets/js/clicutcl-admin.jsclick-trail-handler/includes/assets/css/clicutcl-admin.css?ver=click-trail-handler/includes/assets/js/clicutcl-admin.js?ver=HTML / DOM Fingerprints
clicutcl-admin-wrapdata-clicutcl-nonceclicutclAdminVars