Clickback Security & Risk Analysis
wordpress.org/plugins/clickback-web-trackerClickback adds a small line of code to your WordPress site so you can identify companies who have visited your website but haven't converted.
Is Clickback Safe to Use in 2026?
Generally Safe
Score 85/100Clickback has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The clickback-web-tracker plugin version 2.05 exhibits an exceptionally strong security posture based on the provided static analysis and vulnerability history. The code analysis reveals no dangerous functions, file operations, or external HTTP requests. Crucially, all SQL queries are prepared, and all output is properly escaped, indicating robust defense against common injection and cross-site scripting vulnerabilities. The absence of any recorded CVEs, historical or current, further reinforces this positive outlook, suggesting a history of secure development practices or diligent patching by developers.
While the plugin presents a minimal attack surface with zero entry points identified as unprotected, a notable observation is the lack of any nonce checks or capability checks beyond a single instance. This could theoretically expose functionality if new entry points were inadvertently introduced or if the existing single capability check is not sufficiently granular for all contexts. However, given the current analysis showing zero unprotected entry points and no taint flows, the immediate risk is extremely low. The plugin's strengths lie in its clean coding practices regarding data handling and output. The primary area for potential, albeit currently theoretical, concern is the limited use of robust authentication mechanisms across all potential interaction points, a risk that is mitigated by the current absence of exposed interaction points.
Clickback Security Vulnerabilities
Clickback Code Analysis
Output Escaping
Clickback Attack Surface
WordPress Hooks 3
Maintenance & Trust
Clickback Maintenance & Trust
Maintenance Signals
Community Trust
Clickback Alternatives
Lead Forensics
lead-forensics-roi
Lead Forensics helps you to turn your anonymous website visitors into paying customers. Our business database is the biggest in the world, so every vi …
Online Succes
online-succes
With this plugin you can easily add the Online Succes tracking code to your WordPress site.
IP Tracking by Gambit Nash
gn-ip-tracking
The IP Tracking plugin from Gambit Nash is an easy way to integrate our B2B IP Tracking service into your WordPress website.
Wholesale Suite – B2B, Dynamic Pricing & WooCommerce Wholesale Prices
woocommerce-wholesale-prices
WooCommerce wholesale plugin for serving wholesale & B2B customers. Adds wholesale pricing, user roles, dynamic pricing & more.
B2BKing — Ultimate WooCommerce B2B and Wholesale Solution — Dynamic Pricing, Wholesale Order Form & More
b2bking-wholesale-for-woocommerce
B2BKing is the complete solution for running a Wholesale, B2B or B2B + B2C hybrid store with WooCommerce.
Clickback Developer Profile
1 plugin · 90 total installs
How We Detect Clickback
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/clickback-web-tracker/js/cbw-main.jsclickback-web-tracker/js/cbw-main.js?ver=HTML / DOM Fingerprints
clickback_web_tracker