
ClickGUMSHOE – Click Fraud Detection & Protection Security & Risk Analysis
wordpress.org/plugins/clickgumshoeClickGUMSHOE – We Stop Click Fraud
Is ClickGUMSHOE – Click Fraud Detection & Protection Safe to Use in 2026?
Generally Safe
Score 85/100ClickGUMSHOE – Click Fraud Detection & Protection has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'clickgumshoe' plugin v1.0.4 exhibits a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities, no dangerous functions, and all SQL queries are properly prepared. This indicates a good effort in avoiding common pitfalls. However, significant concerns arise from the static analysis. The absence of capability checks and nonce checks on any potential entry points, coupled with a complete lack of output escaping for all 40 identified outputs, presents a substantial risk. The single unsanitized path identified in the taint analysis, even if not rated as critical or high, warrants attention due to the overall lack of defensive coding practices in other areas. The plugin's history of zero vulnerabilities could be a positive indicator or simply a reflection of its limited usage or prior exposure. Overall, while the plugin avoids some common vulnerabilities, the lack of essential security controls like output escaping and capability checks creates a high risk of cross-site scripting (XSS) and potentially other vulnerabilities that could be exploited if an attacker can find a way to trigger the identified unsanitized path or exploit the lack of authentication/authorization.
Key Concerns
- 0% output escaping
- 0 capability checks
- 0 nonce checks
- Unsanitized path in taint analysis
ClickGUMSHOE – Click Fraud Detection & Protection Security Vulnerabilities
ClickGUMSHOE – Click Fraud Detection & Protection Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
ClickGUMSHOE – Click Fraud Detection & Protection Attack Surface
WordPress Hooks 6
Maintenance & Trust
ClickGUMSHOE – Click Fraud Detection & Protection Maintenance & Trust
Maintenance Signals
Community Trust
ClickGUMSHOE – Click Fraud Detection & Protection Alternatives
AI Powered Marketing
kliken-marketing-for-google
Kliken's all-in-one marketing helps businesses reach high-intent customers, beat the competition and see sales growth while lowering conversion costs
CallRail Phone Call Tracking
callrail-phone-call-tracking
Dynamically swap CallRail tracking phone numbers based on the visitor's referring source.
Tracking Script Manager
tracking-script-manager
Easy tag management. Manage the tracking tags, codes and scripts you use in your WordPress site; easily add, update, reorder, delete, as required.
REVIEWS.io for WooCommerce
reviewscouk-for-woocommerce
REVIEWS.io, helps eCommerce merchants to collect & display verified product and company reviews. A Google Licensed partner.
Nimbata Call Tracking
nimbata-call-tracking
Dynamically swap your site's phone number with a nimbata tracking numbers. Track which sources generate phone leads to your business.
ClickGUMSHOE – Click Fraud Detection & Protection Developer Profile
5 plugins · 140 total installs
How We Detect ClickGUMSHOE – Click Fraud Detection & Protection
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/clickgumshoe/html/asset/plugins.js/wp-content/plugins/clickgumshoe/html/asset/clickgs.js/wp-content/plugins/clickgumshoe/html/asset/clickgs.css/wp-content/plugins/clickgumshoe/html/asset/plugins.js/wp-content/plugins/clickgumshoe/html/asset/clickgs.jsHTML / DOM Fingerprints
myspinner<!--[clickgs-keep-js]-->data-hcgs-valuedata-hcgs-targetdata-hcgs-refdata-hcgs-labeldata-hcgs-actionhcgs_lockhcgs_plugins