Conversion Pixel and Tracking Tag Manager Security & Risk Analysis

wordpress.org/plugins/conversion-pixel-and-tracking-tag-manager

Simplify management of marketing tags, tracking pixels, and data layer events without coding.

0 active installs v1.0.0 PHP 7.4+ WP 5.0+ Updated Mar 16, 2025
conversion-trackingdata-layermarketing-pixelstag-managertracking
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Conversion Pixel and Tracking Tag Manager Safe to Use in 2026?

Generally Safe

Score 92/100

Conversion Pixel and Tracking Tag Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin "conversion-pixel-and-tracking-tag-manager" v1.0.0 exhibits a generally strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero attack surface. Furthermore, the code demonstrates good practices by not using dangerous functions and exclusively employing prepared statements for SQL queries. The significant percentage of properly escaped output (85%) is also a positive indicator. The absence of any recorded vulnerabilities or CVEs further strengthens this assessment.

However, a few areas warrant attention. The presence of file operations, while not inherently insecure, represents a potential avenue for exploitation if not handled with extreme care. The complete lack of nonce checks and capability checks is a significant concern, especially given that even with a zero attack surface, any future expansion or undiscovered entry points would be completely unprotected. The taint analysis results are encouraging, showing no unsanitized paths or critical/high severity flows, but this is based on a limited analysis (0 flows analyzed).

In conclusion, while the plugin is currently free from known vulnerabilities and demonstrates good SQL and output handling, the absence of security checks like nonces and capability checks represents a notable weakness. This could become a critical issue if new functionalities are added or if previously unanalyzed code paths are discovered to be vulnerable. The current version appears safe, but its future security relies heavily on the developers implementing proper authorization and input validation.

Key Concerns

  • File operations present
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Conversion Pixel and Tracking Tag Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Conversion Pixel and Tracking Tag Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
18
101 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

85% escaped119 total outputs
Attack Surface

Conversion Pixel and Tracking Tag Manager Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
actionplugins_loadedconversion-pixel-and-tracking-tag-manager.php:93
actionplugins_loadedconversion-pixel-and-tracking-tag-manager.php:161
actionwp_enqueue_scriptsconversion-pixel-and-tracking-tag-manager.php:166
actionadmin_menuincludes\admin\class-cpttm-admin.php:15
actionadmin_initincludes\admin\class-cpttm-admin.php:16
actionadmin_enqueue_scriptsincludes\admin\class-cpttm-admin.php:17
actionwp_headincludes\admin\class-cpttm-admin.php:21
actionwp_body_openincludes\admin\class-cpttm-admin.php:22
actionwp_footerincludes\admin\class-cpttm-admin.php:23
actionwp_footerincludes\events\class-cpttm-begin-checkout.php:24
actionwoocommerce_thankyouincludes\events\class-cpttm-purchase.php:24
actionwp_footerincludes\events\class-cpttm-select-item.php:23
actionwp_footerincludes\events\class-cpttm-view-cart.php:24
actionwpincludes\events\class-cpttm-view-item-list.php:23
actionwpincludes\events\class-cpttm-view-item.php:23
Maintenance & Trust

Conversion Pixel and Tracking Tag Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 16, 2025
PHP min version7.4
Downloads310

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Conversion Pixel and Tracking Tag Manager Developer Profile

TAGLAB

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Conversion Pixel and Tracking Tag Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/conversion-pixel-and-tracking-tag-manager/includes/admin/assets/images/cpttm-sidebar-logo.svg/wp-content/plugins/conversion-pixel-and-tracking-tag-manager/includes/admin/assets/css/admin.css/wp-content/plugins/conversion-pixel-and-tracking-tag-manager/assets/js/cpttm-script.js
Script Paths
/wp-content/plugins/conversion-pixel-and-tracking-tag-manager/assets/js/cpttm-script.js
Version Parameters
conversion-pixel-and-tracking-tag-manager/includes/admin/assets/css/admin.css?ver=conversion-pixel-and-tracking-tag-manager/assets/js/cpttm-script.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-page-typedata-page-datedata-page-authordata-taxonomies
JS Globals
cpttm_page_metadata
FAQ

Frequently Asked Questions about Conversion Pixel and Tracking Tag Manager