DM User Tracking Security & Risk Analysis
wordpress.org/plugins/dm-user-tracking-pluginAn extensive, customisable, fully featured user tracking plugin.
Is DM User Tracking Safe to Use in 2026?
Generally Safe
Score 100/100DM User Tracking has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The dm-user-tracking-plugin v1.9.1 presents a mixed security posture. While the plugin exhibits a strong attack surface management with no apparent unprotected entry points (AJAX, REST API, shortcodes), several concerning code signals emerge. The significant use of the `unserialize` function, coupled with a high percentage of SQL queries not using prepared statements, introduces potential risks for arbitrary code execution and SQL injection vulnerabilities. Furthermore, the low percentage of properly escaped output indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website.
The taint analysis reveals a high-severity flow with unsanitized paths, which could be exploited to achieve critical security outcomes. The absence of any recorded vulnerabilities in its history might suggest a lack of past exploitation or thorough security auditing, but it does not guarantee future security. The plugin's reliance on potentially unsafe functions and improper data handling practices, despite a seemingly secure attack surface, warrants careful consideration and mitigation efforts.
Key Concerns
- High number of SQL queries without prepared statements
- High-severity taint flow with unsanitized path
- Dangerous function: unserialize used
- Low percentage of properly escaped output
- File operations present
- External HTTP requests present
DM User Tracking Security Vulnerabilities
DM User Tracking Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
DM User Tracking Attack Surface
WordPress Hooks 10
Scheduled Events 3
Maintenance & Trust
DM User Tracking Maintenance & Trust
Maintenance Signals
Community Trust
DM User Tracking Alternatives
Last Login Tracker & Redirect URL
last-login-tracker-redirect-url
Tracks user last login and allows redirection of 404 pages to the homepage.
Lyon Site Activity
lyon-site-activity
A simple, lightweight plugin that gives site administrators an at-a-glance view of recent content edits.
User Activity Tracker
user-activity-tracker
Track and monitor user activity effortlessly with User Activity Tracker. Stay informed about actions taken on your site.
LogAction – Activity Logs for Admin
logaction
Track and log WordPress activities to monitor and improve your site's security and administrative tasks.
User Who Last Viewed The Order
order-user-last-viewed
Displays the user who last viewed a WooCommerce order in the admin panel, with timestamp.
DM User Tracking Developer Profile
1 plugin · 10 total installs
How We Detect DM User Tracking
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dm-user-tracking-plugin/js/dm_user_tracking.js/wp-content/plugins/dm-user-tracking-plugin/css/dm_user_tracking.cssjs/dm_user_tracking.jsdm-user-tracking-plugin/js/dm_user_tracking.js?ver=dm-user-tracking-plugin/css/dm_user_tracking.css?ver=HTML / DOM Fingerprints
dm-user-tracking-dashboard-widget<!-- DM User Tracking -->dm_user_tracking_obj[dm_user_tracking_visitors][dm_user_tracking_browsers][dm_user_tracking_platforms][dm_user_tracking_pages]