Easy UTM Tracking with Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/easy-utm-tracking-with-contact-form-7

Easy UTM Tracking with Contact Form 7 is a simple plugin that lets you track UTM parameters and referrer in your Contact Form 7 lead emails with just …

2K active installs v2.0.6 PHP + WP 5.0+ Updated Apr 19, 2023
cf7contact-formcontact-form-7utmutm-tracking
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Easy UTM Tracking with Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 85/100

Easy UTM Tracking with Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The static analysis of "easy-utm-tracking-with-contact-form-7" v2.0.6 indicates a generally strong security posture. The plugin demonstrates good practices by having no identified dangerous functions, all SQL queries utilizing prepared statements, and all output being properly escaped. The absence of file operations and external HTTP requests further contributes to its security. Furthermore, the vulnerability history shows no recorded CVEs, suggesting a history of secure development or prompt patching of any past issues.

However, a notable concern is the complete lack of any identified entry points, including AJAX handlers, REST API routes, shortcodes, or cron events. While this appears to minimize the attack surface, it's unusual for a plugin designed to interact with Contact Form 7. This could indicate either an extremely minimal functionality or a potential oversight in the analysis process. The absence of nonce and capability checks, while not directly tied to an exploit in this analysis, is a missed opportunity for robust security, especially if future updates introduce new functionalities or if the analysis missed subtle entry points. Overall, the plugin exhibits commendable security fundamentals, but the lack of discernible entry points and the absence of any authorization checks warrants cautious consideration, particularly if its functionality is more extensive than what is immediately apparent from this analysis.

Key Concerns

  • No capability checks identified
  • No nonce checks identified
Vulnerabilities
None known

Easy UTM Tracking with Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Easy UTM Tracking with Contact Form 7 Release Timeline

v2.0.6Current
v2.0.5
v2.0.4
Code Analysis
Analyzed Mar 16, 2026

Easy UTM Tracking with Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped3 total outputs
Attack Surface

Easy UTM Tracking with Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_noticeseasy-utm-tracking-with-contact-form-7.php:13
actionwp_enqueue_scriptseasy-utm-tracking-with-contact-form-7.php:26
actionwpcf7_before_send_maileasy-utm-tracking-with-contact-form-7.php:28
Maintenance & Trust

Easy UTM Tracking with Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedApr 19, 2023
PHP min version
Downloads22K

Community Trust

Rating90/100
Number of ratings8
Active installs2K
Developer Profile

Easy UTM Tracking with Contact Form 7 Developer Profile

basirmukhtar

1 plugin · 2K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Easy UTM Tracking with Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easy-utm-tracking-with-contact-form-7/js/ucf7_scripts.js
Script Paths
/wp-content/plugins/easy-utm-tracking-with-contact-form-7/js/ucf7_scripts.js
Version Parameters
easy-utm-tracking-with-contact-form-7/js/ucf7_scripts.js?ver=

HTML / DOM Fingerprints

Shortcode Output
<style type="text/css">tr:nth-child(even) { background-color: #eff0f1; }</style><table cellpadding="10" border="1" style="border-collapse:collapse; width:50%;"><tr style="background-color: #eff0f1;"><td><strong>UTM Parameter:</strong></td><td><strong>Value</strong></td></tr><tr><td>utm_source:</td><td><tr style="background-color: #eff0f1;"><td>utm_medium:</td><td>
FAQ

Frequently Asked Questions about Easy UTM Tracking with Contact Form 7