etracker analytics Security & Risk Analysis

wordpress.org/plugins/etracker

Consent-free, despite ad blockers and tracking prevention: Web analytics, tag and consent manager for best data quality, ad returns and conversions.

1K active installs v2.7.7 PHP 7.2+ WP 5.5+ Updated Dec 2, 2025
analyticsdsgvogdprtrackingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is etracker analytics Safe to Use in 2026?

Generally Safe

Score 100/100

etracker analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The etracker plugin v2.7.7 exhibits a generally good security posture with strong adherence to several security best practices. The vast majority of SQL queries utilize prepared statements, and output escaping is also well-implemented, minimizing risks of SQL injection and XSS vulnerabilities. The absence of file operations and external HTTP requests further reduces potential attack vectors. Furthermore, a clean vulnerability history with no recorded CVEs suggests a history of secure development and prompt patching of any past issues.

However, a significant concern arises from the presence of two AJAX handlers that lack authentication checks. This creates a direct entry point for unauthenticated users to interact with potentially sensitive plugin functionality, which could be exploited if these handlers perform critical actions or expose information. The lack of nonce checks on these AJAX endpoints exacerbates this risk, as it allows for Cross-Site Request Forgery (CSRF) attacks.

In conclusion, while the plugin demonstrates a commitment to secure coding practices in many areas, the unprotected AJAX endpoints represent a critical weakness that requires immediate attention. The absence of any taint analysis results is positive, indicating no detected unsanitized data flows in the analyzed code, but this is overshadowed by the direct exposure of AJAX functionality.

Key Concerns

  • AJAX handlers without auth checks
  • AJAX handlers without nonce checks
Vulnerabilities
None known

etracker analytics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

etracker analytics Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
10 prepared
Unescaped Output
6
54 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

77% prepared13 total queries

Output Escaping

90% escaped60 total outputs
Attack Surface
2 unprotected

etracker analytics Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_etracker_dismiss_customer_pollingsrc\Etracker_Main.php:193
authwp_ajax_etracker_dismiss_notice_enable_integrated_reportingsrc\Etracker_Main.php:194

Shortcodes 1

[etracker_send_wc_order] src\Etracker_Main.php:285
WordPress Hooks 34
actionplugins_loadedsrc\Etracker_Main.php:166
actionadmin_menusrc\Etracker_Main.php:178
actionadmin_initsrc\Etracker_Main.php:179
filterplugin_action_links_etracker/etracker.phpsrc\Etracker_Main.php:180
actiongenerate_rewrite_rulessrc\Etracker_Main.php:181
filterposts_joinsrc\Etracker_Main.php:183
filterposts_orderbysrc\Etracker_Main.php:184
filterdefault_hidden_columnssrc\Etracker_Main.php:186
actionadmin_enqueue_scriptssrc\Etracker_Main.php:188
actionadmin_noticessrc\Etracker_Main.php:190
actionadmin_noticessrc\Etracker_Main.php:191
actionadmin_noticessrc\Etracker_Main.php:192
actionload-edit.phpsrc\Etracker_Main.php:196
actionwp_headsrc\Etracker_Main.php:230
filterdocument_title_partssrc\Etracker_Main.php:231
filterwpseo_titlesrc\Etracker_Main.php:232
actionwoocommerce_after_single_productsrc\Etracker_Main.php:269
actionwoocommerce_after_add_to_cart_buttonsrc\Etracker_Main.php:271
filterwoocommerce_loop_add_to_cart_linksrc\Etracker_Main.php:273
actionwp_footersrc\Etracker_Main.php:274
actionwoocommerce_thankyousrc\Etracker_Main.php:276
filterwoocommerce_cart_item_remove_linksrc\Etracker_Main.php:278
actionwoocommerce_after_cartsrc\Etracker_Main.php:279
actionwoocommerce_after_mini_cartsrc\Etracker_Main.php:280
actionwoocommerce_after_cartsrc\Etracker_Main.php:282
actionwoocommerce_after_mini_cartsrc\Etracker_Main.php:283
actionetracker_cron_fetch_reportssrc\Etracker_Main.php:399
actionetracker_cron_cleanup_loggingsrc\Etracker_Main.php:400
actionupdated_optionsrc\Etracker_Main.php:401
actionupdated_optionsrc\Etracker_Main.php:402
actionetracker_cron_trigger_customer_pollingsrc\Etracker_Main.php:403
actioninitsrc\Etracker_Main.php:416
actionplugins_loadedsrc\Etracker_Main.php:427
filtermod_rewrite_rulessrc\Plugin\Deactivator.php:34

Scheduled Events 2

etracker_cron_fetch_reports
etracker_cron_cleanup_logging
Maintenance & Trust

etracker analytics Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 2, 2025
PHP min version7.2
Downloads37K

Community Trust

Rating78/100
Number of ratings7
Active installs1K
Developer Profile

etracker analytics Developer Profile

etracker GmbH

1 plugin · 1K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect etracker analytics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/etracker/public/css/admin.css/wp-content/plugins/etracker/public/js/admin.js
Script Paths
/wp-content/plugins/etracker/public/js/admin.js
Version Parameters
etracker/public/css/admin.css?ver=etracker/public/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
etracker-plugin-settings
Data Attributes
data-etracker-settings
JS Globals
etracker
REST Endpoints
/wp-json/etracker/
FAQ

Frequently Asked Questions about etracker analytics