FBS Activity Tracker Security & Risk Analysis
wordpress.org/plugins/fbs-activity-trackerA modern, granular user activity and audit log WordPress plugin with a custom-designed dashboard interface for comprehensive site monitoring.
Is FBS Activity Tracker Safe to Use in 2026?
Generally Safe
Score 100/100FBS Activity Tracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "fbs-activity-tracker" plugin v1.0.1 demonstrates a generally strong security posture, largely due to its adherence to good development practices. All identified AJAX and REST API entry points are protected by appropriate authentication and capability checks. The plugin exclusively uses prepared statements for its SQL queries, mitigating SQL injection risks, and shows a high percentage of properly escaped output. File operations and external HTTP requests are absent, further reducing the attack surface. The presence of nonce checks and capability checks on all entry points is commendable.
However, the static analysis reveals two critical severity taint flows with unsanitized paths. While the specific nature of these paths is not detailed, unsanitized paths represent a significant risk, potentially allowing attackers to inject malicious code or manipulate data. The absence of any recorded historical vulnerabilities is positive, suggesting a stable codebase. Despite the excellent use of prepared statements and output escaping, these two taint flows represent the most immediate and concerning security weakness in this version.
In conclusion, "fbs-activity-tracker" v1.0.1 is well-developed with robust defenses against common web vulnerabilities like SQL injection and XSS. The lack of historical CVEs and the secure handling of common entry points are significant strengths. The primary area requiring attention is the resolution of the two critical taint flows with unsanitized paths, which should be addressed promptly to maintain its otherwise strong security profile.
Key Concerns
- Critical severity taint flow with unsanitized path (x2)
FBS Activity Tracker Security Vulnerabilities
FBS Activity Tracker Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
FBS Activity Tracker Attack Surface
AJAX Handlers 4
WordPress Hooks 18
Scheduled Events 1
Maintenance & Trust
FBS Activity Tracker Maintenance & Trust
Maintenance Signals
Community Trust
FBS Activity Tracker Alternatives
Logify WP – Activity Log & User Audit Log
logify-wp
Logify WP - Activity Log & User Audit Log tracks critical changes, logins, and updates with searchable logs for site security.
Logify – Event Logger, Activity Monitor, Activity Log & Audit Log
logify
Monitor, track, and review everything happening on your WordPress site. Logify helps you stay secure, stay compliant, and stay in control.
Activity Monitor Pro
activity-monitor-pro
Comprehensive activity monitoring, undo system, and AI-powered anomaly detection for WordPress.
Liaison Site Prober
liaison-site-prober
Liaison Site Prober helps you log and track key changes and user actions on your WordPress website — giving you better visibility and security.
TeleLog
telelog
Keep track of everything happening on your WordPress in Telegram
FBS Activity Tracker Developer Profile
5 plugins · 50 total installs
How We Detect FBS Activity Tracker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fbs-activity-tracker/admin/css/fbs-activity-tracker-admin.css/wp-content/plugins/fbs-activity-tracker/admin/css/fbs-activity-tracker-notifications.css/wp-content/plugins/fbs-activity-tracker/admin/js/fbs-activity-tracker-admin.js/wp-content/plugins/fbs-activity-tracker/admin/js/fbs-activity-tracker-admin.jsfbs-activity-tracker/admin/css/fbs-activity-tracker-admin.css?ver=fbs-activity-tracker/admin/css/fbs-activity-tracker-notifications.css?ver=fbs-activity-tracker/admin/js/fbs-activity-tracker-admin.js?ver=HTML / DOM Fingerprints
fbsActivityTracker