Form Attribution Tracking Security & Risk Analysis

wordpress.org/plugins/form-attribution-tracking

Track the complete customer journey from first click to conversion with referral and Google Ads attribution data captured in your WordPress forms.

0 active installs v1.1.2 PHP 8.0+ WP 6.0+ Updated Nov 17, 2025
attributionformsreferraltracking
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Form Attribution Tracking Safe to Use in 2026?

Generally Safe

Score 100/100

Form Attribution Tracking has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The "form-attribution-tracking" plugin v1.1.2 demonstrates a strong security posture based on the provided static analysis. It shows excellent adherence to security best practices with a high percentage of prepared SQL statements and properly escaped output. The absence of dangerous functions, file operations, and external HTTP requests further bolsters its security. Crucially, all identified AJAX entry points are protected by nonce and capability checks, and there are no REST API routes or shortcodes that could introduce vulnerabilities. The lack of any recorded CVEs and a clean vulnerability history indicates a well-maintained and secure plugin over time.

While the static analysis reveals no immediate critical or high-severity risks, the small number of analyzed taint flows (zero) means that complex or subtle vulnerabilities might not have been detected. However, given the plugin's small attack surface and robust implementation of standard security measures, the overall risk is currently assessed as very low. The plugin appears to be a safe and well-developed option for its intended functionality.

Vulnerabilities
None known

Form Attribution Tracking Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Form Attribution Tracking Release Timeline

v1.1.2Current
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

Form Attribution Tracking Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
22 prepared
Unescaped Output
1
33 escaped
Nonce Checks
5
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

88% prepared25 total queries

Output Escaping

97% escaped34 total outputs
Attack Surface

Form Attribution Tracking Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_form_attribution_tracking_bulk_actionsrc\Plugin.php:115
authwp_ajax_form_attribution_tracking_get_formssrc\Plugin.php:116
authwp_ajax_form_attribution_tracking_get_statssrc\Plugin.php:117
WordPress Hooks 11
actionplugins_loadedattribution-tracking.php:35
actionfluentform/inserted_new_formsrc\Integrations\FluentFormsIntegration.php:61
actionfluentform/before_insert_submissionsrc\Integrations\FluentFormsIntegration.php:64
actionfrm_after_create_formsrc\Integrations\FormidableFormsIntegration.php:62
filterfrm_pre_create_entrysrc\Integrations\FormidableFormsIntegration.php:65
actiongform_after_save_formsrc\Integrations\GravityFormsIntegration.php:28
actiongform_pre_submissionsrc\Integrations\GravityFormsIntegration.php:29
actionadmin_menusrc\Plugin.php:107
actionadmin_initsrc\Plugin.php:108
actionadmin_enqueue_scriptssrc\Plugin.php:109
actionwp_enqueue_scriptssrc\Plugin.php:112
Maintenance & Trust

Form Attribution Tracking Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 17, 2025
PHP min version8.0
Downloads205

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Form Attribution Tracking Developer Profile

Ryan Howard

7 plugins · 30K total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
3 days
View full developer profile
Detection Fingerprints

How We Detect Form Attribution Tracking

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/form-attribution-tracking/resources/css/admin.css/wp-content/plugins/form-attribution-tracking/resources/js/admin.js/wp-content/plugins/form-attribution-tracking/resources/js/frontend.js
Script Paths
/wp-content/plugins/form-attribution-tracking/resources/js/admin.js/wp-content/plugins/form-attribution-tracking/resources/js/frontend.js
Version Parameters
form-attribution-tracking/resources/css/admin.css?ver=form-attribution-tracking/resources/js/admin.js?ver=form-attribution-tracking/resources/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
form-attribution-tracking-admin-wrapattribution-tracking-settings-section
HTML Comments
<!-- Form Attribution Tracking Plugin --><!-- Load admin scripts --><!-- Load frontend scripts --><!-- Main Plugin class -->
Data Attributes
data-attribution-tracking-cookie-durationdata-attribution-tracking-debug-modedata-attribution-tracking-field-namedata-attribution-tracking-auto-add
JS Globals
formAttributionTrackingAdminformAttributionTrackingFrontend
REST Endpoints
/wp-json/form-attribution-tracking/v1/settings/wp-json/form-attribution-tracking/v1/log
FAQ

Frequently Asked Questions about Form Attribution Tracking