Gps Tracker Security & Risk Analysis
wordpress.org/plugins/gps-trackerTrack Android cell phones in real time and store routes for later viewing.
Is Gps Tracker Safe to Use in 2026?
Generally Safe
Score 85/100Gps Tracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gps-tracker" v1.0.4 plugin presents a mixed security posture. On the positive side, it demonstrates good practices by having no known CVEs in its history and appears to have robust controls for its entry points, with all AJAX handlers and REST API routes protected by authentication or permission checks. The absence of file operations and external HTTP requests further reduces the attack surface in these areas. However, the static analysis reveals significant concerns regarding output sanitization. The fact that 0% of the total 6 outputs are properly escaped indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities if any of the data displayed to users originates from untrusted sources or user input. While there are no reported vulnerabilities, this absence could be due to a lack of deep security auditing rather than inherent security. The SQL query usage is also a minor concern, with 42% not using prepared statements, which could lead to SQL injection vulnerabilities if those queries handle unsanitized input.
Despite the lack of historical vulnerabilities, the static analysis points to potential weaknesses that could be exploited. The unescaped output is the most glaring issue, offering a clear path for XSS attacks. The use of raw SQL queries without prepared statements for a significant portion of queries also introduces a risk of SQL injection. The plugin's overall score is impacted by these identified code-level weaknesses, even with its strengths in access control and lack of known vulnerabilities.
Key Concerns
- Unescaped output detected
- SQL queries not using prepared statements
Gps Tracker Security Vulnerabilities
Gps Tracker Release Timeline
Gps Tracker Code Analysis
SQL Query Safety
Output Escaping
Gps Tracker Attack Surface
AJAX Handlers 8
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
Gps Tracker Maintenance & Trust
Maintenance Signals
Community Trust
Gps Tracker Alternatives
Gps Plotter
gps-plotter
Use Google maps to track cell phones from your WordPress website in real time.
WPtouch – Make your WordPress Website Mobile-Friendly
wptouch
With just a few clicks, make your WordPress website mobile-friendly (iPhone, Android, and more). Recommended by Google, it will instantly enable a mob …
Multi Device Switcher
multi-device-switcher
Multi Device Switcher plugin allows you to set a separate theme for device (Smart Phone, Tablet PC, Mobile Phone, Game and custom).
AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker)
appmysite
Turn your WordPress or WooCommerce site into a native Android & iOS app in minutes — no coding required.
AppPresser – Mobile App Framework
apppresser
Connect your WordPress site to a native mobile app.
Gps Tracker Developer Profile
1 plugin · 30 total installs
How We Detect Gps Tracker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gps-tracker/assets/css/admin.css/wp-content/plugins/gps-tracker/assets/js/public.js/wp-content/plugins/gps-tracker/assets/js/leaflet.js/wp-content/plugins/gps-tracker/assets/css/leaflet.css/wp-content/plugins/gps-tracker/assets/js/public.js/wp-content/plugins/gps-tracker/assets/js/leaflet.jsgpstracker/assets/css/admin.css?ver=gpstracker/assets/js/public.js?ver=gpstracker/assets/js/leaflet.js?ver=gpstracker/assets/css/leaflet.css?ver=HTML / DOM Fingerprints
gps-tracker-map-containerGpsTrackerLeaflet[gps_tracker]