Issues Tracker Security & Risk Analysis
wordpress.org/plugins/issues-trackerIssues Tracker allows you view and search WordPress logs, receive security advice, track 404 errors, and view your server settings.
Is Issues Tracker Safe to Use in 2026?
Generally Safe
Score 92/100Issues Tracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "issues-tracker" plugin v1.16 exhibits significant security concerns primarily due to a large, unprotected attack surface and inadequate output escaping. With 20 AJAX handlers, all lacking authentication checks, any unauthenticated user could potentially interact with these endpoints. This is further exacerbated by the taint analysis, which reveals 7 flows with unsanitized paths, including 4 of high severity, indicating potential for code injection or manipulation. The limited proper output escaping (18%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities across many output points.
While the plugin has no recorded CVEs or bundled outdated libraries aside from Freemius v1.0 which is generally well-maintained, this positive history should not overshadow the immediate risks identified in the static analysis. The absence of capability checks on AJAX handlers is a critical oversight. The plugin demonstrates some good practices by using prepared statements for most SQL queries and including a single nonce check, but these are insufficient to mitigate the overarching security gaps. The conclusion is that this plugin, in its current state, presents a substantial security risk that requires immediate attention, particularly regarding the unprotected AJAX endpoints and the identified taint flows.
Key Concerns
- All AJAX handlers lack auth checks
- High severity unsanitized taint flows
- Many unsanitized path taint flows
- Low percentage of properly escaped output
- No capability checks on AJAX handlers
- Bundled Freemius v1.0 library
Issues Tracker Security Vulnerabilities
Issues Tracker Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Issues Tracker Attack Surface
AJAX Handlers 20
WordPress Hooks 7
Maintenance & Trust
Issues Tracker Maintenance & Trust
Maintenance Signals
Community Trust
Issues Tracker Alternatives
Log Deprecated Notices
log-deprecated-notices
Logs the usage of deprecated files, functions, and function arguments, and identifies where the deprecated functionality is being used.
Log Deprecated Notices Extender
log-deprecated-notices-extender
This developer-oriented WordPress plugin extends Andrew Nacin's Log Deprecated Notices to show a link in the WP 3.3+ Toolbar.
MilesWeb Tools
milesweb-tools
MilesWeb Tools is a powerful WordPress plugin designed to enhance your site's functionality and security. It helps you manage security settings, …
Developer Loggers for Simple History
developer-loggers-for-simple-history
Useful loggers for SimpleHistory for developers during development of a site or to maintain a live site.
Debug Bar – Enable WP_DEBUG from admin dashboard
enable-wp-debug-from-admin-dashboard
[ ✅ 𝐒𝐄𝐂𝐔𝐑𝐄 𝐏𝐋𝐔𝐆𝐈𝐍𝐒 b𝓎 𝒫𝓊𝓋𝑜𝓍] You can easily enable WP_DEBUG using a toolbar button. READ DESCRIPTION!
Issues Tracker Developer Profile
2 plugins · 1K total installs
How We Detect Issues Tracker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/issues-tracker/assets/css/themes/dark-mode.css/wp-content/plugins/issues-tracker/assets/css/themes/default.css/wp-content/plugins/issues-tracker/assets/css/variables.css/wp-content/plugins/issues-tracker/assets/css/issues-tracker.css/wp-content/plugins/issues-tracker/assets/js/issues-tracker.js/wp-content/plugins/issues-tracker/assets/js/issues-tracker.jsissues-tracker/assets/css/themes/dark-mode.css?ver=issues-tracker/assets/css/themes/default.css?ver=issues-tracker/assets/css/variables.css?ver=issues-tracker/assets/css/issues-tracker.css?ver=issues-tracker/assets/js/issues-tracker.js?ver=HTML / DOM Fingerprints
istkr-tableistkr-log-vieweristkr-advisoristkr-404data-type="issues-tracker"issues_tracker_ajax_object/wp-json/issues-tracker/v1/log/wp-json/issues-tracker/v1/advisor/wp-json/issues-tracker/v1/404