KP Tracking Code Security & Risk Analysis
wordpress.org/plugins/its-tracking-codeThis plugin used to add tracking code to header & footer section.
Is KP Tracking Code Safe to Use in 2026?
Generally Safe
Score 92/100KP Tracking Code has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "its-tracking-code" plugin v1.0.4 exhibits a generally good security posture based on the static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code signals indicate a conscientious effort towards secure coding practices, with all SQL queries utilizing prepared statements and a nonce check present. The lack of any recorded CVEs or previous vulnerabilities suggests a history of stable and secure operation.
However, the static analysis does reveal a critical weakness: 100% of the identified output points are not properly escaped. This represents a significant risk, as unescaped output can lead to cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into web pages viewed by users. While the plugin has no recorded vulnerability history, the presence of unescaped output creates a potential avenue for exploitation that has not yet been discovered or reported. The lack of capability checks on the single nonce check also presents a minor concern, as it might not be tied to appropriate user roles.
Key Concerns
- Unescaped output present
- Nonce check without capability check
KP Tracking Code Security Vulnerabilities
KP Tracking Code Code Analysis
Output Escaping
Data Flow Analysis
KP Tracking Code Attack Surface
WordPress Hooks 4
Maintenance & Trust
KP Tracking Code Maintenance & Trust
Maintenance Signals
Community Trust
KP Tracking Code Alternatives
AddFunc Head & Footer Code
addfunc-head-footer-code
Easily add code to your head, footer and/or immediately after the opening body tag, site-wide and/or on any individual page/post.
GAinWP Google Analytics Integration for WordPress
ga-in
Enable Google Analytics tracking and reporting dashboards in your WordPress site in just seconds.
Embed Code – Headers & Footers by DesignBombs
embed-code
The easiest way to embed code in the head or footer of your site, globally or on a per-page/post basis.
Order Tracking – WordPress Status Tracking Plugin
order-tracking
Order tracking, status and project management plugin. Create tickets and tracking numbers. Send email updates. Works standalone and with WooCommerce.
Qyrr – simply and modern QR-Code creation
qyrr-code
Create, manage and track fully customizable QR Codes without any Third-Party-APIs.
KP Tracking Code Developer Profile
5 plugins · 2K total installs
How We Detect KP Tracking Code
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/its-tracking-code/includes/class-tracking-code-public.php/wp-content/plugins/its-tracking-code/includes/admin/class-tracking-code-admin.php