Kawuda UTM source tracker Security & Risk Analysis
wordpress.org/plugins/kawuda-utm-source-trackerKawuda is a simple UTM source tracking system. No need depend on 3rd party. You can use this as your own anatlatic system
Is Kawuda UTM source tracker Safe to Use in 2026?
Generally Safe
Score 92/100Kawuda UTM source tracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "kawuda-utm-source-tracker" plugin v1.6.0 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding output escaping, with 98% of outputs being properly escaped. It also avoids dangerous functions, file operations, and external HTTP requests, which are common sources of vulnerabilities. Furthermore, its vulnerability history is clean, with no recorded CVEs, suggesting a generally stable codebase in the past.
However, significant concerns arise from the attack surface analysis. A total of 7 entry points are identified, and alarmingly, all 7 are unprotected, meaning they lack authentication and authorization checks. This creates a broad attack surface where an attacker could potentially interact with these functions without proper validation. The taint analysis further exacerbates this concern, revealing 4 high-severity flows with unsanitized paths. While not explicitly detailed as vulnerabilities, these unsanitized paths in a large unprotected attack surface strongly indicate potential for exploitation.
In conclusion, while the plugin has a positive history and good practices in specific areas like output escaping, the extensive unprotected attack surface combined with high-severity unsanitized taint flows presents a significant risk. The lack of robust authentication and permission checks on numerous entry points is a critical weakness that could allow for unauthorized actions or data manipulation.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API route
- High severity unsanitized taint flows
Kawuda UTM source tracker Security Vulnerabilities
Kawuda UTM source tracker Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Kawuda UTM source tracker Attack Surface
AJAX Handlers 6
REST API Routes 1
WordPress Hooks 6
Maintenance & Trust
Kawuda UTM source tracker Maintenance & Trust
Maintenance Signals
Community Trust
Kawuda UTM source tracker Alternatives
GA Google Analytics – Connect Google Analytics to WordPress
ga-google-analytics
Adds Google Analytics tracking code to your WordPress site. Supports many tracking features.
Metricool
metricool
Metricool is the first tool designed to measure #Blog impact and #SocialMedia activity.
SlimStat Analytics
wp-slimstat
The leading web analytics plugin for WordPress
Connect Matomo – Analytics Dashboard for WordPress
wp-piwik
Adds Matomo (former Piwik) statistics to your WordPress dashboard and is also able to add the Matomo Tracking Code to your blog.
Pixel Manager for WooCommerce – Conversion Tracking, Google Ads, GA4, TikTok, Dynamic Remarketing
woocommerce-google-adwords-conversion-tracking-tag
Conversion tracking for WooCommerce. Google Ads, GA4, Meta/Facebook Pixel, TikTok & more. Recover 30% more conversions with server-side tracking!
Kawuda UTM source tracker Developer Profile
4 plugins · 30 total installs
How We Detect Kawuda UTM source tracker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kawuda-utm-source-tracker/assets/css/jquery-ui.min.css/wp-content/plugins/kawuda-utm-source-tracker/assets/css/style.css/wp-content/plugins/kawuda-utm-source-tracker/assets/js/common.js/wp-content/plugins/kawuda-utm-source-tracker/assets/js/loader.js/wp-content/plugins/kawuda-utm-source-tracker/assets/js/chart.js/wp-content/plugins/kawuda-utm-source-tracker/assets/js/common.js/wp-content/plugins/kawuda-utm-source-tracker/assets/js/loader.js/wp-content/plugins/kawuda-utm-source-tracker/assets/js/chart.jskawuda-utm-source-tracker/assets/css/style.css?v=kawuda-utm-source-tracker/assets/js/common.js?ver=kawuda-utm-source-tracker/assets/js/loader.js?ver=kawuda-utm-source-tracker/assets/js/chart.js?ver=HTML / DOM Fingerprints
kawuda_js_vars/wp-json/kawuda/v1/hit/