LeadDyno WordPress Plugin Security & Risk Analysis

wordpress.org/plugins/leaddyno

Integrates the LeadDyno affiliate tracking and web analytics service into your blog/wordpress/woocommerce site.

200 active installs v1.10.11 PHP + WP 4.0+ Updated Jan 2, 2026
affiliateaffiliate-marketingaffiliate-programaffiliate-trackingleaddyno
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LeadDyno WordPress Plugin Safe to Use in 2026?

Generally Safe

Score 100/100

LeadDyno WordPress Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the leaddyno plugin version 1.10.11 appears to have a strong security posture. The absence of any reported CVEs and the clean static analysis results, particularly the lack of dangerous functions, unsanitized taint flows, and the use of prepared statements for all SQL queries, are highly positive indicators. The plugin also demonstrates good practices with 100% output escaping and proper nonce and capability checks on its identified entry points.

However, a single external HTTP request without further context presents a potential, albeit minor, area for scrutiny. While the static analysis did not reveal any direct vulnerabilities related to this, it's a common vector for certain types of attacks if not handled with extreme care on the receiving end. The complete lack of recorded vulnerabilities in its history is an excellent sign of robust development and maintenance, suggesting a mature and well-tested codebase. Overall, this plugin seems to be developed with security in mind, with minimal apparent risks based on the data.

Key Concerns

  • External HTTP request without context
Vulnerabilities
None known

LeadDyno WordPress Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

LeadDyno WordPress Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
10 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped10 total outputs
Attack Surface

LeadDyno WordPress Plugin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionplugins_loadedclass-leaddyno-admin.php:40
actionadmin_menuclass-leaddyno-admin.php:63
filterplugin_action_linksclass-leaddyno-admin.php:65
actionadmin_print_stylesclass-leaddyno-admin.php:67
actionadmin_noticesclass-leaddyno-admin.php:197
actionwp_enqueue_scriptsclass-leaddyno-admin.php:463
actionwp_footerclass-leaddyno-admin.php:464
actionwoocommerce_order_status_changedclass-leaddyno-admin.php:465
actionmm_payment_receivedclass-leaddyno-admin.php:532
actionmm_refund_issuedclass-leaddyno-admin.php:573
actionmm_member_status_changeclass-leaddyno-admin.php:604
Maintenance & Trust

LeadDyno WordPress Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 2, 2026
PHP min version
Downloads16K

Community Trust

Rating100/100
Number of ratings30
Active installs200
Developer Profile

LeadDyno WordPress Plugin Developer Profile

leaddyno

1 plugin · 200 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect LeadDyno WordPress Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/leaddyno/leaddyno.css

HTML / DOM Fingerprints

CSS Classes
ld_rowld_desc
Data Attributes
id="leaddynowarning"id="updatemessage"
JS Globals
leaddyno_warning
FAQ

Frequently Asked Questions about LeadDyno WordPress Plugin