LeadSource Tracker – Free Edition Security & Risk Analysis
wordpress.org/plugins/leadsource-trackerLeadSource Tracker is a simple campaign and marketing attribution that tracks multiple lead sources per visitor.
Is LeadSource Tracker – Free Edition Safe to Use in 2026?
Generally Safe
Score 85/100LeadSource Tracker – Free Edition has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "leadsource-tracker" v1.0 plugin exhibits a generally strong security posture based on the provided static analysis. A notable strength is the complete absence of dangerous functions, file operations, external HTTP requests, and the consistent use of prepared statements for SQL queries. All identified output is also properly escaped, indicating good development practices in these critical areas. The lack of any recorded vulnerabilities, including CVEs of any severity, further contributes to a positive security outlook.
However, the analysis does raise some concerns. The 'Taint Analysis' section indicates two flows with unsanitized paths. While these are not classified as critical or high severity, they represent potential avenues for injection vulnerabilities if user-supplied data is not handled meticulously within these flows. Furthermore, the complete absence of nonce checks and capability checks across all entry points is a significant weakness. This lack of authentication and authorization controls on potential entry points, even if currently limited, opens the door for privilege escalation or unauthorized data manipulation if any new entry points are introduced or if the existing ones are discovered and exploited.
In conclusion, the plugin demonstrates solid coding hygiene in areas like SQL and output handling, and its vulnerability history is clean. Nevertheless, the unsanitized taint flows and the complete lack of authorization mechanisms on entry points are significant security gaps that require attention. Addressing these would elevate the plugin's security to a more robust level.
Key Concerns
- Unsanitized paths in taint flows
- Missing nonce checks on entry points
- Missing capability checks on entry points
LeadSource Tracker – Free Edition Security Vulnerabilities
LeadSource Tracker – Free Edition Code Analysis
Data Flow Analysis
LeadSource Tracker – Free Edition Attack Surface
WordPress Hooks 4
Maintenance & Trust
LeadSource Tracker – Free Edition Maintenance & Trust
Maintenance Signals
Community Trust
LeadSource Tracker – Free Edition Alternatives
CallTrackingMetrics
call-tracking-metrics
CallTrackingMetrics integrates with your WordPress site to provide powerful call tracking and attribution.
ThoughtMetric for WooCommerce
thoughtmetric-for-woocommerce
ThoughtMetric is a marketing attribution solution for e-commerce stores.
UTM Tracker for Contact Form 7
utm-tracker-for-contact-form-7
Track UTM parameters in Contact Form 7 submissions automatically and identify which campaigns generate real leads from your marketing traffic.
LeadSource Tracker – Free Edition Developer Profile
1 plugin · 10 total installs
How We Detect LeadSource Tracker – Free Edition
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrapname="ldsrctrckr_store_leadsource_pg_1"