LH UTM Tracking Security & Risk Analysis
wordpress.org/plugins/lh-utm-trackingThe proper way to capture UTMs on your (optin) forms.
Is LH UTM Tracking Safe to Use in 2026?
Generally Safe
Score 85/100LH UTM Tracking has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "lh-utm-tracking" v1.00 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, unescaped output, raw SQL queries, file operations, external HTTP requests, and a complete lack of identified taint flows with unsanitized paths are all excellent indicators of secure coding practices. Furthermore, the plugin's attack surface is negligible, with no AJAX handlers, REST API routes, shortcodes, or cron events found, and critically, no unprotected entry points.
The vulnerability history is also clean, with zero known CVEs, indicating that this plugin has either been very well-maintained or has not been a target for attackers. The lack of any recorded vulnerability types or recent issues further strengthens this observation. However, it is important to note that the analysis reports zero capability checks and zero nonce checks. While the current attack surface is minimal, any future introduction of functionalities that handle user input or perform sensitive actions without proper authorization and nonce verification would represent a significant risk.
In conclusion, "lh-utm-tracking" v1.00 appears to be a highly secure plugin in its current state, with no readily apparent vulnerabilities. Its minimal attack surface and clean vulnerability history are commendable. The primary area for caution lies in the absence of capability and nonce checks, which, while not an issue in this version's limited scope, could become a critical weakness if the plugin were expanded without these security measures.
Key Concerns
- No capability checks found
- No nonce checks found
LH UTM Tracking Security Vulnerabilities
LH UTM Tracking Code Analysis
LH UTM Tracking Attack Surface
WordPress Hooks 2
Maintenance & Trust
LH UTM Tracking Maintenance & Trust
Maintenance Signals
Community Trust
LH UTM Tracking Alternatives
UTM Leads Tracker – XLPlugins
utm-leads-tracker-lite
Discover which marketing campaigns are actually profitable and which are wasting your time & money. UTM Lead Tracker records the source of the lea …
Lenix Leads Collector
lenix-elementor-leads-addon
Leads Collector, Collects forms entries from Elementor,Cf7,WPForms and more with export to CSV.
UTM Event Tracker and Analytics, UTM Grabber
utm-event-tracker-and-analytics
Easily capture UTM parameters, track button and link clicks, and analyze campaigns to improve your marketing ROI in WordPress.
UTM Manager – UTM Tracking, Lead Attribution & Campaign Analytics
utm-manager
Track UTM parameters, capture leads with full attribution, and analyze marketing campaigns directly from your WordPress dashboard.
GB Forms DB
gb-forms-db
One lead collector to rule them all! The best place to save all your leads from all forms in one place! Easily manage, export or post all your leads …
LH UTM Tracking Developer Profile
77 plugins · 15K total installs
How We Detect LH UTM Tracking
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lh-utm-tracking/scripts/purser.js/wp-content/plugins/lh-utm-tracking/scripts/purser.jslh-utm-tracking/scripts/purser.js?ver=HTML / DOM Fingerprints
defer="defer"