LH UTM Tracking Security & Risk Analysis

wordpress.org/plugins/lh-utm-tracking

The proper way to capture UTMs on your (optin) forms.

0 active installs v1.00 PHP + WP 4.0+ Updated Oct 27, 2017
collectgrabberleadsshortcodesutm
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LH UTM Tracking Safe to Use in 2026?

Generally Safe

Score 85/100

LH UTM Tracking has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "lh-utm-tracking" v1.00 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, unescaped output, raw SQL queries, file operations, external HTTP requests, and a complete lack of identified taint flows with unsanitized paths are all excellent indicators of secure coding practices. Furthermore, the plugin's attack surface is negligible, with no AJAX handlers, REST API routes, shortcodes, or cron events found, and critically, no unprotected entry points.

The vulnerability history is also clean, with zero known CVEs, indicating that this plugin has either been very well-maintained or has not been a target for attackers. The lack of any recorded vulnerability types or recent issues further strengthens this observation. However, it is important to note that the analysis reports zero capability checks and zero nonce checks. While the current attack surface is minimal, any future introduction of functionalities that handle user input or perform sensitive actions without proper authorization and nonce verification would represent a significant risk.

In conclusion, "lh-utm-tracking" v1.00 appears to be a highly secure plugin in its current state, with no readily apparent vulnerabilities. Its minimal attack surface and clean vulnerability history are commendable. The primary area for caution lies in the absence of capability and nonce checks, which, while not an issue in this version's limited scope, could become a critical weakness if the plugin were expanded without these security measures.

Key Concerns

  • No capability checks found
  • No nonce checks found
Vulnerabilities
None known

LH UTM Tracking Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

LH UTM Tracking Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

LH UTM Tracking Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filterscript_loader_taglh-utm-tracking.php:56
actioninitlh-utm-tracking.php:123
Maintenance & Trust

LH UTM Tracking Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedOct 27, 2017
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

LH UTM Tracking Developer Profile

shawfactor

77 plugins · 15K total installs

91
trust score
Avg Security Score
87/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect LH UTM Tracking

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lh-utm-tracking/scripts/purser.js
Script Paths
/wp-content/plugins/lh-utm-tracking/scripts/purser.js
Version Parameters
lh-utm-tracking/scripts/purser.js?ver=

HTML / DOM Fingerprints

Data Attributes
defer="defer"
FAQ

Frequently Asked Questions about LH UTM Tracking