Linkyy – A Link Click Tracker Security & Risk Analysis
wordpress.org/plugins/linkyy-link-trackerLightweight link click tracking with admin dashboard analytics for WordPress.
Is Linkyy – A Link Click Tracker Safe to Use in 2026?
Generally Safe
Score 100/100Linkyy – A Link Click Tracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "linkyy-link-tracker" v1.0.0 plugin exhibits a generally good security posture, with several positive indicators. Notably, all SQL queries utilize prepared statements, all output is properly escaped, and there are no dangerous functions or file operations detected. The plugin also avoids making external HTTP requests and does not bundle any libraries, which reduces the potential attack surface from these vectors. The complete absence of known vulnerabilities and a clean vulnerability history further bolster its security profile.
However, there are a few areas that warrant attention. The plugin exposes one unprotected REST API route, which represents a potential entry point for unauthorized access or manipulation if not properly secured at the application level. While taint analysis shows no issues, the limited scope of analysis (0 flows analyzed) might not cover all potential risks. The presence of only two nonce checks and one capability check across all entry points also suggests a potential for privilege escalation or unauthorized actions if these checks are insufficient for the specific functionality they are intended to protect.
In conclusion, the plugin demonstrates strong adherence to fundamental security practices like prepared statements and output escaping. Its clean vulnerability history is a significant strength. The primary concerns lie with the unprotected REST API endpoint and the limited scope of security checks, which could be improved. Overall, the plugin appears relatively secure for version 1.0.0, but the identified entry point without explicit permission checks requires careful consideration.
Key Concerns
- Unprotected REST API route
- Limited taint analysis scope
- Low number of capability checks
Linkyy – A Link Click Tracker Security Vulnerabilities
Linkyy – A Link Click Tracker Release Timeline
Linkyy – A Link Click Tracker Code Analysis
SQL Query Safety
Output Escaping
Linkyy – A Link Click Tracker Attack Surface
REST API Routes 3
WordPress Hooks 9
Scheduled Events 1
Maintenance & Trust
Linkyy – A Link Click Tracker Maintenance & Trust
Maintenance Signals
Community Trust
Linkyy – A Link Click Tracker Alternatives
Track a click on Google Analytics
track-a-click-on-google-analytics
A simple shortcode to insert Google Analytics event tracking code on your links
Macymed Link Tracker
macymed-link-tracker
LinkTracker is a powerful tool to analyze your site traffic, analyze clicks on your links and generate detailed reports for your campaigns.
Click Counter by Simple Tools
click-counter
Advanced click tracking for any CSS selector. Analytics, charts, goals, CSV export, visual picker, and more.
ShortLinks Pro – Affiliate Links, Link Shortening, Click Tracking & Marketing
shortlinkspro
Shorten, track, manage and share any URL using your own domain name!
Smart Click Tracker
smart-click-tracker
Track clicks on any element of your WordPress site and view detailed statistics with beautiful charts.
Linkyy – A Link Click Tracker Developer Profile
1 plugin · 10 total installs
How We Detect Linkyy – A Link Click Tracker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/linkyy-link-tracker/assets/css/admin.css/wp-content/plugins/linkyy-link-tracker/assets/js/admin-dashboard.js/wp-content/plugins/linkyy-link-tracker/assets/js/admin-dashboard.jslinkyy-link-tracker/assets/css/admin.css?ver=linkyy-link-tracker/assets/js/admin-dashboard.js?ver=HTML / DOM Fingerprints
window.LinkyyDashboardConfigwindow.LinkyyI18n/wp-json/linkyy/v1/pages/wp-json/linkyy/v1/clicks