LoL Tracker Security & Risk Analysis
wordpress.org/plugins/loltrackerLoL Tracker is a set of tools relating your league of Legends account.
Is LoL Tracker Safe to Use in 2026?
Generally Safe
Score 85/100LoL Tracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "loltracker" plugin v1.0.0 exhibits a concerning security posture due to its unprotected entry points and lack of robust security checks. The analysis reveals two AJAX handlers, both lacking authentication checks, which represent significant attack vectors. Furthermore, the presence of the dangerous `create_function` call is a critical red flag, often associated with remote code execution vulnerabilities if user input is involved. The low percentage of properly escaped output (7%) indicates a high risk of cross-site scripting (XSS) vulnerabilities. While the plugin avoids raw SQL queries and has no recorded vulnerability history, these positive points are heavily overshadowed by the critical flaws in its handling of user input and entry points. The absence of nonce and capability checks on its AJAX endpoints makes it highly susceptible to unauthorized actions and further exploitation.
Key Concerns
- AJAX handlers without auth checks
- Dangerous function create_function used
- Low output escaping percentage
- No nonce checks on AJAX
- No capability checks on AJAX
LoL Tracker Security Vulnerabilities
LoL Tracker Release Timeline
LoL Tracker Code Analysis
Dangerous Functions Found
Output Escaping
LoL Tracker Attack Surface
AJAX Handlers 2
WordPress Hooks 9
Maintenance & Trust
LoL Tracker Maintenance & Trust
Maintenance Signals
Community Trust
LoL Tracker Alternatives
Ad Inserter – Ad Manager & AdSense Ads
ad-inserter
Manage Google AdSense ads, banners, ad rotation, sticky widgets, AMP ads, ads.txt, tracking, header and footer code, PHP code, global custom fields
FlatPM – Ad Manager, AdSense and Custom Code
flatpm-wp
Flat PM is an ad management plugin. You might be thinking, "why do I need it?". It's simple: this is the best plugin for organizing ads …
Image Rotation Repair
image-rotation-repair
The Image Rotation Repair plugin simply fixes image orientation based on EXIF data. This is primarily a patch for mis-oriented images delivered from …
Fix Image Rotation
fix-image-rotation
Fixes the rotation of the images based on EXIF data
Random Content
random-content
Display random content anywhere on your WordPress site. Rotate testimonials, banners, CTAs, and more with a simple shortcode or widget.
LoL Tracker Developer Profile
1 plugin · 10 total installs
How We Detect LoL Tracker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/loltracker/admin/css/lol-tracker-admin.css/wp-content/plugins/loltracker/admin/js/lol-tracker-admin.js/wp-content/plugins/loltracker/admin/js/lol-tracker-admin.jslol-tracker-admin.css?ver=lol-tracker-admin.js?ver=HTML / DOM Fingerprints
name='lol_tracker_settings[lol_tracker_riot_api_key]'name='lol_tracker_settings[lol_tracker_region_name]'