Macymed Link Tracker Security & Risk Analysis
wordpress.org/plugins/macymed-link-trackerLinkTracker is a powerful tool to analyze your site traffic, analyze clicks on your links and generate detailed reports for your campaigns.
Is Macymed Link Tracker Safe to Use in 2026?
Generally Safe
Score 92/100Macymed Link Tracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "macymed-link-tracker" v1.2.0.0 plugin exhibits a concerning security posture primarily due to its substantial attack surface exposed through AJAX handlers. A significant weakness is the presence of 10 AJAX handlers, all of which lack authentication checks, creating a broad entry point for potential attackers. While the plugin demonstrates good practices in other areas, such as a high percentage of properly escaped output and the predominant use of prepared statements for SQL queries, these strengths are overshadowed by the critical exposure of its AJAX endpoints.
The taint analysis reveals 4 flows with unsanitized paths, all categorized as high severity. This indicates that user-supplied data in these flows is not being adequately validated or sanitized before being processed, potentially leading to vulnerabilities like cross-site scripting (XSS) or path traversal if these flows are reachable through the unprotected AJAX endpoints.
Fortunately, the plugin has no recorded vulnerability history, which suggests a historical lack of exploitable flaws. However, this positive track record should not detract from the immediate risks identified in the static analysis. The combination of a large, unprotected attack surface and high-severity taint flows presents a clear and present danger that requires immediate attention.
Key Concerns
- 10 unprotected AJAX handlers
- 4 high severity unsanitized flows
- Bundled outdated library: dompdf
Macymed Link Tracker Security Vulnerabilities
Macymed Link Tracker Release Timeline
Macymed Link Tracker Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Macymed Link Tracker Attack Surface
AJAX Handlers 10
WordPress Hooks 96
Maintenance & Trust
Macymed Link Tracker Maintenance & Trust
Maintenance Signals
Community Trust
Macymed Link Tracker Alternatives
Linkyy – A Link Click Tracker
linkyy-link-tracker
Lightweight link click tracking with admin dashboard analytics for WordPress.
Track a click on Google Analytics
track-a-click-on-google-analytics
A simple shortcode to insert Google Analytics event tracking code on your links
Click Counter by Simple Tools
click-counter
Advanced click tracking for any CSS selector. Analytics, charts, goals, CSV export, visual picker, and more.
ShortLinks Pro – Affiliate Links, Link Shortening, Click Tracking & Marketing
shortlinkspro
Shorten, track, manage and share any URL using your own domain name!
Smart Click Tracker
smart-click-tracker
Track clicks on any element of your WordPress site and view detailed statistics with beautiful charts.
Macymed Link Tracker Developer Profile
1 plugin · 0 total installs
How We Detect Macymed Link Tracker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/macymed-link-tracker/resources/css/app.css/wp-content/plugins/macymed-link-tracker/resources/js/app.js/wp-content/plugins/macymed-link-tracker/resources/js/app.jsmacymed-link-tracker/resources/css/app.css?ver=macymed-link-tracker/resources/js/app.js?ver=HTML / DOM Fingerprints
macymed-link-tracker-redirect-pagedata-macymed-redirect-urldata-macymed-redirect-delaymacymedLinkTrackerData