MCP Tracker Security & Risk Analysis
wordpress.org/plugins/mcp-trackerRecords and displays MCP-related REST API requests made to your WordPress site.
Is MCP Tracker Safe to Use in 2026?
Generally Safe
Score 100/100MCP Tracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mcp-tracker plugin version 1.0.0 exhibits a strong security posture based on the provided static analysis. The absence of any identified attack surface entry points without authentication checks, coupled with 100% usage of prepared statements for SQL queries and proper output escaping, indicates diligent development practices concerning common web vulnerabilities. The plugin also demonstrates a clean vulnerability history with zero recorded CVEs, suggesting a stable and well-maintained codebase. There are no critical or high severity taint flows detected, further reinforcing its security. However, the complete absence of nonce checks, while not directly a vulnerability in this specific static analysis due to a lack of entry points, is a standard security measure that is often implemented to prevent CSRF attacks. Similarly, the presence of capability checks without associated entry points suggests either incomplete analysis or potential for future risk if entry points are added without proper authorization. Overall, the plugin appears secure for its current state, but vigilance regarding potential future additions to the attack surface and ensuring proper authorization checks are maintained is recommended.
Key Concerns
- Missing nonce checks on potential future entry points
- Capability checks present without entry points
MCP Tracker Security Vulnerabilities
MCP Tracker Release Timeline
MCP Tracker Code Analysis
SQL Query Safety
Output Escaping
MCP Tracker Attack Surface
WordPress Hooks 9
Maintenance & Trust
MCP Tracker Maintenance & Trust
Maintenance Signals
Community Trust
MCP Tracker Alternatives
Developer Loggers for Simple History
developer-loggers-for-simple-history
Useful loggers for SimpleHistory for developers during development of a site or to maintain a live site.
Easy MCP AI
easy-mcp-ai
Connect Claude, ChatGPT & any MCP-compatible AI to WordPress — create, edit & manage content without the admin panel. 100+ built-in tools. 100% free.
Enable Abilities for MCP
enable-abilities-for-mcp
Manage which WordPress Abilities are exposed to MCP servers. Supports WooCommerce, The Events Calendar, and any custom post type.
WPRaiz Content API Tool
wpraiz-content-api-tool
REST API + MCP Server for WordPress. Create, update, and manage posts programmatically. AI content generation with your own API keys (BYOK).
REST API Route Tester
rest-api-route-tester
A WordPress admin tool to quickly test REST API routes, path params, headers, body payloads, and copy requests as cURL.
MCP Tracker Developer Profile
12 plugins · 201K total installs
How We Detect MCP Tracker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mcp-tracker/assets/admin/css/app.css/wp-content/plugins/mcp-tracker/assets/admin/js/app.js/wp-content/plugins/mcp-tracker/assets/admin/js/app.js/wp-content/plugins/mcp-tracker/assets/admin/js/app.js?ver=/wp-content/plugins/mcp-tracker/assets/admin/css/app.css?ver=HTML / DOM Fingerprints
wpvmcpt-app-rootdata-api-urldata-noncedata-site-urldata-admin-urldata-plugin-urlwpvmcpt/wpvmcpt/v1/requests/wpvmcpt/v1/filters