Microsoft Advertising Universal Event Tracking (UET) Security & Risk Analysis
wordpress.org/plugins/microsoft-advertising-universal-event-tracking-uetThe official plugin for setting up Microsoft Advertising UET
Is Microsoft Advertising Universal Event Tracking (UET) Safe to Use in 2026?
Generally Safe
Score 100/100Microsoft Advertising Universal Event Tracking (UET) has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of the 'microsoft-advertising-universal-event-tracking-uet' plugin v1.0.8 reveals a generally good security posture. The plugin has a zero attack surface in terms of AJAX handlers, REST API routes, shortcodes, and cron events, meaning there are no direct entry points for attackers to exploit through these common vectors. Furthermore, the code does not utilize dangerous functions, performs file operations, or make external HTTP requests, all of which are positive security indicators. All detected SQL queries are properly prepared, and all output is correctly escaped, mitigating risks of injection and cross-site scripting from these areas. Taint analysis shows no critical or high severity flows, indicating that user-supplied data is not being mishandled in sensitive ways.
Despite these strengths, the plugin has a history of one known Common Vulnerability and Exposure (CVE). While this CVE is reported as currently unpatched and was a medium severity Cross-Site Scripting (XSS) vulnerability discovered in July 2022, the absence of any further reported vulnerabilities since then is a positive sign. However, the existence of a past XSS vulnerability, even if addressed in later versions not analyzed here, warrants caution. The lack of explicit capability checks and nonce checks, while not immediately indicating a vulnerability given the zero attack surface, is a weakness that could become a concern if new entry points are introduced in future versions without corresponding security measures.
In conclusion, the plugin exhibits strong adherence to secure coding practices regarding SQL, output, and code execution. The primary concern stems from its past XSS vulnerability, which, though seemingly resolved in subsequent versions, highlights a potential for such issues. The zero attack surface is a significant strength, but the absence of nonces and capability checks on non-existent entry points represents a gap that should ideally be addressed to maintain a robust security posture, especially if the plugin evolves.
Key Concerns
- Past Medium severity XSS vulnerability
- No nonce checks on entry points
- No capability checks on entry points
Microsoft Advertising Universal Event Tracking (UET) Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Microsoft Advertising Universal Event Tracking (UET) <= 1.0.3 - Authenticated Stored Cross-Site Scripting
Microsoft Advertising Universal Event Tracking (UET) Code Analysis
Output Escaping
Microsoft Advertising Universal Event Tracking (UET) Attack Surface
WordPress Hooks 6
Maintenance & Trust
Microsoft Advertising Universal Event Tracking (UET) Maintenance & Trust
Maintenance Signals
Community Trust
Microsoft Advertising Universal Event Tracking (UET) Alternatives
Product Feed for Google Shopping, Microsoft Advertising and 40+ Channels for WooCommerce Merchant
shopping-feed-for-google
Automate real-time product syncing to Google, Microsoft & Facebook from WooCommerce. Launch campaigns and track interactions with Google Analytics 4.
Bing Ads UET
bing-ads-uet
Easily setup Bing Ads UET tag in your WordPress website. A time saver for any #ppc advertiser!
Muzaara Content API Microsoft/Bing Data Feed
muzaara-micosoft-bing-product-data-feed
Microsoft Ads Data Feed - Integrates your WooCommerce Products into Microsoft Merchant Center using the content API or XML data feeds.
Finsbury Media Cookie Consent
finsbury-media-cookie-consent
Lightweight cookie banner with Google, Bing, and Clarity consent support and optional customization.
Ads.txt Manager
ads-txt
Create, manage, and validate your ads.txt and app-ads.txt from within WordPress, like any other content asset.
Microsoft Advertising Universal Event Tracking (UET) Developer Profile
3 plugins · 105K total installs
How We Detect Microsoft Advertising Universal Event Tracking (UET)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/microsoft-advertising-universal-event-tracking-uet/js/uet-tag.js/wp-content/plugins/microsoft-advertising-universal-event-tracking-uet/js/consent.js/wp-content/plugins/microsoft-advertising-universal-event-tracking-uet/js/uet-tag.jsmicrosoft-advertising-universal-event-tracking-uet/js/consent.js?ver=microsoft-advertising-universal-event-tracking-uet/js/uet-tag.js?ver=HTML / DOM Fingerprints
<!-- NOTE: If you update 'Version' above, update the 'tm' parameter in the script. -->name="UetTagSettings[uet_tag_id]"name="UetTagSettings[enable_spa_tracking]"id="uet_tag_id"id="enable_spa_tracking"uet_tag_data