PlugTracker Security & Risk Analysis
wordpress.org/plugins/plugtrackerTracks plugin activity, including activation, deactivation, addition, deletion, and updates, with date, time, and user information recorded.
Is PlugTracker Safe to Use in 2026?
Generally Safe
Score 100/100PlugTracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "plugtracker" v1.0 plugin exhibits a mixed security posture. On the positive side, there are no recorded historical vulnerabilities (CVEs), no dangerous functions used, no file operations, no external HTTP requests, and a high percentage of properly escaped output. This suggests some good development practices are in place.
However, significant concerns are raised by the static analysis. The plugin has a single AJAX handler that lacks any authentication or capability checks, creating a critical attack surface. Furthermore, both SQL queries are executed without prepared statements, posing a risk of SQL injection. The absence of nonce checks on the AJAX endpoint is another major security oversight. The lack of taint analysis results is unusual but doesn't negate the identified risks.
In conclusion, while the absence of historical vulnerabilities is a positive indicator, the current version of "plugtracker" presents immediate and serious security risks due to its unprotected AJAX endpoint and vulnerable SQL query handling. These findings necessitate immediate attention to secure these entry points. The plugin's strengths lie in its limited external interactions and relatively good output sanitization, but these are overshadowed by the fundamental security flaws.
Key Concerns
- Unprotected AJAX handler
- SQL queries without prepared statements
- Missing nonce checks on AJAX
PlugTracker Security Vulnerabilities
PlugTracker Code Analysis
SQL Query Safety
Output Escaping
PlugTracker Attack Surface
AJAX Handlers 1
WordPress Hooks 9
Maintenance & Trust
PlugTracker Maintenance & Trust
Maintenance Signals
Community Trust
PlugTracker Alternatives
WP Plugin Manager – Deactivate plugins per page
wp-plugin-manager
"WP Plugin Manager" is a plugin that allows you to disable plugins on specific pages, posts, or devices for better performance.
Plugin Activation Tracker
plugin-activation-tracker
Keep track of plugins you activate or deactivate through the dashboard by viewing when each and every one of them was enabled or disabled.
WP Rollback – Rollback Plugins and Themes
wp-rollback
Rollback (or forward) any WordPress.org plugin, theme, or block like a boss.
Download Plugin
download-plugin
Download any plugin from your WordPress admin panel's Plugins page by just one click! Now, download themes, users, blog posts, pages, custom post …
Advanced Automatic Updates
automatic-updater
Adds extra options to WordPress' built-in Automatic Updates feature.
PlugTracker Developer Profile
8 plugins · 320 total installs
How We Detect PlugTracker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/plugtracker/assets/css/style.css/wp-content/plugins/plugtracker/assets/js/admin.js/wp-content/plugins/plugtracker/assets/js/admin.jsplugtracker-script?ver=plugtracker-style?ver=HTML / DOM Fingerprints
tab-containertab-buttontab-contentdata-tabWPTAjax