
schubwerk Tracking Security & Risk Analysis
wordpress.org/plugins/schubwerkschubwerk Analytics Plugin für Wordpress: DSGVO-konformes, serverseitiges Tracking (cookieless)
Is schubwerk Tracking Safe to Use in 2026?
Generally Safe
Score 100/100schubwerk Tracking has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The schubwerk plugin v2.3.0 exhibits a generally good security posture, with no recorded vulnerabilities or critical issues identified in taint analysis. The code demonstrates strong adherence to secure coding practices, notably the absence of dangerous functions, exclusive use of prepared statements for SQL queries, and a high percentage of properly escaped output. The plugin also includes capability checks, which is a positive sign for access control.
However, a significant concern arises from the presence of one unprotected REST API route, representing a direct entry point to the plugin's functionality that lacks permission validation. While there are no currently known CVEs or a history of past vulnerabilities, this single unprotected entry point could be a potential vector for attack if it exposes sensitive operations or data. The lack of nonce checks on any AJAX handlers (though there are none) and the absence of taint flows analyzed could also mask potential issues, but the current data doesn't provide evidence of this.
In conclusion, schubwerk v2.3.0 is largely secure due to its sound coding practices. The primary weakness lies in the unprotected REST API endpoint, which warrants immediate attention and the implementation of appropriate permission checks to fully mitigate any associated risks.
Key Concerns
- Unprotected REST API route
schubwerk Tracking Security Vulnerabilities
schubwerk Tracking Code Analysis
Output Escaping
schubwerk Tracking Attack Surface
REST API Routes 1
WordPress Hooks 8
Maintenance & Trust
schubwerk Tracking Maintenance & Trust
Maintenance Signals
Community Trust
schubwerk Tracking Alternatives
Pixelavo – Server Side Tracking & Pixel + AI Ads Tools
pixelavo
Add pixel tracking to your WordPress site with Conversions API, server-side tracking, AI ad copy generation, and AI marketing consultant.
Beetle Tracking – Cloudflare Zaraz for WooCommerce
beetle-tracking
Track Key Events and Parameters on WordPress Effortlessly with Cloudflare Zaraz's Real Edge Server-Side Tracking Technology.
UniPixel: Meta, Pinterest, TikTok, Google & Microsoft Server-Side Tracking for WooCommerce
unipixel
Send conversion events from your WordPress server to Meta, Pinterest, TikTok, Google and Microsoft. No cloud, no GTM. WooCommerce and custom events.
Server Side Tracking via GTM for Google Analytics 4, Meta Conversions API & Google Ads
server-side-tagging-via-google-tag-manager-for-wordpress
Fix missing WooCommerce conversions using server-side GTM tracking. Improve GA4, Google Ads & Meta Conversions API accuracy.
ClickTrail – UTM, Click ID & Ad Tracking (with Consent)
click-trail-handler
Consent-aware attribution for WooCommerce, WordPress forms, and event flows. Capture UTMs and click IDs across conversion paths.
schubwerk Tracking Developer Profile
1 plugin · 100 total installs
How We Detect schubwerk Tracking
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/schubwerk-tracking/public/css/schubwerk-tracking-public.css/wp-content/plugins/schubwerk-tracking/public/js/schubwerk-tracking-public.js/wp-content/plugins/schubwerk-tracking/public/js/schubwerk-tracking-public.jsschubwerk-tracking-public.css?ver=schubwerk-tracking-public.js?ver=HTML / DOM Fingerprints
<!--Elementor/Iframes issue when uncommented-->schubwerk_tracker_ajax_object/wp-json/schubwerk-tracking