
Simple Tracking Security & Risk Analysis
wordpress.org/plugins/simple-theme-optionsAdd site-wide tracking codes and conversion pixels. Additionally manage all your social media links, and display them on your site using shortcodes.
Is Simple Tracking Safe to Use in 2026?
Generally Safe
Score 100/100Simple Tracking has a strong security track record. Known vulnerabilities have been patched promptly.
The "simple-theme-options" plugin v2.0.1 exhibits a generally strong security posture, particularly in its handling of SQL queries and output escaping, with 100% of SQL queries using prepared statements and 95% of outputs being properly escaped. The static analysis indicates a very small attack surface with no unprotected entry points and a single capability check. Taint analysis also reveals no critical or high severity vulnerabilities, suggesting a good level of input sanitization and validation within the analyzed flows. However, the absence of nonce checks across all entry points is a notable weakness, leaving the plugin potentially susceptible to CSRF attacks if certain actions were to be exposed through its shortcodes. The vulnerability history, while showing only one past medium severity CVE related to XSS, and no currently unpatched issues, indicates a past instance of improper input neutralization. This, combined with the missing nonce checks, warrants attention for potential future vulnerabilities if new functionalities are added without robust CSRF protection.
Key Concerns
- Missing Nonce Checks
- Past Medium Severity CVE (XSS)
Simple Tracking Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Simple Tracking <= 1.6 - Stored Cross-Site Scripting
Simple Tracking Code Analysis
Output Escaping
Simple Tracking Attack Surface
Shortcodes 2
WordPress Hooks 11
Maintenance & Trust
Simple Tracking Maintenance & Trust
Maintenance Signals
Community Trust
Simple Tracking Alternatives
PixelYourSite – Your smart PIXEL (TAG) & API Manager
pixelyoursite
Add Meta Pixel with Conversion API, Google Analytics (GA4) + Consent Mode, Google Tag Manager, and Head & Footer scripts.
GA Google Analytics – Connect Google Analytics to WordPress
ga-google-analytics
Adds Google Analytics tracking code to your WordPress site. Supports many tracking features.
Pixel Manager for WooCommerce – Conversion Tracking, Google Ads, GA4, TikTok, Dynamic Remarketing
woocommerce-google-adwords-conversion-tracking-tag
Conversion tracking for WooCommerce. Google Ads, GA4, Meta/Facebook Pixel, TikTok & more. Recover 30% more conversions with server-side tracking!
Conversios: Google Analytics (GA4), Google Ads, Conversion and Analytics Tracking for Multi-Channels
enhanced-e-commerce-for-woocommerce-store
Track GA4 Analytics, Google Ads, Microsoft Ads, & Conversion with server-side tracking (CAPI) & product feed to improve ROAS, reports for WooCommerce.
Simple Universal Google Analytics
simple-universal-google-analytics
Enable Universal Google Analytics tracking option on your WordPress site. Add tracking code to every page with WordPress Google Analytics plugin.
Simple Tracking Developer Profile
4 plugins · 400 total installs
How We Detect Simple Tracking
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-theme-options/assets/css/chrssto-admin-styles.css/wp-content/plugins/simple-theme-options/assets/js/chrssto-admin-scripts.js/wp-content/plugins/simple-theme-options/assets/js/simple-theme-options.js/wp-content/plugins/simple-theme-options/assets/js/chrssto-admin-scripts.js/wp-content/plugins/simple-theme-options/assets/js/simple-theme-options.jssimple-theme-options/assets/css/chrssto-admin-styles.css?ver=simple-theme-options/assets/js/chrssto-admin-scripts.js?ver=simple-theme-options/assets/js/simple-theme-options.js?ver=HTML / DOM Fingerprints
chrssto-social-tablechrssto-template-codechrssto-shortcodechrssto-copy-btndata-copychrssto_vars[social-link[social-icons]