
Simple Tracking Security & Risk Analysis
wordpress.org/plugins/simple-theme-optionsAdd site-wide tracking codes and conversion pixels. Additionally manage all your social media links, and display them on your site using shortcodes.
Is Simple Tracking Safe to Use in 2026?
Generally Safe
Score 100/100Simple Tracking has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "simple-theme-options" plugin v2.0.1 exhibits a generally strong security posture, particularly in its handling of SQL queries and output escaping, with 100% of SQL queries using prepared statements and 95% of outputs being properly escaped. The static analysis indicates a very small attack surface with no unprotected entry points and a single capability check. Taint analysis also reveals no critical or high severity vulnerabilities, suggesting a good level of input sanitization and validation within the analyzed flows. However, the absence of nonce checks across all entry points is a notable weakness, leaving the plugin potentially susceptible to CSRF attacks if certain actions were to be exposed through its shortcodes. The vulnerability history, while showing only one past medium severity CVE related to XSS, and no currently unpatched issues, indicates a past instance of improper input neutralization. This, combined with the missing nonce checks, warrants attention for potential future vulnerabilities if new functionalities are added without robust CSRF protection.
Key Concerns
- Missing Nonce Checks
- Past Medium Severity CVE (XSS)
Simple Tracking Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Simple Tracking <= 1.6 - Stored Cross-Site Scripting
Simple Tracking Release Timeline
Simple Tracking Code Analysis
Output Escaping
Simple Tracking Attack Surface
Shortcodes 2
WordPress Hooks 11
Maintenance & Trust
Simple Tracking Maintenance & Trust
Maintenance Signals
Community Trust
Simple Tracking Alternatives
BIG-FLYTX by MAS
big-flytx-by-mas
WooCommerce conversion tracking with GA4, Meta Pixel, dataLayer and optional server-side event delivery for WordPress.
Carticy Conversion Tracking with GA4, Google Ads, and Meta Pixel for WooCommerce
carticy-conversions-for-woocommerce
Reliable, consent-respecting WooCommerce conversion tracking for GA4, Google Ads, and Meta Pixel - tracked from the order, not the thank-you page.
PixelYourSite – Your smart PIXEL (TAG) & API Manager
pixelyoursite
Add Meta Pixel with Conversion API, Google Analytics (GA4) + Consent Mode, Google Tag Manager, and Head & Footer scripts.
GA Google Analytics – Connect Google Analytics to WordPress
ga-google-analytics
Adds Google Analytics tracking code to your WordPress site. Supports many tracking features.
Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative)
burst-statistics
Simple, lightweight WordPress analytics with privacy-friendly visitor tracking. Cookieless and GDPR-ready. Setup in seconds, no cookie banner needed.
Simple Tracking Developer Profile
5 plugins · 350 total installs
How We Detect Simple Tracking
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-theme-options/assets/css/chrssto-admin-styles.css/wp-content/plugins/simple-theme-options/assets/js/chrssto-admin-scripts.js/wp-content/plugins/simple-theme-options/assets/js/simple-theme-options.js/wp-content/plugins/simple-theme-options/assets/js/chrssto-admin-scripts.js/wp-content/plugins/simple-theme-options/assets/js/simple-theme-options.jssimple-theme-options/assets/css/chrssto-admin-styles.css?ver=simple-theme-options/assets/js/chrssto-admin-scripts.js?ver=simple-theme-options/assets/js/simple-theme-options.js?ver=HTML / DOM Fingerprints
chrssto-social-tablechrssto-template-codechrssto-shortcodechrssto-copy-btndata-copychrssto_vars[social-link[social-icons]