Simple URL Tracker – By Projekt15 Security & Risk Analysis

wordpress.org/plugins/simple-url-tracker

Simple URL Tracker is an easy to use campaign link generator. Simply enter your parameters and update the page or post to create a trackable link.

10 active installs v1.0.0 PHP 7.1+ WP 5.1+ Updated Dec 14, 2019
campaigncampaign-urltrackingurlurl-tracker
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple URL Tracker – By Projekt15 Safe to Use in 2026?

Generally Safe

Score 85/100

Simple URL Tracker – By Projekt15 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "simple-url-tracker" v1.0.0 plugin exhibits a seemingly strong security posture based on the provided static analysis and vulnerability history. The absence of identified AJAX handlers, REST API routes, shortcodes, cron events, and dangerous functions suggests a limited attack surface and adherence to secure coding practices in these areas. Furthermore, the complete utilization of prepared statements for SQL queries and the absence of file operations and external HTTP requests are significant strengths.

However, a notable concern arises from the output escaping analysis, where only 50% of the total outputs are properly escaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, as unsanitized output can be injected with malicious scripts that are then rendered by the browser. The lack of any identified taint flows or non-existent vulnerability history, while positive, does not negate the risk posed by insufficient output escaping. The plugin's vulnerability history being entirely clear also suggests either excellent past security or potentially limited prior analysis or usage, making the current static analysis results particularly important.

In conclusion, while the plugin demonstrates good practices in areas like SQL handling and attack surface minimization, the 50% rate of unescaped output is a significant weakness that warrants attention. The absence of known vulnerabilities is encouraging, but this should not overshadow the identified potential for XSS. Further investigation into the specific outputs that are not properly escaped would be recommended to fully assess and mitigate this risk.

Key Concerns

  • Half of output is not properly escaped
Vulnerabilities
None known

Simple URL Tracker – By Projekt15 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Simple URL Tracker – By Projekt15 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped10 total outputs
Attack Surface

Simple URL Tracker – By Projekt15 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadd_meta_boxesadmin\class-simple-track-admin.php:122
actionsave_postadmin\class-simple-track-admin.php:223
actionplugins_loadedincludes\class-simple-track.php:142
actionadmin_enqueue_scriptsincludes\class-simple-track.php:157
actionadmin_enqueue_scriptsincludes\class-simple-track.php:158
actionwp_enqueue_scriptsincludes\class-simple-track.php:173
actionwp_enqueue_scriptsincludes\class-simple-track.php:174
Maintenance & Trust

Simple URL Tracker – By Projekt15 Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedDec 14, 2019
PHP min version7.1
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Simple URL Tracker – By Projekt15 Developer Profile

jasonat15

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple URL Tracker – By Projekt15

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-url-tracker/admin/css/simple-track-admin.css/wp-content/plugins/simple-url-tracker/admin/js/simple-track-admin.js
Script Paths
/wp-content/plugins/simple-url-tracker/admin/js/simple-track-admin.js

HTML / DOM Fingerprints

Shortcode Output
<div style='width:100%;'>?utm_source=&utm_medium=&utm_campaign=
FAQ

Frequently Asked Questions about Simple URL Tracker – By Projekt15