Simple URL Tracker – By Projekt15 Security & Risk Analysis
wordpress.org/plugins/simple-url-trackerSimple URL Tracker is an easy to use campaign link generator. Simply enter your parameters and update the page or post to create a trackable link.
Is Simple URL Tracker – By Projekt15 Safe to Use in 2026?
Generally Safe
Score 85/100Simple URL Tracker – By Projekt15 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "simple-url-tracker" v1.0.0 plugin exhibits a seemingly strong security posture based on the provided static analysis and vulnerability history. The absence of identified AJAX handlers, REST API routes, shortcodes, cron events, and dangerous functions suggests a limited attack surface and adherence to secure coding practices in these areas. Furthermore, the complete utilization of prepared statements for SQL queries and the absence of file operations and external HTTP requests are significant strengths.
However, a notable concern arises from the output escaping analysis, where only 50% of the total outputs are properly escaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, as unsanitized output can be injected with malicious scripts that are then rendered by the browser. The lack of any identified taint flows or non-existent vulnerability history, while positive, does not negate the risk posed by insufficient output escaping. The plugin's vulnerability history being entirely clear also suggests either excellent past security or potentially limited prior analysis or usage, making the current static analysis results particularly important.
In conclusion, while the plugin demonstrates good practices in areas like SQL handling and attack surface minimization, the 50% rate of unescaped output is a significant weakness that warrants attention. The absence of known vulnerabilities is encouraging, but this should not overshadow the identified potential for XSS. Further investigation into the specific outputs that are not properly escaped would be recommended to fully assess and mitigate this risk.
Key Concerns
- Half of output is not properly escaped
Simple URL Tracker – By Projekt15 Security Vulnerabilities
Simple URL Tracker – By Projekt15 Code Analysis
Output Escaping
Simple URL Tracker – By Projekt15 Attack Surface
WordPress Hooks 7
Maintenance & Trust
Simple URL Tracker – By Projekt15 Maintenance & Trust
Maintenance Signals
Community Trust
Simple URL Tracker – By Projekt15 Alternatives
Easy UTM Builder
easy-utm-builder
Easy to build trackable URLs with UTM parameters in Bulk (complete site or specific post type) for Google Analytics!
Festival ID Tracker
festival-id-tracker
Track unique festival ID URLs, view stats in dashboard widgets, and enable optional redirects while preserving IDs.
Product Feed for Google Shopping, Microsoft Advertising and 40+ Channels for WooCommerce Merchant
shopping-feed-for-google
Automate real-time product syncing to Google, Microsoft & Facebook from WooCommerce. Launch campaigns and track interactions with Google Analytics 4.
ShortLinks Pro – Affiliate Links, Link Shortening, Click Tracking & Marketing
shortlinkspro
Shorten, track, manage and share any URL using your own domain name!
PublishPress Shortlinks – Custom URLs for Posts and External Links – Share Previews for Draft Posts
tinypress
Create custom links for your posts. These links are brandable, trackable, and can have custom view permissions.
Simple URL Tracker – By Projekt15 Developer Profile
1 plugin · 10 total installs
How We Detect Simple URL Tracker – By Projekt15
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-url-tracker/admin/css/simple-track-admin.css/wp-content/plugins/simple-url-tracker/admin/js/simple-track-admin.js/wp-content/plugins/simple-url-tracker/admin/js/simple-track-admin.jsHTML / DOM Fingerprints
<div style='width:100%;'>?utm_source=&utm_medium=&utm_campaign=