Smart Click Tracker Security & Risk Analysis
wordpress.org/plugins/smart-click-trackerTrack clicks on any element of your WordPress site and view detailed statistics with beautiful charts.
Is Smart Click Tracker Safe to Use in 2026?
Generally Safe
Score 100/100Smart Click Tracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'smart-click-tracker' plugin version 1.0.8 exhibits a mixed security posture. On the positive side, it shows strong adherence to best practices in several areas. Notably, there are no dangerous functions, file operations, or external HTTP requests, indicating a reduced risk of common attack vectors. The plugin also demonstrates a very high percentage of properly escaped outputs and prepared SQL statements, which are critical for preventing cross-site scripting (XSS) and SQL injection vulnerabilities, respectively. The absence of any known CVEs and a clean vulnerability history further contribute to a sense of stability.
However, a significant concern arises from the plugin's attack surface. With 8 AJAX handlers, a substantial 5 of them are not protected by authentication checks. While the taint analysis shows no critical or high severity unsanitized flows, the lack of authorization on these AJAX endpoints represents a direct gateway for unauthenticated users to potentially interact with plugin functionality in unintended ways. This could lead to privilege escalation, information disclosure, or denial-of-service attacks, depending on the specific actions performed by these unprotected handlers. The presence of nonce checks on only 5 of the 8 AJAX handlers further exacerbates this risk.
In conclusion, while 'smart-click-tracker' v1.0.8 has made commendable efforts in secure coding for SQL and output handling and boasts a clean vulnerability record, the large number of unprotected AJAX endpoints is a substantial security weakness. This oversight creates a significant risk of unauthorized access and manipulation of plugin features. Addressing these unprotected AJAX handlers should be the top priority for improving the plugin's security.
Key Concerns
- Unprotected AJAX handlers
- Missing nonce checks on AJAX
Smart Click Tracker Security Vulnerabilities
Smart Click Tracker Release Timeline
Smart Click Tracker Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Smart Click Tracker Attack Surface
AJAX Handlers 8
WordPress Hooks 10
Scheduled Events 1
Maintenance & Trust
Smart Click Tracker Maintenance & Trust
Maintenance Signals
Community Trust
Smart Click Tracker Alternatives
Epic Tracking – Click & Event Tracking for WordPress
epic-tracking
Click and event tracking for WordPress. Point, click, and track — no code, no tag managers, no third-party scripts.
Click Counter by Simple Tools
click-counter
Advanced click tracking for any CSS selector. Analytics, charts, goals, CSV export, visual picker, and more.
Track a click on Google Analytics
track-a-click-on-google-analytics
A simple shortcode to insert Google Analytics event tracking code on your links
GA Google Analytics – Connect Google Analytics to WordPress
ga-google-analytics
Adds Google Analytics tracking code to your WordPress site. Supports many tracking features.
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)
burst-statistics
Analytics you'll actually use. Privacy-friendly, zero config, and designed to be actionable. Get insights, not just raw data.
Smart Click Tracker Developer Profile
1 plugin · 100 total installs
How We Detect Smart Click Tracker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smart-click-tracker/admin/css/smart-click-tracker-admin.css/wp-content/plugins/smart-click-tracker/admin/js/smart-click-tracker-admin.js/wp-content/plugins/smart-click-tracker/admin/js/vendor/chart.min.js/wp-content/plugins/smart-click-tracker/admin/js/smart-click-tracker-admin.js/wp-content/plugins/smart-click-tracker/admin/js/vendor/chart.min.jssmart-click-tracker/admin/css/smart-click-tracker-admin.css?ver=smart-click-tracker/admin/js/smart-click-tracker-admin.js?ver=smart-click-tracker/admin/js/vendor/chart.min.js?ver=HTML / DOM Fingerprints
sct-tracker-itemsct-tracker-stats-wrappersct-add-new-tracker-formsct-analytics-filter<!-- Start Smart Click Tracker Dashboard --><!-- End Smart Click Tracker Dashboard --><!-- Start Add New Tracker Form --><!-- End Add New Tracker Form -->+2 moredata-tracker-iddata-noncedata-ajaxurlsmarcltrAdminSMARCLTR_Admin/wp-json/smart-click-tracker/v1/stats/wp-json/smart-click-tracker/v1/trackers/wp-json/smart-click-tracker/v1/settings[smart_click_tracker][sct_tracker][sct_analytics]