Source Medium Tracker for Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/source-medium-tracker-for-contact-form-7Tracks the source and medium of visitors and includes this information in Contact Form 7 submissions.
Is Source Medium Tracker for Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 100/100Source Medium Tracker for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "source-medium-tracker-for-contact-form-7" plugin version 2.5 exhibits a generally strong security posture based on the provided static analysis. The plugin effectively utilizes prepared statements for all its SQL queries, demonstrates robust output escaping with 92% of outputs properly handled, and implements nonce checks and capability checks where appropriate. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its secure design. Crucially, the taint analysis found no critical or high severity flows with unsanitized paths, indicating no immediate risks of code injection or data manipulation through untrusted input. The plugin also has no recorded vulnerability history, which is a positive indicator of its ongoing security maintenance.
While the static analysis reveals excellent adherence to secure coding practices, the limited attack surface (one AJAX handler, zero REST API routes, shortcodes, or cron events) makes it difficult to draw sweeping conclusions about its overall security in all potential scenarios. However, the single AJAX handler appears to be protected by the identified nonce and capability checks, mitigating common web application vulnerabilities. The plugin's strengths lie in its careful handling of database operations and output, and the absence of historical vulnerabilities. The primary weakness, if any, would be the limited scope of the analysis provided, rather than any inherent flaws identified in the code itself.
Source Medium Tracker for Contact Form 7 Security Vulnerabilities
Source Medium Tracker for Contact Form 7 Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Source Medium Tracker for Contact Form 7 Attack Surface
AJAX Handlers 1
WordPress Hooks 15
Maintenance & Trust
Source Medium Tracker for Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
Source Medium Tracker for Contact Form 7 Alternatives
Easy UTM Tracking with Contact Form 7
easy-utm-tracking-with-contact-form-7
Easy UTM Tracking with Contact Form 7 is a simple plugin that lets you track UTM parameters and referrer in your Contact Form 7 lead emails with just …
UTM Tracker for Contact Form 7
utm-tracker-for-contact-form-7
Track UTM parameters in Contact Form 7 submissions automatically and identify which campaigns generate real leads from your marketing traffic.
Kawuda UTM source tracker
kawuda-utm-source-tracker
Kawuda is a simple UTM source tracking system. No need depend on 3rd party. You can use this as your own anatlatic system
HandL UTM Grabber / Tracker
handl-utm-grabber
The WordPress attribution plugin used by over 200,000+ sites to capture UTMs, gclid, and source data in your forms, CRM, and revenue workflows.
Lead info with country for Contact Form 7
contact-form-7-lead-info-with-country
Lead info with country for Contact Form 7 helps to track users that fill in forms.
Source Medium Tracker for Contact Form 7 Developer Profile
2 plugins · 100 total installs
How We Detect Source Medium Tracker for Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/source-medium-tracker-for-contact-form-7/js/smt-cf7-tracking.jssource-medium-tracker-for-contact-form-7/js/smt-cf7-tracking.js?ver=HTML / DOM Fingerprints
smt-cf7-kpissmt-cf7-kpismt-cf7-comparesmt-cf7-compare-iconsmt-cf7-compare-textname="source"name="medium"<input type="hidden" name="source" value="Unknown" /><input type="hidden" name="medium" value="Unknown" />