Tail DMP Security & Risk Analysis

wordpress.org/plugins/tailtarget

Using Tail DMP plugin you will be able to better understand your web site audience.

30 active installs v1.4 PHP + WP 3.0+ Updated Jan 22, 2019
analyticsdata-sciencedmpstatisticsstats
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Tail DMP Safe to Use in 2026?

Generally Safe

Score 85/100

Tail DMP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "tailtarget" v1.4 plugin exhibits a concerning security posture due to a significant number of unprotected entry points. While the plugin demonstrates good practices by using prepared statements for all SQL queries and not making external HTTP requests or file operations, the lack of authentication checks on its AJAX handlers creates a substantial attack surface. This means that any unauthenticated user could potentially interact with these handlers, leading to unintended consequences or exploitation if vulnerabilities are present within them. The taint analysis revealing unsanitized paths on all analyzed flows, although not resulting in critical or high severity issues in this scan, is a warning sign that user-supplied data is not being properly handled before being used in sensitive operations. The absence of any recorded vulnerability history is positive, but it does not negate the inherent risks posed by the identified code quality issues. In conclusion, the plugin has strengths in its database query handling and lack of external dependencies, but the unprotected AJAX endpoints and unsanitized data flows represent critical weaknesses that require immediate attention.

Key Concerns

  • Unprotected AJAX handlers
  • Taint flows with unsanitized paths
  • Lack of capability checks
  • Lack of nonce checks
  • Low percentage of properly escaped output
Vulnerabilities
None known

Tail DMP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Tail DMP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
15
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

6% escaped16 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
save_trackingid_data_callback (includes\Connect.php:15)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Tail DMP Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

authwp_ajax_save_trackingid_dataincludes\Connect.php:8
noprivwp_ajax_save_trackingid_dataincludes\Connect.php:9
authwp_ajax_get_trackingid_dataincludes\Connect.php:11
noprivwp_ajax_get_trackingid_dataincludes\Connect.php:12
WordPress Hooks 4
actionadmin_menuincludes\Layout.php:8
actionadmin_headincludes\Scripts.php:8
actionwp_headincludes\Scripts.php:9
actionplugins_loadedincludes\Translate.php:8
Maintenance & Trust

Tail DMP Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedJan 22, 2019
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs30
Developer Profile

Tail DMP Developer Profile

Tail - Target Audience & Insights Lab

1 plugin · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Tail DMP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tailtarget/public/js/angular.min.js/wp-content/plugins/tailtarget/public/js/app.admin.js/wp-content/plugins/tailtarget/public/css/style.admin.css
Script Paths
/wp-content/plugins/tailtarget/public/js/angular.min.js/wp-content/plugins/tailtarget/public/js/app.admin.js
Version Parameters
tailtarget/style.admin.css?ver=tailtarget/style.admin.css?ver=tailtarget/style.admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
tailtarget-admin-navtailtarget-admin-menu
HTML Comments
tailtarget.com plugin TailTarget DMP v end tailtarget.com tailtarget.com.br plugin Tail Target for Wordpress v end tailtarget.com.br
Data Attributes
data-ng-include
JS Globals
_tailtarget_ttqts
Shortcode Output
<div data-ng-include="template.url"></div>
FAQ

Frequently Asked Questions about Tail DMP