Track-A-Bot Security & Risk Analysis

wordpress.org/plugins/track-a-bot

Logs and analyzes SEO bots, AI crawlers, and other automated traffic.

30 active installs v1.0.3 PHP 7.0+ WP 5.0+ Updated Mar 3, 2026
ai-activityanalyticsbot-trackingcrawler-detectionseo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Track-A-Bot Safe to Use in 2026?

Generally Safe

Score 100/100

Track-A-Bot has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "track-a-bot" plugin v1.0.3 demonstrates a generally strong security posture based on the provided static analysis and vulnerability history. The plugin exhibits good practices by implementing nonce checks and capability checks, and a high percentage of its SQL queries utilize prepared statements, significantly mitigating SQL injection risks. Furthermore, the vast majority of its output is properly escaped, reducing the likelihood of cross-site scripting (XSS) vulnerabilities. The absence of file operations and external HTTP requests also limits the plugin's attack surface in these common areas.

Key Concerns

  • One cron event found
  • 11% of SQL queries not prepared
  • 11% of outputs not properly escaped
Vulnerabilities
None known

Track-A-Bot Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Track-A-Bot Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
14 prepared
Unescaped Output
8
67 escaped
Nonce Checks
1
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

93% prepared15 total queries

Output Escaping

89% escaped75 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
trackabot_log_page (track-a-bot-functions.php:515)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Track-A-Bot Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionadmin_inittrack-a-bot.php:33
actionadmin_menutrack-a-bot.php:39
actionadmin_enqueue_scriptstrack-a-bot.php:42
actionadmin_menutrack-a-bot.php:45
actionadmin_inittrack-a-bot.php:48
actionadmin_inittrack-a-bot.php:51
actiontemplate_redirecttrack-a-bot.php:54
actionadmin_enqueue_scriptstrack-a-bot.php:57
actionadmin_noticestrack-a-bot.php:60
filtersubmenu_filetrack-a-bot.php:63
actionplugins_loadedtrack-a-bot.php:66
filtercron_schedulestrack-a-bot.php:69
actiontrackabot_cron_enrich_hostnamestrack-a-bot.php:75

Scheduled Events 1

trackabot_cron_enrich_hostnames
Maintenance & Trust

Track-A-Bot Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 3, 2026
PHP min version7.0
Downloads321

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Track-A-Bot Developer Profile

Track-A-Bot

1 plugin · 30 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Track-A-Bot

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/track-a-bot/assets/css/trackabot-admin.css/wp-content/plugins/track-a-bot/assets/js/trackabot-admin.js
Script Paths
/wp-content/plugins/track-a-bot/assets/js/trackabot-admin.js
Version Parameters
trackabot-admin.css?ver=trackabot-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
trackabot-settings
HTML Comments
<!-- Track-A-Bot: A physical robots.txt file exists at the site root. WordPress will serve that file directly, so Track-A-Bot robots rules (robots_txt filter) will not apply. Delete/rename the physical robots.txt if you want WordPress to generate robots.txt dynamically. -->
Data Attributes
data-page-titledata-page-hook
FAQ

Frequently Asked Questions about Track-A-Bot