
track-incoming-referrer Security & Risk Analysis
wordpress.org/plugins/track-incoming-referrerTrack incoming referrer and write it to any hidden form field with the identifier "referrer".
Is track-incoming-referrer Safe to Use in 2026?
Generally Safe
Score 100/100track-incoming-referrer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'track-incoming-referrer' plugin v1.0.0 exhibits a generally positive security posture due to the absence of known vulnerabilities and a lack of dangerous functions or file operations. The code analysis indicates no SQL injection risks as all queries utilize prepared statements. However, a significant concern arises from the complete lack of output escaping. With two output points identified and zero properly escaped, any data displayed to users, especially if it originates from external sources like referrers, could be vulnerable to cross-site scripting (XSS) attacks. Furthermore, the absence of nonce checks and capability checks, while not directly identified as a risk in this analysis given the limited attack surface, represents a missed opportunity for robust security hardening. The plugin's vulnerability history is clean, suggesting good development practices or limited exposure. Overall, while the plugin is free from critical known issues, the unescaped output poses a notable risk that requires immediate attention.
Key Concerns
- 0% of outputs properly escaped
- No nonce checks implemented
- No capability checks implemented
track-incoming-referrer Security Vulnerabilities
track-incoming-referrer Code Analysis
Output Escaping
track-incoming-referrer Attack Surface
WordPress Hooks 3
Maintenance & Trust
track-incoming-referrer Maintenance & Trust
Maintenance Signals
Community Trust
track-incoming-referrer Alternatives
Remove noreferrer
remove-noreferrer
"Remove noreferrer" automatically removes rel="noreferrer" attribute from links on your website on-the-fly.
AffiliateWP – Affiliate Info
affiliatewp-affiliate-info
Display information based on the affiliate's referral URL.
Analytics Spam Blocker
analytics-spam-blocker
Prevent referrer spam from affecting your website analytics. Easily create a blocklist and receive new domains weekly to stay on top of the issue.
Referrer Input for Contact Form 7
referrer-input-for-contact-form-7
Contact Form 7 Addon that creates a cache-resistant input that contains the URL of the page the user visited before the contact form page.
CP Referrer and Conversion Tracking
cp-referrer-and-conversions-tracking
CP Referrer and Conversion Tracking registers how the website visitors reached the website, identifying the referral website. Also track conversions.
track-incoming-referrer Developer Profile
1 plugin · 10 total installs
How We Detect track-incoming-referrer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/track-incoming-referrer/track-incoming-referrer.phpHTML / DOM Fingerprints
getCookiewriteCookiegetParameterByNamesetReferrerOnSubmit