Tracker.ly Security & Risk Analysis
wordpress.org/plugins/trackerlyAdds WordPress compatibility for the Tracker.ly link redirection service. All your marketing links for all domains, managed in one place.
Is Tracker.ly Safe to Use in 2026?
Generally Safe
Score 85/100Tracker.ly has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The trackerly v1.1 plugin exhibits a mixed security posture, with several positive indicators but also significant concerns. On the positive side, the plugin demonstrates a lack of known vulnerabilities historically, with zero CVEs recorded. It also correctly uses prepared statements for all SQL queries, avoids external HTTP requests, and includes nonce and capability checks, suggesting some level of awareness for secure coding practices. However, the static analysis reveals a critical weakness: 100% of its output is unescaped. This is a major concern as it opens the door to cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into pages viewed by users. Furthermore, while the plugin has only a limited number of file operations and no dangerous functions identified, the presence of unsanitized paths in taint analysis, even without critical or high severity flows, warrants attention as it could potentially be exploited in conjunction with other issues. The absence of any attack surface in terms of AJAX, REST API, shortcodes, or cron events is a strength, but the unescaped output remains the most pressing risk.
Key Concerns
- All output is unescaped
- Taint flows with unsanitized paths
Tracker.ly Security Vulnerabilities
Tracker.ly Code Analysis
Output Escaping
Data Flow Analysis
Tracker.ly Attack Surface
WordPress Hooks 4
Maintenance & Trust
Tracker.ly Maintenance & Trust
Maintenance Signals
Community Trust
Tracker.ly Alternatives
Redirection
redirection
Manage 301 redirects, track 404 errors, and improve your site. No knowledge of Apache or Nginx required.
301 Redirects – Redirect Manager
eps-301-redirects
Manage 301 & 302 redirects. Simple redirection & redirects validation. Includes redirect stats & 404 error log.
All 404 Redirect to Homepage
all-404-redirect-to-homepage
Using this plugin, you can fix all 404 error links by redirecting them to homepage using the SEO 301 redirection. Improve your SEO rank & pages speed
404 to 301 – Redirect, Log and Notify 404 Errors
404-to-301
Automatically redirect, log and notify all 404 page errors to any page using 301 redirect for SEO. No more 404 Errors in WebMaster tool.
Redirection
redirect-redirection
Redirection
Tracker.ly Developer Profile
1 plugin · 30 total installs
How We Detect Tracker.ly
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/trackerly/css/trackerly-admin.css/wp-content/plugins/trackerly/js/trackerly-admin.jstrackerly/css/trackerly-admin.css?ver=trackerly/js/trackerly-admin.js?ver=HTML / DOM Fingerprints
trackerly-confid="trackerly-conf"name="install_folder"id="install_folder"