Tracking Code Manager Security & Risk Analysis

wordpress.org/plugins/tracking-code-manager

A plugin to manage ALL of your tracking code and conversion pixels. Compatible with Facebook Ads, Google Adwords, WooCommerce, Easy Digital Downloads, …

90K active installs v2.5.0 PHP 5.6+ WP 3.6.0+ Updated Jun 16, 2025
deliver-content-by-admap-google-adsprofit-google-adtrack-google-adutm-management
96
A · Safe
CVEs total6
Unpatched0
Last CVEDec 23, 2024
Safety Verdict

Is Tracking Code Manager Safe to Use in 2026?

Generally Safe

Score 96/100

Tracking Code Manager has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

6 known CVEsLast CVE: Dec 23, 2024Updated 11mo ago
Risk Assessment

The "tracking-code-manager" plugin v2.5.0 exhibits a generally good security posture based on the static analysis. The plugin demonstrates strong adherence to secure coding practices, with 100% of SQL queries utilizing prepared statements and an impressive 98% of output being properly escaped. The limited attack surface, with no unprotected entry points found in AJAX handlers, REST API routes, or shortcodes, is also a positive indicator. The plugin also implements a healthy number of nonce and capability checks, further strengthening its defenses.

However, the vulnerability history presents a significant concern. With a total of six known CVEs, including one high-severity and five medium-severity vulnerabilities, this indicates a recurring pattern of security weaknesses that have required attention in the past. While there are no currently unpatched vulnerabilities, the types of past issues – Cross-site Scripting, Missing Authorization, and Uncontrolled Resource Consumption – are serious and could indicate underlying architectural flaws or a tendency to introduce such issues in development. The presence of an outdated bundled library (Select2 v4.0.13) is a minor but noteworthy concern, as older versions can harbor known vulnerabilities.

In conclusion, while the static analysis shows commendable coding practices and a controlled attack surface, the plugin's past vulnerability record necessitates caution. The plugin has strengths in its secure SQL handling and output escaping, but its history suggests a need for continued vigilance and thorough security reviews to prevent the recurrence of past issues. The outdated bundled library is a minor point of attention but doesn't detract significantly from the overall assessment given the other positive indicators.

Key Concerns

  • Bundled outdated library (Select2 v4.0.13)
  • History of 6 CVEs (1 high, 5 medium)
Vulnerabilities
6 published

Tracking Code Manager Security Vulnerabilities

CVEs by Year

2 CVEs in 2017
2017
4 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

High
1
Medium
5

6 total CVEs

CVE-2024-8721medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Tracking Code Manager <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 23, 2024 Patched in 2.4.0 (59d)
CVE-2024-6335medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Tracking Code Manager <= 2.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

Jun 3, 2024 Patched in 2.3.0 (100d)
CVE-2024-31347medium · 4.3Missing Authorization

Tracking Code Manager <= 2.1.0 - Missing Authorization via change_order()

Apr 5, 2024 Patched in 2.2.0 (7d)
CVE-2024-2579medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Tracking Code Manager <= 2.0.16 - Authenticated (Administrator+) Stored Cross-Site Scripting

Mar 18, 2024 Patched in 2.1.0 (5d)
WF-8f52fd57-abfe-48c4-a950-66d72a5a9627-tracking-code-managermedium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Tracking Code Manager < 1.11.5 - Cross-Site Scripting

May 10, 2017 Patched in 1.11.5 (2449d)
WF-99418bd5-041a-4210-9571-fee6842fb692-tracking-code-managerhigh · 7.5Uncontrolled Resource Consumption

Tracking Code Manager < 1.11.5 - Denial of Service

May 10, 2017 Patched in 1.11.5 (2449d)
Code Analysis
Analyzed Mar 16, 2026

Tracking Code Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
10 prepared
Unescaped Output
4
248 escaped
Nonce Checks
6
Capability Checks
4
File Operations
5
External Requests
1
Bundled Libraries
1

Bundled Libraries

Select24.0.13

SQL Query Safety

100% prepared10 total queries

Output Escaping

98% escaped252 total outputs
Attack Surface

Tracking Code Manager Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 1

authwp_ajax_TCMP_changeOrderincludes\classes\core\Manager.php:10

Shortcodes 2

[tcmp] includes\core.php:51
[tcm] includes\core.php:52
WordPress Hooks 17
actionadd_meta_boxesincludes\admin\metabox.php:74
actionsave_postincludes\admin\metabox.php:129
actionadmin_menuincludes\classes\ui\Tabs.php:10
filterplugin_action_linksincludes\classes\ui\Tabs.php:11
actionadmin_enqueue_scriptsincludes\classes\ui\Tabs.php:13
filtercron_schedulesincludes\classes\utils\Cron.php:11
actionwpincludes\classes\utils\Cron.php:12
actionwoocommerce_thankyouincludes\classes\utils\Ecommerce.php:10
actionedd_payment_receipt_after_tableincludes\classes\utils\Ecommerce.php:13
actionwpsc_transaction_result_cart_itemincludes\classes\utils\Ecommerce.php:14
actiontcmp_weekly_scheduled_eventsincludes\classes\utils\Tracking.php:20
filterwp_headincludes\core.php:3
actionwp_body_openincludes\core.php:23
actionwp_footerincludes\core.php:31
filteradmin_footerincludes\core.php:79
actionadmin_initincludes\install.php:16
filterjetpack_shortcodes_to_includetcmp_free_wp_kses_tags_attrs.php:154

Scheduled Events 2

tcmp_weekly_scheduled_events
tcmp_daily_scheduled_events
Maintenance & Trust

Tracking Code Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 16, 2025
PHP min version5.6
Downloads2.5M

Community Trust

Rating82/100
Number of ratings58
Active installs90K
Alternatives

Tracking Code Manager Alternatives

No alternatives data available yet.

Developer Profile

Tracking Code Manager Developer Profile

Data443 Risk Mitigation, Inc.

11 plugins · 203K total installs

67
trust score
Avg Security Score
83/100
Avg Patch Time
411 days
View full developer profile
Detection Fingerprints

How We Detect Tracking Code Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tracking-code-manager/assets/css/style.css/wp-content/plugins/tracking-code-manager/assets/css/manager.css/wp-content/plugins/tracking-code-manager/assets/deps/select2-4.0.13/select2.css/wp-content/plugins/tracking-code-manager/assets/deps/select2-4.0.13/select2.full.js/wp-content/plugins/tracking-code-manager/assets/deps/starrr/starrr.js/wp-content/plugins/tracking-code-manager/assets/js/library.js/wp-content/plugins/tracking-code-manager/assets/js/plugin.js/wp-content/plugins/tracking-code-manager/assets/js/editor.js+4 more
Script Paths
/wp-content/plugins/tracking-code-manager/assets/deps/select2-4.0.13/select2.full.js/wp-content/plugins/tracking-code-manager/assets/deps/starrr/starrr.js/wp-content/plugins/tracking-code-manager/assets/js/library.js/wp-content/plugins/tracking-code-manager/assets/js/plugin.js/wp-content/plugins/tracking-code-manager/assets/js/editor.js/wp-content/plugins/tracking-code-manager/assets/js/manager.js+2 more
Version Parameters
tracking-code-manager/assets/css/style.css?v=tracking-code-manager/assets/css/manager.css?v=tracking-code-manager/assets/deps/select2-4.0.13/select2.css?v=tracking-code-manager/assets/deps/select2-4.0.13/select2.full.js?v=tracking-code-manager/assets/deps/starrr/starrr.js?v=tracking-code-manager/assets/js/library.js?v=tracking-code-manager/assets/js/plugin.js?v=tracking-code-manager/assets/js/editor.js?v=tracking-code-manager/assets/js/manager.js?v=tracking-code-manager/assets/js/delete-confirm.js?v=tracking-code-manager/assets/js/ace/ace.js?v=tracking-code-manager/assets/css/font-awesome.min.css?v=

HTML / DOM Fingerprints

HTML Comments
<!-- Tracking Code Manager: Start --><!-- Tracking Code Manager: End -->
Data Attributes
data-tcmp-editor-id
JS Globals
TCMP__managerdelete_data
FAQ

Frequently Asked Questions about Tracking Code Manager