
Trackserver Security & Risk Analysis
wordpress.org/plugins/trackserverGPS Track Server for TrackMe, OruxMaps and others
Is Trackserver Safe to Use in 2026?
Generally Safe
Score 99/100Trackserver has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "trackserver" v5.1.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices such as a high percentage of prepared SQL statements and properly escaped output. The plugin also implements a significant number of nonce and capability checks, indicating an awareness of common WordPress security vulnerabilities.
However, there are notable concerns. The presence of one unprotected AJAX handler represents a significant attack vector. The taint analysis reveals four high-severity flows with unsanitized paths, suggesting potential vulnerabilities that could be exploited if these paths are reachable by user input. Furthermore, the plugin has a history of two medium-severity Cross-Site Scripting (XSS) vulnerabilities, with the most recent one being in 2025. While currently unpatched CVEs are zero, this historical pattern of XSS, coupled with unsanitized taint flows, indicates a recurrent risk of input validation and output sanitization issues.
In conclusion, while "trackserver" has strengths in its use of prepared statements and output escaping, the unprotected AJAX handler and high-severity unsanitized taint flows are critical points of concern. The past XSS vulnerabilities, even if addressed in this version, suggest a need for vigilant review of input handling and sanitization throughout the plugin's codebase.
Key Concerns
- Unprotected AJAX handler
- High severity unsanitized taint flows
- History of XSS vulnerabilities
Trackserver Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Trackserver <= 5.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Trackserver <= 5.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Trackserver Release Timeline
Trackserver Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Trackserver Attack Surface
AJAX Handlers 1
WordPress Hooks 24
Maintenance & Trust
Trackserver Maintenance & Trust
Maintenance Signals
Community Trust
Trackserver Alternatives
Spotmap
spotmap
Live GPS tracking for WordPress — display positions from SPOT, Garmin inReach, OsmAnd, Teltonika, and more on interactive maps.
Anonindo Heatmap Analytics
anonindo-heatmap-analytics
Record anonymous clicks, scroll depth, and hover activity, then review heatmap reports directly inside WordPress.
Geo Location
geo-location
Plugin that that collect geological info of visitors and display them in Bing Map and gives admin ability to block them.
Boat Tracker
boat-tracker
Track your boat around the globe with Iridium, AIS, InReach, PredictWind, SPOT, Startlink, etc, and display an interactive map on your website.
CrazyEgg Integrator for WordPress
crazyegg-integrator-for-wordpress
Add the Crazyegg code required to integrate it to your WordPress site
Trackserver Developer Profile
1 plugin · 400 total installs
How We Detect Trackserver
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/trackserver/css/trackserver-map.css/wp-content/plugins/trackserver/js/trackserver-map.js/wp-content/plugins/trackserver/css/trackserver-admin.css/wp-content/plugins/trackserver/js/trackserver-admin.js/wp-content/plugins/trackserver/lib/leaflet.js/wp-content/plugins/trackserver/lib/esri-leaflet.js/wp-content/plugins/trackserver/lib/trackserver.js/wp-content/plugins/trackserver/js/trackserver-map.js/wp-content/plugins/trackserver/lib/leaflet.js/wp-content/plugins/trackserver/lib/esri-leaflet.js/wp-content/plugins/trackserver/lib/trackserver.js/wp-content/plugins/trackserver/js/trackserver-admin.jstrackserver/css/trackserver-map.css?ver=trackserver/js/trackserver-map.js?ver=trackserver/css/trackserver-admin.css?ver=trackserver/js/trackserver-admin.js?ver=trackserver/lib/leaflet.js?ver=trackserver/lib/esri-leaflet.js?ver=trackserver/lib/trackserver.js?ver=HTML / DOM Fingerprints
trackserver-maptrackserver-admin-wraptrackserver-upload-form<!-- START TRACKSERVER TRACKLIST --><!-- END TRACKSERVER TRACKLIST --><!-- START TRACKSERVER UPLOAD FORM --><!-- END TRACKSERVER UPLOAD FORM -->+2 moredata-trackserver-map-iddata-trackserver-map-optionsdata-trackserver-track-idtrackserver_map_settingstrackserver_trackstrackserver_track_datatrackserver_tracklist/wp-json/trackserver/v1/track//wp-json/trackserver/v1/tracks/[trackserver_map][trackserver_tracklist][trackserver_upload_track]