User Activity Tracker Security & Risk Analysis

wordpress.org/plugins/user-activity-tracker

Track and monitor user activity effortlessly with User Activity Tracker. Stay informed about actions taken on your site.

10 active installs v1.0.0 PHP 7.4+ WP 5.6+ Updated Jun 12, 2025
customloggingtrackinguser-activity
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is User Activity Tracker Safe to Use in 2026?

Generally Safe

Score 100/100

User Activity Tracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The "user-activity-tracker" plugin version 1.0.0 demonstrates a generally good security posture in its static analysis results. It exhibits zero unprotected entry points across AJAX handlers, REST API routes, shortcodes, and cron events. Furthermore, all identified output is properly escaped, and there are no critical or high severity taint flows. The plugin also includes nonce and capability checks, indicating an awareness of fundamental WordPress security practices. The absence of any recorded vulnerabilities, including CVEs, is a significant positive indicator. However, a notable concern is the complete lack of prepared statements for all six SQL queries. This represents a significant risk of SQL injection vulnerabilities, especially if any of the data used in these queries originates from user input, even if the static analysis didn't explicitly flag a taint flow in this specific version. While the vulnerability history is clean, the reliance on raw SQL queries without preparation is a severe oversight that could lead to exploitable weaknesses. The presence of file operations, while not inherently insecure, warrants careful review in conjunction with the SQL query issue to ensure no unintended interactions occur.

Key Concerns

  • All SQL queries use raw SQL without prepared statements
Vulnerabilities
None known

User Activity Tracker Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

User Activity Tracker Code Analysis

Dangerous Functions
0
Raw SQL Queries
6
0 prepared
Unescaped Output
0
27 escaped
Nonce Checks
2
Capability Checks
2
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared6 total queries

Output Escaping

100% escaped27 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
uact_settings_dashboard (includes\Admin\class-admin-settings.php:78)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

User Activity Tracker Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_menuincludes\Admin\class-admin-settings.php:5
actionadmin_initincludes\Admin\class-admin-settings.php:6
actionwp_loginincludes\utilities\class-logger.php:13
actionwp_insert_commentincludes\utilities\class-logger.php:14
actionedit_postincludes\utilities\class-logger.php:15
actionwp_insert_postincludes\utilities\class-logger.php:16
actionwp_trash_postincludes\utilities\class-logger.php:17
actionuntrash_postincludes\utilities\class-logger.php:18
Maintenance & Trust

User Activity Tracker Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJun 12, 2025
PHP min version7.4
Downloads320

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

User Activity Tracker Developer Profile

whizPlugins

3 plugins · 50 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect User Activity Tracker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
data-uact-user-id
FAQ

Frequently Asked Questions about User Activity Tracker