User Activity Tracker Security & Risk Analysis
wordpress.org/plugins/user-activity-trackerTrack and monitor user activity effortlessly with User Activity Tracker. Stay informed about actions taken on your site.
Is User Activity Tracker Safe to Use in 2026?
Generally Safe
Score 100/100User Activity Tracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "user-activity-tracker" plugin version 1.0.0 demonstrates a generally good security posture in its static analysis results. It exhibits zero unprotected entry points across AJAX handlers, REST API routes, shortcodes, and cron events. Furthermore, all identified output is properly escaped, and there are no critical or high severity taint flows. The plugin also includes nonce and capability checks, indicating an awareness of fundamental WordPress security practices. The absence of any recorded vulnerabilities, including CVEs, is a significant positive indicator. However, a notable concern is the complete lack of prepared statements for all six SQL queries. This represents a significant risk of SQL injection vulnerabilities, especially if any of the data used in these queries originates from user input, even if the static analysis didn't explicitly flag a taint flow in this specific version. While the vulnerability history is clean, the reliance on raw SQL queries without preparation is a severe oversight that could lead to exploitable weaknesses. The presence of file operations, while not inherently insecure, warrants careful review in conjunction with the SQL query issue to ensure no unintended interactions occur.
Key Concerns
- All SQL queries use raw SQL without prepared statements
User Activity Tracker Security Vulnerabilities
User Activity Tracker Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
User Activity Tracker Attack Surface
WordPress Hooks 8
Maintenance & Trust
User Activity Tracker Maintenance & Trust
Maintenance Signals
Community Trust
User Activity Tracker Alternatives
Easy UTM Builder
easy-utm-builder
Easy to build trackable URLs with UTM parameters in Bulk (complete site or specific post type) for Google Analytics!
LinkCentral – URL shortener, Custom Links & Affiliate Link Shortener with Link Tracking
linkcentral
The easiest URL shortener, short links manager, and link tracking plugin. Fast and optimised for better short links, redirects and affiliate links.
Simple URLs Legacy
simple-urls-legacy
Simple URLs Legacy is a fork of the plugin by Nathan Rice. A URL management system to create, manage, and track outbound links from your site.
PublishPress Shortlinks – Custom URLs for Posts and External Links – Share Previews for Draft Posts
tinypress
Create custom links for your posts. These links are brandable, trackable, and can have custom view permissions.
Dashly
dashly
Dashly combines all instruments for marketing automation, sales and communications. Supports WooCommerce 5.x, 6.x, 7.x (tested up to 7.1.0).
User Activity Tracker Developer Profile
3 plugins · 50 total installs
How We Detect User Activity Tracker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
data-uact-user-id