User Activity Tracking and Log Security & Risk Analysis
wordpress.org/plugins/user-activity-tracking-and-logTrack time and monitor user activity & history on your website, LMS online learning system, membership or WooCommerce site.
Is User Activity Tracking and Log Safe to Use in 2026?
Generally Safe
Score 99/100User Activity Tracking and Log has a strong security track record. Known vulnerabilities have been patched promptly.
The "user-activity-tracking-and-log" plugin v4.2.1 presents a mixed security posture. While the majority of SQL queries are prepared and output escaping is generally well-handled, there are significant concerns regarding the attack surface. A high number of AJAX handlers, specifically 8 out of 9, lack authentication checks, creating a large entry point for potential abuse by unauthenticated users. Furthermore, the taint analysis revealed 5 high-severity flows with unsanitized paths, indicating potential vulnerabilities where user-supplied input could lead to unintended consequences, such as arbitrary code execution or data manipulation. The plugin's vulnerability history, while currently showing no unpatched CVEs, includes 2 past medium-severity vulnerabilities, notably Authentication Bypass by Spoofing and Cross-Site Request Forgery (CSRF). This history, coupled with the identified unsanitized paths and unprotected AJAX endpoints, suggests a recurring pattern of weaknesses in input validation and authentication mechanisms. The presence of the `unserialize` function also raises concerns, as it can be a vector for remote code execution if not used with extreme caution on untrusted data. The use of an outdated bundled library (Select2 v3.4.8) adds another layer of potential risk. Overall, while some security best practices are followed, the substantial unprotected attack surface and critical taint flows require immediate attention.
Key Concerns
- AJAX handlers without auth checks
- High severity taint flows
- Dangerous function: unserialize
- Bundled outdated library: Select2 v3.4.8
- Past medium CVEs (2 total)
User Activity Tracking and Log Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
User Activity Tracking and Log <= 4.1.3 - IP Spoofing
User Activity Tracking and Log <= 4.0.8 - Cross-Site Request Forgery
User Activity Tracking and Log Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
User Activity Tracking and Log Attack Surface
AJAX Handlers 9
Shortcodes 1
WordPress Hooks 50
Maintenance & Trust
User Activity Tracking and Log Maintenance & Trust
Maintenance Signals
Community Trust
User Activity Tracking and Log Alternatives
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)
burst-statistics
Analytics you'll actually use. Privacy-friendly, zero config, and designed to be actionable. Get insights, not just raw data.
Statify
statify
Visitor statistics for WordPress with focus on data protection, transparency and clarity. Perfect as a widget in your WordPress Dashboard.
Koko Analytics – Privacy Friendly Statistics for WordPress
koko-analytics
Koko Analytics is a privacy-friendly statistics plugin for WordPress that is an easy to use alternative to Google Analytics.
Connect Matomo – Analytics Dashboard for WordPress
wp-piwik
Adds Matomo (former Piwik) statistics to your WordPress dashboard and is also able to add the Matomo Tracking Code to your blog.
Visitor Traffic Real Time Statistics
visitors-traffic-real-time-statistics
This plugin will help you to track your visitors, browsers, operating systems, visits and much more in one dashboard page.
User Activity Tracking and Log Developer Profile
6 plugins · 308K total installs
How We Detect User Activity Tracking and Log
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/user-activity-tracking-and-log/assets/css/moove-activity-user-profile.css/wp-content/plugins/user-activity-tracking-and-log/assets/js/moove-activity-user-profile.js/wp-content/plugins/user-activity-tracking-and-log/assets/js/moove-activity-datatable.js/wp-content/plugins/user-activity-tracking-and-log/assets/js/moove-activity-options.js/wp-content/plugins/user-activity-tracking-and-log/assets/js/moove-activity-script.js/wp-content/plugins/user-activity-tracking-and-log/assets/js/moove-activity-user-login-log.js/wp-content/plugins/user-activity-tracking-and-log/assets/js/moove-activity-user-profile.js/wp-content/plugins/user-activity-tracking-and-log/assets/js/moove-activity-datatable.js/wp-content/plugins/user-activity-tracking-and-log/assets/js/moove-activity-options.js/wp-content/plugins/user-activity-tracking-and-log/assets/js/moove-activity-script.js/wp-content/plugins/user-activity-tracking-and-log/assets/js/moove-activity-user-login-log.jsuser-activity-tracking-and-log/assets/css/moove-activity-user-profile.css?ver=user-activity-tracking-and-log/assets/js/moove-activity-user-profile.js?ver=user-activity-tracking-and-log/assets/js/moove-activity-datatable.js?ver=user-activity-tracking-and-log/assets/js/moove-activity-options.js?ver=user-activity-tracking-and-log/assets/js/moove-activity-script.js?ver=user-activity-tracking-and-log/assets/js/moove-activity-user-login-log.js?ver=HTML / DOM Fingerprints
moove-uat-star-ratingmoove-activity-settingsmoove-activity-user-login-log-tablemoove-activity-post-activity-table<!-- User Activity Tracking and Log --><!-- plugin: user-activity-tracking-and-log --><!-- This plugin gives you the ability to track user activity on your website. --><!-- Author: Moove Agency -->+3 moredata-plugin-pathdata-plugin-urimoove_activity_ajax_object