User Login Tracker Security & Risk Analysis
wordpress.org/plugins/user-login-trackerMonitor user login activity with advanced analytics, visual charts, and comprehensive tracking dashboard.
Is User Login Tracker Safe to Use in 2026?
Generally Safe
Score 100/100User Login Tracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The user-login-tracker v2.0.1 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any known CVEs, critical or high-severity taint flows, and a good percentage of SQL queries using prepared statements indicate that the developers have followed secure coding practices. Furthermore, the plugin has a controlled attack surface with all identified entry points (AJAX handlers) seemingly protected by authentication checks, and no REST API routes or shortcodes present potential vulnerabilities. The presence of nonce and capability checks further bolsters its security.
While the plugin appears robust, there are minor areas for attention. The 15% of SQL queries not using prepared statements represent a potential, albeit small, risk of SQL injection if the input is not sufficiently sanitized elsewhere. Similarly, the 16% of outputs that are not properly escaped could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is reflected directly in the output. The single file operation also warrants a closer look to ensure it doesn't introduce any file manipulation vulnerabilities. Overall, the plugin's history of no vulnerabilities is a very positive sign, suggesting a mature and secure development process. The low number of potential risks identified in the code analysis, combined with the lack of past vulnerabilities, suggests a low to moderate risk profile.
Key Concerns
- SQL queries not using prepared statements (20%)
- Outputs not properly escaped (16%)
User Login Tracker Security Vulnerabilities
User Login Tracker Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
User Login Tracker Attack Surface
AJAX Handlers 3
WordPress Hooks 18
Scheduled Events 1
Maintenance & Trust
User Login Tracker Maintenance & Trust
Maintenance Signals
Community Trust
User Login Tracker Alternatives
Last Login Display
last-login-display
Show the last login date and time of users in the admin dashboard.
Last Login Tracker & Redirect URL
last-login-tracker-redirect-url
Tracks user last login and allows redirection of 404 pages to the homepage.
Login Activity Tracker
login-activity-tracker
Tracks user login attempts and displays login logs with styled pagination for admins and users.
When Last Login
when-last-login
Show a users last login date by creating a sortable column in your WordPress users list.
Loggedin – Limit Concurrent Sessions
loggedin
Lightweight plugin that limits an account to a specific number of concurrent logins.
User Login Tracker Developer Profile
1 plugin · 30 total installs
How We Detect User Login Tracker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/user-login-tracker/css/ultk-admin.css/wp-content/plugins/user-login-tracker/js/ultk-admin.js/wp-content/plugins/user-login-tracker/css/ultk-dashboard-widget.css/wp-content/plugins/user-login-tracker/js/ultk-dashboard-widget.js/wp-content/plugins/user-login-tracker/js/ultk-admin.js/wp-content/plugins/user-login-tracker/js/ultk-dashboard-widget.jsuser-login-tracker/css/ultk-admin.css?ver=user-login-tracker/js/ultk-admin.js?ver=user-login-tracker/css/ultk-dashboard-widget.css?ver=user-login-tracker/js/ultk-dashboard-widget.js?ver=HTML / DOM Fingerprints
ultk-login-history-tableultk-export-buttonultk-dashboard-widget-contentultk-user-login-history-modal<!-- User Login Tracker Admin Settings --><!-- User Login Tracker Dashboard Widget --><!-- User Login Tracker User History Modal -->data-user-iddata-noncedata-actionultk_ajax_object/wp-json/ultk/v1/export/wp-json/ultk/v1/user-history