
User Page Logs Security & Risk Analysis
wordpress.org/plugins/user-page-logsLogging and Tracking your User visit History
Is User Page Logs Safe to Use in 2026?
Generally Safe
Score 85/100User Page Logs has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "user-page-logs" v1.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any known CVEs in its history and the lack of critical or high-severity issues in taint analysis are positive indicators. Furthermore, the plugin has a very limited attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events. This significantly reduces the potential for external exploitation.
However, there are areas for improvement. The code signals reveal that only 63% of output is properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if malicious input is not handled correctly. While the SQL queries are mostly prepared (69%), the remaining percentage could still be a risk. Additionally, the lack of capability checks (0) means that functionality might not be adequately restricted to authorized users, although the limited attack surface mitigates this risk in this specific version. The presence of file operations (1) without context is a minor concern, as such operations can be exploited if not secured.
Overall, the plugin is relatively secure due to its small attack surface and lack of historical vulnerabilities. However, the unescaped outputs and potential for insecure file operations warrant attention. Developers should prioritize addressing the output escaping issues to prevent potential XSS flaws. Improving the preparedness of all SQL queries and implementing capability checks for any sensitive operations would further enhance the plugin's security.
Key Concerns
- Low output escaping rate (63%)
- SQL queries not using prepared statements (31%)
- No capability checks found
- Presence of file operations (1)
User Page Logs Security Vulnerabilities
User Page Logs Release Timeline
User Page Logs Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
User Page Logs Attack Surface
WordPress Hooks 5
Maintenance & Trust
User Page Logs Maintenance & Trust
Maintenance Signals
Community Trust
User Page Logs Alternatives
IP2GA
ip2ga
Track all user activities on the site, including page views, button clicks, and form submissions, and send them to Google Analytics 4.
JENTIS – simply better data
jentis
JENTIS plugin is implementing the JENTIS Tracking Code to the web page and provides the Signals to JENTIS Runtime Environment.
Scripts + Pixels DataLayer Manager
scripts-and-pixels-datalayer-manager
Automatically detects WordPress context and injects dataLayer variables for analytics tools (GA4/GTM). No coding required.
GA Google Analytics – Connect Google Analytics to WordPress
ga-google-analytics
Adds Google Analytics tracking code to your WordPress site. Supports many tracking features.
Metricool
metricool
Metricool is the first tool designed to measure #Blog impact and #SocialMedia activity.
User Page Logs Developer Profile
1 plugin · 10 total installs
How We Detect User Page Logs
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/user-page-logs/style.cssuser-page-logs/style.css?ver=HTML / DOM Fingerprints
uplupl_headerupl_info_headupl_info_content