UserTracker Security & Risk Analysis
wordpress.org/plugins/usertrackerThis plugin will let you track which pages your users who are logged in are viewing. It logs the username, ip, datetime, referer and url viewed.
Is UserTracker Safe to Use in 2026?
Generally Safe
Score 85/100UserTracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "usertracker" v1.2 plugin exhibits a concerning security posture despite a clean vulnerability history. While the attack surface appears minimal with zero identified entry points requiring authentication, the static analysis reveals significant code-level weaknesses. Notably, 100% of output operations are not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis highlights three flows with unsanitized paths, all flagged as high severity. This suggests potential vulnerabilities where user-supplied data is not adequately validated or sanitized before being processed or displayed.
The complete absence of known CVEs and a lack of historical vulnerabilities is a positive indicator, suggesting the developers may have a generally good approach to security in the past. However, this historical data does not mitigate the immediate risks identified in the current code analysis. The lack of capability checks and nonce checks on potential (though not explicitly identified) entry points further compounds these concerns. The plugin's strength lies in its apparent lack of direct external interaction and raw SQL queries, but this is overshadowed by critical unescaped outputs and unsanitized data flows.
Key Concerns
- High severity unsanitized taint flows
- 100% of output not properly escaped
- No nonce checks
- No capability checks
UserTracker Security Vulnerabilities
UserTracker Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
UserTracker Attack Surface
WordPress Hooks 3
Maintenance & Trust
UserTracker Maintenance & Trust
Maintenance Signals
Community Trust
UserTracker Alternatives
Post Views Counter
post-views-counter
Post Views Counter allows you to collect and display how many times a post, page, or other content has been viewed in a simple, fast and reliable way.
WebberZone Top 10 — Popular Posts
top-10
Track post views and page views, and display popular posts and trending content on your WordPress site.
Page View Count
page-views-count
Places an icon, all time views count and views today count at the bottom of posts, pages and custom post types on any WordPress website.
Light Views Counter – Fast, Scalable View Counter for High-Traffic Sites
light-views-counter
Lightweight and fast post view counter with smart tracking, built for high-traffic sites and large post databases.
YAHMAN Add-ons
yahman-add-ons
YAHMAN Add-ons has Multiple functions.
UserTracker Developer Profile
5 plugins · 200 total installs
How We Detect UserTracker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wraptablenavtablenav-pageswidefatname='m'id='userTracker-filter'WP_User_Search