
utm.codes Security & Risk Analysis
wordpress.org/plugins/utm-dot-codesA WordPress plugin that makes building analytics friendly links quick and easy.
Is utm.codes Safe to Use in 2026?
Generally Safe
Score 100/100utm.codes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "utm-dot-codes" plugin v1.9.1 exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates excellent adherence to secure coding practices, with no dangerous functions identified, all SQL queries utilizing prepared statements, and a remarkably high percentage (97%) of outputs being properly escaped. Furthermore, the absence of any file operations and a robust implementation of nonce and capability checks on its single AJAX handler indicate a well-thought-out approach to preventing common vulnerabilities. The vulnerability history is also clean, with no known CVEs, suggesting a history of responsible development and maintenance.
However, while the current analysis shows no critical or high-severity issues, there are subtle points to consider. The presence of four external HTTP requests, while not inherently a vulnerability, represents a potential attack vector if the external services are compromised or if the plugin does not handle responses securely. Although the single entry point is protected, a larger attack surface could introduce more complex challenges. The data indicates a proactive approach to security, but continuous vigilance regarding external dependencies and potential future vulnerabilities remains important.
Key Concerns
- External HTTP requests detected
utm.codes Security Vulnerabilities
utm.codes Release Timeline
utm.codes Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
utm.codes Attack Surface
AJAX Handlers 1
WordPress Hooks 21
Maintenance & Trust
utm.codes Maintenance & Trust
Maintenance Signals
Community Trust
utm.codes Alternatives
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)
google-analytics-for-wordpress
The best free Google Analytics plugin for WordPress. See how visitors find and use your website so you can grow your business with powerful analytics.
GTM4WP – A Google Tag Manager (GTM) plugin for WordPress
duracelltomi-google-tag-manager
Advanced tag management for WordPress with Google Tag Manager
WP Statistics – Simple, privacy-friendly Google Analytics alternative
wp-statistics
Get website traffic insights with GDPR/CCPA compliant, privacy-friendly analytics. Includes visitor data, stunning graphs, and no data sharing.
PixelYourSite – Your smart PIXEL (TAG) & API Manager
pixelyoursite
Add Meta Pixel with Conversion API, Google Analytics (GA4) + Consent Mode, Google Tag Manager, and Head & Footer scripts.
GA Google Analytics – Connect Google Analytics to WordPress
ga-google-analytics
Adds Google Analytics tracking code to your WordPress site. Supports many tracking features.
utm.codes Developer Profile
1 plugin · 400 total installs
How We Detect utm.codes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/utm-dot-codes/css/utmdotcodes-admin.css/wp-content/plugins/utm-dot-codes/js/utmdotcodes-admin.js/wp-content/plugins/utm-dot-codes/js/utmdotcodes-link-preview.jsutm.codes v1.9.1/wp-content/plugins/utm-dot-codes/js/utmdotcodes-admin.js/wp-content/plugins/utm-dot-codes/js/utmdotcodes-link-preview.jsutm-dot-codes/css/utmdotcodes-admin.css?ver=utm-dot-codes/js/utmdotcodes-admin.js?ver=utm-dot-codes/js/utmdotcodes-link-preview.js?ver=HTML / DOM Fingerprints
utmdotcodes-admin-cssutmdotcodes-link-preview-cssutmdotcodes-fieldutmdotcodes-field-required<!-- UTMDOTCODES: START SHORTCODE OUTPUT --><!-- UTMDOTCODES: END SHORTCODE OUTPUT --><!-- UTMDOTCODES: START META BOX --><!-- UTMDOTCODES: END META BOX -->data-copy-textdata-copy-titledata-copy-success-titledata-copy-error-titledata-utmdc-ajax-urldata-utmdc-nonce+2 moreutm_dot_codes_admin_paramsutm_dot_codes_link_preview_params/wp-json/utmdc/v1/check_url_response<div class="utmdotcodes-shortcode-wrapper"><div class="utmdotcodes-shortcode-link"><a href="