UTM Leads Tracker – XLPlugins Security & Risk Analysis
wordpress.org/plugins/utm-leads-tracker-liteDiscover which marketing campaigns are actually profitable and which are wasting your time & money. UTM Lead Tracker records the source of the lea …
Is UTM Leads Tracker – XLPlugins Safe to Use in 2026?
Generally Safe
Score 85/100UTM Leads Tracker – XLPlugins has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The overall security posture of utm-leads-tracker-lite v1.2.0 appears to be relatively good, with no known CVEs in its history and a complete absence of external HTTP requests, file operations, and SQL queries that do not use prepared statements. The static analysis also indicates a small attack surface with zero identified entry points, further contributing to a positive security outlook. However, there are significant concerns stemming from the code analysis. The low percentage of properly escaped output (35%) suggests a high likelihood of cross-site scripting (XSS) vulnerabilities, as data rendered to the user may not be sufficiently sanitized. Furthermore, the taint analysis revealing four flows with unsanitized paths, even if not classified as critical or high severity, indicates potential weaknesses in how user-supplied data is handled, which could lead to unexpected behavior or information disclosure if exploited in conjunction with other issues.
Key Concerns
- Low output escaping percentage (35%)
- Four taint flows with unsanitized paths
- No nonce checks
- No capability checks
UTM Leads Tracker – XLPlugins Security Vulnerabilities
UTM Leads Tracker – XLPlugins Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
UTM Leads Tracker – XLPlugins Attack Surface
WordPress Hooks 10
Maintenance & Trust
UTM Leads Tracker – XLPlugins Maintenance & Trust
Maintenance Signals
Community Trust
UTM Leads Tracker – XLPlugins Alternatives
UTM Event Tracker and Analytics, UTM Grabber
utm-event-tracker-and-analytics
Easily capture UTM parameters, track button and link clicks, and analyze campaigns to improve your marketing ROI in WordPress.
HandL UTM Grabber / Tracker
handl-utm-grabber
The WordPress attribution plugin used by over 200,000+ sites to capture UTMs, gclid, and source data in your forms, CRM, and revenue workflows.
Easy UTM Tracking with Contact Form 7
easy-utm-tracking-with-contact-form-7
Easy UTM Tracking with Contact Form 7 is a simple plugin that lets you track UTM parameters and referrer in your Contact Form 7 lead emails with just …
UTM Tracker for Contact Form 7
utm-tracker-for-contact-form-7
Track UTM parameters in Contact Form 7 submissions automatically and identify which campaigns generate real leads from your marketing traffic.
UTM Manager – UTM Tracking, Lead Attribution & Campaign Analytics
utm-manager
Track UTM parameters, capture leads with full attribution, and analyze marketing campaigns directly from your WordPress dashboard.
UTM Leads Tracker – XLPlugins Developer Profile
9 plugins · 117K total installs
How We Detect UTM Leads Tracker – XLPlugins
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/utm-leads-tracker-lite/admin/assets/css/xlutm-admin.cssutm-leads-tracker-lite/admin/assets/css/xlutm-admin.css?ver=