UTM Manager – UTM Tracking, Lead Attribution & Campaign Analytics Security & Risk Analysis

wordpress.org/plugins/utm-manager

Track UTM parameters, capture leads with full attribution, and analyze marketing campaigns directly from your WordPress dashboard.

100 active installs v1.3.0 PHP 7.4+ WP 5.0+ Updated Jan 27, 2026
analyticsinsightsleadsutmutm-tracker
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is UTM Manager – UTM Tracking, Lead Attribution & Campaign Analytics Safe to Use in 2026?

Generally Safe

Score 100/100

UTM Manager – UTM Tracking, Lead Attribution & Campaign Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "utm-manager" v1.3.0 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs, critical taint flows, raw SQL queries, and a complete lack of unescaped output are significant strengths. All identified entry points, including the single AJAX handler and cron event, appear to have appropriate authentication and capability checks, further bolstering its security. The plugin also demonstrates good practice by utilizing nonce checks and proper output escaping for all identified outputs.

However, there are minor areas for potential improvement. While the attack surface is small (1 entry point), the fact that it's not explicitly stated if the AJAX handler is protected by a capability check warrants a slight caution. The presence of file operations, though not inherently risky, can sometimes introduce attack vectors if not handled with extreme care, especially if user-supplied data influences file paths. The plugin also has a moderate number of nonce checks (7) and capability checks (4) which, while good, could indicate a more complex internal logic where potential vulnerabilities might be masked if not thoroughly reviewed. Overall, the plugin appears to be developed with security in mind, but continuous vigilance and potentially more granular permission checks on its entry points would further solidify its security.

Key Concerns

  • AJAX handler without explicit auth check detail
  • Presence of file operations
Vulnerabilities
None known

UTM Manager – UTM Tracking, Lead Attribution & Campaign Analytics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

UTM Manager – UTM Tracking, Lead Attribution & Campaign Analytics Release Timeline

v1.3.0Current
v1.2.6
v1.2.5
v1.2.4
v1.2.3
v1.2.2
v1.2.1
v1.2.0
v1.1.0
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

UTM Manager – UTM Tracking, Lead Attribution & Campaign Analytics Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
68 escaped
Nonce Checks
7
Capability Checks
4
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped68 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

4 flows
handle_settings (includes\Controllers\Actions.php:30)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

UTM Manager – UTM Tracking, Lead Attribution & Campaign Analytics Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_utmm_export_csvincludes\Controllers\Actions.php:20
WordPress Hooks 15
actionadmin_menuincludes\Admin\Admin.php:23
actionadmin_menuincludes\Admin\Admin.php:24
actionadmin_menuincludes\Admin\Admin.php:25
filterset-screen-optionincludes\Admin\Admin.php:26
actionload-toplevel_page_utm-managerincludes\Admin\Admin.php:27
actionadmin_enqueue_scriptsincludes\Admin\Admin.php:28
actionadmin_post_utmm_update_settingsincludes\Controllers\Actions.php:19
actionadmin_post_utmm_download_exported_csvincludes\Controllers\Actions.php:21
actioninitincludes\Installer.php:31
filtercron_schedulesincludes\Installer.php:32
actionutmm_migrate_dataincludes\Installer.php:33
actioninitincludes\Leads.php:21
actionadmin_noticesincludes\Plugin.php:116
actioninitincludes\Plugin.php:117
actioninitincludes\PostTypes.php:23

Scheduled Events 1

utmm_migrate_data
Maintenance & Trust

UTM Manager – UTM Tracking, Lead Attribution & Campaign Analytics Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 27, 2026
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

UTM Manager – UTM Tracking, Lead Attribution & Campaign Analytics Developer Profile

UrlDev

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect UTM Manager – UTM Tracking, Lead Attribution & Campaign Analytics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/utm-manager/assets/css/admin.css/wp-content/plugins/utm-manager/assets/js/admin.js
Script Paths
/wp-content/plugins/utm-manager/assets/js/admin.js
Version Parameters
utm-manager/assets/css/admin.css?ver=utm-manager/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
utmm-datatableutmm-leads-filter-wraputmm-leads-filter-btnutmm-lead-actions-wraputmm-settings-wraputmm-tools-wraputmm-view-lead-wrap
Data Attributes
data-utm-leads-per-pagedata-roledata-field
JS Globals
UTMM_VERSIONUTMM_ASSETS_URL
FAQ

Frequently Asked Questions about UTM Manager – UTM Tracking, Lead Attribution & Campaign Analytics