UTM Tracker for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/utm-tracker-for-contact-form-7

Track UTM parameters in Contact Form 7 submissions automatically and identify which campaigns generate real leads from your marketing traffic.

200 active installs v1.5 PHP 7.2+ WP 5.6+ Updated Mar 13, 2026
cf7-utm-trackingcontact-form-7marketing-attributionutm-parametersutm-tracking
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is UTM Tracker for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 100/100

UTM Tracker for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The plugin 'utm-tracker-for-contact-form-7' v1.5 demonstrates a strong security posture based on the provided static analysis. The absence of any detected dangerous functions, file operations, or external HTTP requests is commendable. Furthermore, all SQL queries utilize prepared statements, and all output is properly escaped, indicating good practices in preventing common web vulnerabilities like SQL injection and cross-site scripting. The plugin also shows a lack of common attack vectors such as AJAX handlers, REST API routes, and shortcodes that are often targets for exploitation. The vulnerability history is also completely clear, with no recorded CVEs, which suggests a well-maintained and secure plugin over time.

While the static analysis indicates a very secure codebase, the sole capability check present is a weakness. Plugins typically require capability checks for various administrative or user-facing actions to ensure proper authorization. The absence of other checks, coupled with zero unprotected entry points, is highly unusual and might suggest either an extremely simple plugin with no user interaction beyond Contact Form 7's own mechanisms, or a potential oversight in the analysis itself if the plugin does indeed have functionalities that require specific permissions. The taint analysis showing zero flows is also excellent, implying no sensitive data is being mishandled. Overall, the plugin appears robustly secured against known web attack vectors, with the primary area for potential concern being the limited evident authorization checks.

Key Concerns

  • Only one capability check detected
Vulnerabilities
None known

UTM Tracker for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

UTM Tracker for Contact Form 7 Release Timeline

v1.5Current
v1.4
v1.3
Code Analysis
Analyzed Mar 16, 2026

UTM Tracker for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
14 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped14 total outputs
Attack Surface

UTM Tracker for Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actioninitutm-tracker-for-contact-form-7.php:27
actionadmin_menuutm-tracker-for-contact-form-7.php:65
actionadmin_initutm-tracker-for-contact-form-7.php:66
actionwpcf7_initutm-tracker-for-contact-form-7.php:67
actionwpcf7_before_send_mailutm-tracker-for-contact-form-7.php:68
filterwpcf7_posted_datautm-tracker-for-contact-form-7.php:69
filterwpcf7_form_elementsutm-tracker-for-contact-form-7.php:70
actionwp_enqueue_scriptsutm-tracker-for-contact-form-7.php:71
Maintenance & Trust

UTM Tracker for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 13, 2026
PHP min version7.2
Downloads1K

Community Trust

Rating100/100
Number of ratings2
Active installs200
Developer Profile

UTM Tracker for Contact Form 7 Developer Profile

Adnan Buksh

1 plugin · 200 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect UTM Tracker for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/utm-tracker-for-contact-form-7/js/utm-tracker.js
Script Paths
js/utm-tracker.js
Version Parameters
utm-tracker-for-contact-form-7/js/utm-tracker.js?ver=

HTML / DOM Fingerprints

CSS Classes
utmutm_sourceutm_mediumutm_campaignutm_idutm_termutm_content
Data Attributes
name="utm_source"name="utm_medium"name="utm_campaign"name="utm_id"name="utm_term"name="utm_content"+7 more
Shortcode Output
<input type="hidden" name="utm_source" class="utm utm_source" value="" /><input type="hidden" name="utm_medium" class="utm utm_medium" value="" /><input type="hidden" name="utm_campaign" class="utm utm_campaign" value="" /><input type="hidden" name="utm_id" class="utm utm_id" value="" />
FAQ

Frequently Asked Questions about UTM Tracker for Contact Form 7