UTM Tracker for Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/utm-tracker-for-contact-form-7Track UTM parameters in Contact Form 7 submissions automatically and identify which campaigns generate real leads from your marketing traffic.
Is UTM Tracker for Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 100/100UTM Tracker for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'utm-tracker-for-contact-form-7' v1.5 demonstrates a strong security posture based on the provided static analysis. The absence of any detected dangerous functions, file operations, or external HTTP requests is commendable. Furthermore, all SQL queries utilize prepared statements, and all output is properly escaped, indicating good practices in preventing common web vulnerabilities like SQL injection and cross-site scripting. The plugin also shows a lack of common attack vectors such as AJAX handlers, REST API routes, and shortcodes that are often targets for exploitation. The vulnerability history is also completely clear, with no recorded CVEs, which suggests a well-maintained and secure plugin over time.
While the static analysis indicates a very secure codebase, the sole capability check present is a weakness. Plugins typically require capability checks for various administrative or user-facing actions to ensure proper authorization. The absence of other checks, coupled with zero unprotected entry points, is highly unusual and might suggest either an extremely simple plugin with no user interaction beyond Contact Form 7's own mechanisms, or a potential oversight in the analysis itself if the plugin does indeed have functionalities that require specific permissions. The taint analysis showing zero flows is also excellent, implying no sensitive data is being mishandled. Overall, the plugin appears robustly secured against known web attack vectors, with the primary area for potential concern being the limited evident authorization checks.
Key Concerns
- Only one capability check detected
UTM Tracker for Contact Form 7 Security Vulnerabilities
UTM Tracker for Contact Form 7 Release Timeline
UTM Tracker for Contact Form 7 Code Analysis
Output Escaping
UTM Tracker for Contact Form 7 Attack Surface
WordPress Hooks 8
Maintenance & Trust
UTM Tracker for Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
UTM Tracker for Contact Form 7 Alternatives
Easy UTM Tracking with Contact Form 7
easy-utm-tracking-with-contact-form-7
Easy UTM Tracking with Contact Form 7 is a simple plugin that lets you track UTM parameters and referrer in your Contact Form 7 lead emails with just …
UTM Event Tracker and Analytics, UTM Grabber
utm-event-tracker-and-analytics
Easily capture UTM parameters, track button and link clicks, and analyze campaigns to improve your marketing ROI in WordPress.
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
ReCaptcha v2 for Contact Form 7
wpcf7-recaptcha
Adds reCaptcha v2 from Contact Form 7 5.0.5 that was dropped on Contact Form 7 5.1
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
UTM Tracker for Contact Form 7 Developer Profile
1 plugin · 200 total installs
How We Detect UTM Tracker for Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/utm-tracker-for-contact-form-7/js/utm-tracker.jsjs/utm-tracker.jsutm-tracker-for-contact-form-7/js/utm-tracker.js?ver=HTML / DOM Fingerprints
utmutm_sourceutm_mediumutm_campaignutm_idutm_termutm_contentname="utm_source"name="utm_medium"name="utm_campaign"name="utm_id"name="utm_term"name="utm_content"+7 more<input type="hidden" name="utm_source" class="utm utm_source" value="" /><input type="hidden" name="utm_medium" class="utm utm_medium" value="" /><input type="hidden" name="utm_campaign" class="utm utm_campaign" value="" /><input type="hidden" name="utm_id" class="utm utm_id" value="" />