
Affiliate Sales in Google Analytics and other tools Security & Risk Analysis
wordpress.org/plugins/wecantrackIntegrate all your affiliate sales in Google Analytics, Google Ads, Facebook, Data Studio and more!
Is Affiliate Sales in Google Analytics and other tools Safe to Use in 2026?
Generally Safe
Score 99/100Affiliate Sales in Google Analytics and other tools has a strong security track record. Known vulnerabilities have been patched promptly.
The "wecantrack" plugin v4.0.2 exhibits a mixed security posture. While it shows positive signs like using prepared statements for all SQL queries and performing file operations, significant concerns arise from its attack surface and output sanitization. The presence of two AJAX handlers without authentication checks presents a direct and exploitable entry point for attackers.
The taint analysis reveals a concerning four flows with unsanitized paths, indicating a potential for various vulnerabilities if these paths involve user-controlled input. Although the static analysis did not identify critical or high severity taint flows in this specific scan, the sheer number of unsanitized paths is a strong indicator of potential risk.
Historically, the plugin has had a medium-severity vulnerability classified as 'Open Redirect'. While there are currently no unpatched CVEs, the past occurrence of an Open Redirect, coupled with the current findings of unprotected AJAX endpoints and unsanitized paths, suggests a pattern of potential security weaknesses that require ongoing vigilance. The plugin's output escaping is also a weak point, with less than half of the outputs being properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities.
Key Concerns
- AJAX handlers without auth checks
- Flows with unsanitized paths
- Low percentage of properly escaped output
- Past medium severity vulnerability (Open Redirect)
Affiliate Sales in Google Analytics and other tools Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Affiliate Sales in Google Analytics and other tools <= 2.0.0 - Open Redirect
Affiliate Sales in Google Analytics and other tools Code Analysis
Output Escaping
Data Flow Analysis
Affiliate Sales in Google Analytics and other tools Attack Surface
AJAX Handlers 2
WordPress Hooks 6
Maintenance & Trust
Affiliate Sales in Google Analytics and other tools Maintenance & Trust
Maintenance Signals
Community Trust
Affiliate Sales in Google Analytics and other tools Alternatives
Affiliate Sales in Google Analytics and other tools Developer Profile
2 plugins · 5K total installs
How We Detect Affiliate Sales in Google Analytics and other tools
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wecantrack/build/static/js/main.js/wp-content/plugins/wecantrack/build/static/css/main.css/wp-content/plugins/wecantrack/build/static/js/main.jswecantrack/build/static/css/main.css?ver=wecantrack/build/static/js/main.js?ver=HTML / DOM Fingerprints
wecantrack-admin-page<!-- WeCanTrack - START CODE FOR THE WEBSITES --><!-- WeCanTrack - END CODE FOR THE WEBSITES -->data-wecantrack-iddata-wct-idwindow.wecantrackvar wecantrack/wp-json/wecantrack/v1/track/wp-json/wecantrack/v1/redirect