WhatsLink Click Tracker Security & Risk Analysis
wordpress.org/plugins/whatslink-click-trackerTrack every WhatsApp and Telegram link click in WordPress. See which pages, UTM sources, and campaigns drive real conversations — no code needed.
Is WhatsLink Click Tracker Safe to Use in 2026?
Generally Safe
Score 100/100WhatsLink Click Tracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "whatslink-click-tracker" v1.1.1 plugin exhibits a concerning security posture due to a significant number of unprotected AJAX handlers, representing its primary attack surface. While the plugin demonstrates good practices in output escaping and generally uses prepared statements for SQL queries, the lack of authentication checks on these AJAX endpoints is a critical vulnerability. The taint analysis reveals three high-severity flows with unsanitized paths, which, when combined with the unprotected AJAX handlers, strongly suggests potential for unauthorized actions or data manipulation. The plugin's lack of any recorded historical vulnerabilities, while seemingly positive, could also indicate that it hasn't been subjected to rigorous security testing or that past vulnerabilities were not publicly disclosed, offering little reassurance. Overall, the plugin's strengths in code sanitation and SQL querying are overshadowed by the critical security flaw of exposed AJAX functionality, making it a high-risk component if not immediately addressed.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows with unsanitized paths
WhatsLink Click Tracker Security Vulnerabilities
WhatsLink Click Tracker Release Timeline
WhatsLink Click Tracker Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WhatsLink Click Tracker Attack Surface
AJAX Handlers 6
WordPress Hooks 10
Maintenance & Trust
WhatsLink Click Tracker Maintenance & Trust
Maintenance Signals
Community Trust
WhatsLink Click Tracker Alternatives
Novera Smart Chat
novera-smart-chat
WhatsApp Floating Chat Button with Analytics, UTM Tracking, GA4 & Conversion Tools
Joinchat
creame-whatsapp-me
WhatsApp, Messenger, Telegram, Phone call… capture users through their favorite Apps and turn into clients
Pulsating Chat Button
amin-chat-button
WhatsApp or Telegram Chat🔥. Adds a pulsating WhatsApp or Telegram button 🍀 to your website. Fast and easy installation. Setting up target id GTM and Y …
UTM Event Tracker and Analytics, UTM Grabber
utm-event-tracker-and-analytics
Easily capture UTM parameters, track button and link clicks, and analyze campaigns to improve your marketing ROI in WordPress.
Floating Contact Button for MAX and Telegram
floating-contact-button-for-max-and-telegram
A lightweight floating contact button for WordPress with support for Telegram, WhatsApp, Facebook Messenger and MAX.
WhatsLink Click Tracker Developer Profile
2 plugins · 40 total installs
How We Detect WhatsLink Click Tracker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/whatslink-click-tracker/admin/css/whatslink-click-tracker-admin.css/wp-content/plugins/whatslink-click-tracker/admin/js/whatslink-click-tracker-admin.js/wp-content/plugins/whatslink-click-tracker/public/css/whatslink-click-tracker-public.css/wp-content/plugins/whatslink-click-tracker/public/js/whatslink-click-tracker-public.js/wp-content/plugins/whatslink-click-tracker/admin/js/whatslink-click-tracker-admin.js/wp-content/plugins/whatslink-click-tracker/public/js/whatslink-click-tracker-public.jswhatslink-click-tracker/admin/css/whatslink-click-tracker-admin.css?ver=whatslink-click-tracker/admin/js/whatslink-click-tracker-admin.js?ver=whatslink-click-tracker/public/css/whatslink-click-tracker-public.css?ver=whatslink-click-tracker/public/js/whatslink-click-tracker-public.js?ver=HTML / DOM Fingerprints
whatslink-click-tracker-admin-pageWhatsLink_Click_Tracker_Admin