
WP Track Kepper Security & Risk Analysis
wordpress.org/plugins/wp-track-keeperWP Track Keeper watches over your Wordpress directory files and send email and Or SMS notification to your defined Email and Or phone number.
Is WP Track Kepper Safe to Use in 2026?
Generally Safe
Score 85/100WP Track Kepper has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-track-keeper plugin version 1.0 demonstrates a generally good security posture based on the provided static analysis. A significant strength is the absence of any identified vulnerabilities in its history, suggesting a commitment to security or a lack of past exploits. The static analysis reveals no dangerous functions, critical or high severity taint flows, and a low number of file operations and external HTTP requests. Furthermore, all identified AJAX entry points have associated authentication checks, and there are no directly exploitable REST API routes or shortcodes without permission callbacks, minimizing the direct attack surface. However, there are areas for improvement. The relatively low percentage of properly escaped output (36%) is a concern, as this could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully. While there are nonce checks and capability checks present, the balance suggests that not all outputs might be adequately protected against CSRF or unauthorized access. The presence of raw SQL queries without prepared statements, though a minority (17%), still introduces a risk of SQL injection. The plugin's minimal vulnerability history is positive but should not lead to complacency; continued vigilance and security best practices are essential.
Key Concerns
- Output escaping is not consistently applied.
- Some SQL queries do not use prepared statements.
WP Track Kepper Security Vulnerabilities
WP Track Kepper Code Analysis
SQL Query Safety
Output Escaping
WP Track Kepper Attack Surface
AJAX Handlers 3
WordPress Hooks 8
Scheduled Events 1
Maintenance & Trust
WP Track Kepper Maintenance & Trust
Maintenance Signals
Community Trust
WP Track Kepper Alternatives
Injection Guard
injection-guard
This plugin blocks all unauthorized and irrelevant requests through query strings and provides extended session tracking and capability audit.
MailPoet – Newsletters, Email Marketing, and Automation
mailpoet
Send beautiful newsletters from WordPress. Collect subscribers with signup forms, automate your emails for WooCommerce, blog post notifications & more
MalCare WordPress Security Plugin – Malware Scanner, Cleaner, Security Firewall
malcare-security
Get Bulletproof Security for your WordPress site. WordPress security plugin packed with comprehensive Firewall, malware scanner, cleaner & more.
Disable Admin Notices – Hide Dashboard Notifications
disable-admin-notices
Disable admin notices and hide dashboard notifications from plugins, themes and core. Hide all notices, selected ones, or show them in a single line.
Manage Notification E-mails
manage-notification-emails
Enable and disable email notifications that WordPress sends to the admin and user. Works perfectly with many other plugins!
WP Track Kepper Developer Profile
3 plugins · 20 total installs
How We Detect WP Track Kepper
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-track-keeper/assets/js//wp-content/plugins/wp-track-keeper/admin/js//wp-content/plugins/wp-track-keeper/assets/css//wp-content/plugins/wp-track-keeper/admin/css//wp-content/plugins/wp-track-keeper/front/js//wp-content/plugins/wp-track-keeper/front/css//wp-content/plugins/wp-track-keeper/widget/wp-track-keeper/assets/js/wp-track-keeper/admin/js/wp-track-keeper/front/js/wp-track-keeper/assets/css/?ver=wp-track-keeper/admin/css/?ver=wp-track-keeper/front/css/?ver=