WP Tracking Manager Security & Risk Analysis
wordpress.org/plugins/wp-tracking-managerVery Simple plugin to add any type of tracking code on your website and also restrict the direct access of thank page.
Is WP Tracking Manager Safe to Use in 2026?
Generally Safe
Score 85/100WP Tracking Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-tracking-manager plugin v1.5 exhibits a strong security posture from a static analysis perspective, with no identified attack surface points, dangerous functions, or SQL injection vulnerabilities. The absence of external HTTP requests and file operations further contributes to a secure design. However, the low percentage of properly escaped outputs (5%) is a significant concern, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of nonce checks across all entry points, while the entry points themselves are zero, still presents a theoretical weakness if new entry points were introduced without proper security measures. The plugin's vulnerability history is clean, with zero known CVEs, which is a positive indicator. This, combined with the clean taint analysis, suggests a generally well-developed plugin. Nevertheless, the output escaping issue is a critical oversight that needs immediate attention to mitigate potential XSS attacks.
Key Concerns
- Low output escaping percentage
- No nonce checks on entry points
WP Tracking Manager Security Vulnerabilities
WP Tracking Manager Code Analysis
Output Escaping
WP Tracking Manager Attack Surface
WordPress Hooks 5
Maintenance & Trust
WP Tracking Manager Maintenance & Trust
Maintenance Signals
Community Trust
WP Tracking Manager Alternatives
Tracking Script Manager
tracking-script-manager
Easy tag management. Manage the tracking tags, codes and scripts you use in your WordPress site; easily add, update, reorder, delete, as required.
Content Snippet Manager
content-snippet-manager
Content Snippet Manager plugin allows you to create and manage unlimited numbers of HTML and WordPress shortcodes in your WordPress content
Conversion And Remarketing Code
conversion-and-remarketing-code
Easily place tracking code in the header or footer of your entire site or individual posts/pages.
DeMomentSomTres WP Admin GTM
demomentsomtres-wp-admin-gtm
DeMomentSomTres Google Tag Manager for WP-Admin allows to extend DuracellTomi's Google Tag Manager into WP administration.
AI Powered Marketing
kliken-marketing-for-google
Kliken's all-in-one marketing helps businesses reach high-intent customers, beat the competition and see sales growth while lowering conversion costs
WP Tracking Manager Developer Profile
21 plugins · 30K total installs
How We Detect WP Tracking Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-tracking-manager/css/wtm-admin.css/wp-content/plugins/wp-tracking-manager/js/wtm-admin.js/wp-content/plugins/wp-tracking-manager/js/wtm-admin.jswp-tracking-manager/css/wtm-admin.css?ver=wp-tracking-manager/js/wtm-admin.js?ver=HTML / DOM Fingerprints
wtm-toolbar-pagesm_menu_item_classwtm-toolbar-pagesm_menu_item_class