
0 Day Analytics Security & Risk Analysis
wordpress.org/plugins/0-day-analytics0 Day Analytics is a comprehensive WordPress debugging and operational
Is 0 Day Analytics Safe to Use in 2026?
Generally Safe
Score 99/1000 Day Analytics has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin '0-day-analytics' v4.9.0 presents a mixed security posture. On the positive side, the static analysis reveals a seemingly small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries are reported as using prepared statements, and there are no indications of file operations, external HTTP requests, or bundled libraries that could introduce known vulnerabilities. The absence of critical or high-severity taint flows is also a good sign.
However, a significant concern arises from the output escaping. With one total output and 0% properly escaped, any data processed by this plugin and displayed to users is highly susceptible to Cross-Site Scripting (XSS) attacks. Additionally, the vulnerability history, despite having no currently unpatched CVEs, shows a past medium-severity SQL injection vulnerability. The fact that this was a medium severity issue and the plugin has a history of such vulnerabilities suggests a need for ongoing vigilance. The complete lack of nonce and capability checks on any potential (though unreported) entry points is also a weakness, leaving the door open for unauthorized actions or manipulation if any entry points are discovered or added in the future.
Key Concerns
- Unescaped output detected
- Past medium severity SQL injection vulnerability
- Lack of nonce checks
- Lack of capability checks
0 Day Analytics Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
0 Day Analytics <= 4.0.0 - Authenticated (Administrator+) SQL Injection
0 Day Analytics Code Analysis
Output Escaping
0 Day Analytics Attack Surface
Maintenance & Trust
0 Day Analytics Maintenance & Trust
Maintenance Signals
Community Trust
0 Day Analytics Alternatives
WP Healthcheck
wp-healthcheck
WP Healthcheck is a plugin to check the health of your WordPress install.
WpLoadGraph – Log and display server load of your WP site
wploadgraph
Stress testing tool for logging and measuring all requests to your WordPress website and displaying in timeline format.
Cron Error Silence
cron-error-silence
Silence noisy WordPress cron-related error messages and clean up your debug logs – without affecting core functionality.
WP Crontrol
wp-crontrol
WP Crontrol enables you to take control of the cron events on your WordPress website.
Query Monitor – The developer tools panel for WordPress
query-monitor
Query Monitor is the developer tools panel for WordPress and WooCommerce.
0 Day Analytics Developer Profile
2 plugins · 140 total installs
How We Detect 0 Day Analytics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/0-day-analytics/advanced-analytics.php0-day-analytics/advanced-analytics.php?ver=0-day-analytics/vendor/assets/js/admin.js?ver=0-day-analytics/vendor/assets/css/admin.css?ver=0-day-analytics/vendor/assets/css/settings.css?ver=0-day-analytics/vendor/assets/js/settings.js?ver=HTML / DOM Fingerprints
data-advana-logs-urldata-advana-api-noncedata-advana-url-tracker-noncedata-advana-snippets-noncedata-advana-mail-smtp-noncedata-advana-settings-nonce+14 moreADVAN_SettingsADVAN_AJAX_URLADVAN_NONCEADVAN_REST_URLADVAN_VERSIONADVAN_LOCALE+5 more/wp-json/0-day-analytics/v1/logs/wp-json/0-day-analytics/v1/url-tracker/wp-json/0-day-analytics/v1/snippets/wp-json/0-day-analytics/v1/mail-smtp/wp-json/0-day-analytics/v1/settings