0 Day Analytics Security & Risk Analysis

wordpress.org/plugins/0-day-analytics

0 Day Analytics is a comprehensive WordPress debugging and operational

40 active installs v4.9.0 PHP 7.4+ WP 6.0+ Updated Mar 9, 2026
crondebugerror-logperformancetransients
99
A · Safe
CVEs total1
Unpatched0
Last CVENov 12, 2025
Download
Safety Verdict

Is 0 Day Analytics Safe to Use in 2026?

Generally Safe

Score 99/100

0 Day Analytics has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 12, 2025Updated 25d ago
Risk Assessment

The plugin '0-day-analytics' v4.9.0 presents a mixed security posture. On the positive side, the static analysis reveals a seemingly small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries are reported as using prepared statements, and there are no indications of file operations, external HTTP requests, or bundled libraries that could introduce known vulnerabilities. The absence of critical or high-severity taint flows is also a good sign.

However, a significant concern arises from the output escaping. With one total output and 0% properly escaped, any data processed by this plugin and displayed to users is highly susceptible to Cross-Site Scripting (XSS) attacks. Additionally, the vulnerability history, despite having no currently unpatched CVEs, shows a past medium-severity SQL injection vulnerability. The fact that this was a medium severity issue and the plugin has a history of such vulnerabilities suggests a need for ongoing vigilance. The complete lack of nonce and capability checks on any potential (though unreported) entry points is also a weakness, leaving the door open for unauthorized actions or manipulation if any entry points are discovered or added in the future.

Key Concerns

  • Unescaped output detected
  • Past medium severity SQL injection vulnerability
  • Lack of nonce checks
  • Lack of capability checks
Vulnerabilities
1

0 Day Analytics Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-64293medium · 4.9Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

0 Day Analytics <= 4.0.0 - Authenticated (Administrator+) SQL Injection

Nov 12, 2025 Patched in 4.1.0 (6d)
Code Analysis
Analyzed Mar 16, 2026

0 Day Analytics Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

0 Day Analytics Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

0 Day Analytics Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 9, 2026
PHP min version7.4
Downloads6K

Community Trust

Rating100/100
Number of ratings2
Active installs40
Developer Profile

0 Day Analytics Developer Profile

Golemiq

2 plugins · 140 total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
6 days
View full developer profile
Detection Fingerprints

How We Detect 0 Day Analytics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/0-day-analytics/advanced-analytics.php
Version Parameters
0-day-analytics/advanced-analytics.php?ver=0-day-analytics/vendor/assets/js/admin.js?ver=0-day-analytics/vendor/assets/css/admin.css?ver=0-day-analytics/vendor/assets/css/settings.css?ver=0-day-analytics/vendor/assets/js/settings.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-advana-logs-urldata-advana-api-noncedata-advana-url-tracker-noncedata-advana-snippets-noncedata-advana-mail-smtp-noncedata-advana-settings-nonce+14 more
JS Globals
ADVAN_SettingsADVAN_AJAX_URLADVAN_NONCEADVAN_REST_URLADVAN_VERSIONADVAN_LOCALE+5 more
REST Endpoints
/wp-json/0-day-analytics/v1/logs/wp-json/0-day-analytics/v1/url-tracker/wp-json/0-day-analytics/v1/snippets/wp-json/0-day-analytics/v1/mail-smtp/wp-json/0-day-analytics/v1/settings
FAQ

Frequently Asked Questions about 0 Day Analytics