AesirX Analytics Security & Risk Analysis

wordpress.org/plugins/aesirx-analytics

Enhance website tracking with the AesirX Analytics WordPress plugin, using privacy-friendly first-party analytics for accurate insights.

100 active installs v5.0.1 PHP 7.4+ WP 5.9+ Updated Feb 9, 2026
analyticsfirst-party-analyticsvisitor-trackingwebsite-insightswordpress-analytics
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AesirX Analytics Safe to Use in 2026?

Generally Safe

Score 100/100

AesirX Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The aesirx-analytics plugin v5.0.1 exhibits a generally good security posture, with a strong adherence to best practices in several key areas. The high percentage of prepared statements for SQL queries and properly escaped output signals a conscientious approach to preventing common web vulnerabilities. Furthermore, the absence of any recorded vulnerabilities (CVEs) or taint analysis findings further bolsters this perception of a secure plugin. The use of a bundled library like Guzzle, while not inherently a security risk, should be monitored for potential outdated versions that could introduce vulnerabilities.

However, a significant concern arises from the static analysis results. The presence of one unprotected AJAX handler represents a critical entry point into the plugin's functionality without any authorization or permission checks. This unchecked endpoint could potentially be exploited by unauthenticated users to perform unintended actions or expose sensitive data. While the plugin does have a nonce check and capability checks, their application to this specific AJAX handler is not guaranteed without further code inspection, and the absence of such checks is a clear security weakness. The limited attack surface, with only one unprotected entry point, mitigates the overall risk, but the nature of this specific vulnerability requires careful attention.

In conclusion, aesirx-analytics v5.0.1 demonstrates strengths in secure coding practices for database operations and output handling, and has a clean vulnerability history. The primary weakness lies in an unprotected AJAX handler, which introduces a potential security risk that needs to be addressed. Balancing these factors, the plugin is relatively secure but the identified unprotected entry point warrants a deduction in its overall score.

Key Concerns

  • Unprotected AJAX handler
Vulnerabilities
None known

AesirX Analytics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AesirX Analytics Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
67 prepared
Unescaped Output
1
108 escaped
Nonce Checks
1
Capability Checks
2
File Operations
2
External Requests
6
Bundled Libraries
1

Bundled Libraries

Guzzle

SQL Query Safety

99% prepared68 total queries

Output Escaping

99% escaped109 total outputs
Attack Surface
1 unprotected

AesirX Analytics Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_aesirx_dismiss_pro_upsellaesirx-analytics.php:291
WordPress Hooks 19
actionwp_enqueue_scriptsaesirx-analytics.php:43
actionanalytics_cron_geoaesirx-analytics.php:61
actionparse_requestaesirx-analytics.php:100
actionadmin_noticesaesirx-analytics.php:228
actionadmin_noticesaesirx-analytics.php:274
actionadmin_enqueue_scriptsaesirx-analytics.php:276
actionadmin_initaesirx-analytics.php:296
actionadmin_initincludes\settings.php:5
actionadmin_menuincludes\settings.php:50
actionadmin_initincludes\settings.php:215
actionadmin_enqueue_scriptsincludes\settings.php:241
actionadmin_footerincludes\settings.php:395
actionwp_headsrc\Integration\Woocommerce.php:38
actionwoocommerce_add_to_cartsrc\Integration\Woocommerce.php:39
actionwoocommerce_cart_item_removedsrc\Integration\Woocommerce.php:40
actionwoocommerce_cart_item_restoredsrc\Integration\Woocommerce.php:41
actionwoocommerce_cart_item_set_quantitysrc\Integration\Woocommerce.php:42
actionwoocommerce_applied_couponsrc\Integration\Woocommerce.php:43
actionwoocommerce_removed_couponsrc\Integration\Woocommerce.php:44

Scheduled Events 1

analytics_cron_geo
Maintenance & Trust

AesirX Analytics Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 9, 2026
PHP min version7.4
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

AesirX Analytics Developer Profile

AesirX

2 plugins · 120 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AesirX Analytics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/aesirx-analytics/assets/vendor/statistic.js
Script Paths
/wp-content/plugins/aesirx-analytics/assets/vendor/statistic.js

HTML / DOM Fingerprints

Data Attributes
window.aesirx1stparty
JS Globals
aesirx1stparty
REST Endpoints
/remember_flow/{flow}
FAQ

Frequently Asked Questions about AesirX Analytics