
AJAX Yandex.Metrika Security & Risk Analysis
wordpress.org/plugins/ajax-yandexmetrikaAdd Yandex.Metrika counter. And add counter integration for AJAX sites.
Is AJAX Yandex.Metrika Safe to Use in 2026?
Generally Safe
Score 85/100AJAX Yandex.Metrika has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'ajax-yandexmetrika' plugin v2.1.0 exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the complete lack of dangerous functions and the use of prepared statements for all SQL queries are excellent practices. The plugin also shows a clean vulnerability history with zero recorded CVEs, indicating a history of responsible development or a lack of targeted attacks.
However, a critical concern arises from the output escaping signals, where 100% of the four identified outputs are not properly escaped. This presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities if any of the data being output can be influenced by user input, even indirectly. The absence of nonce checks and the sole capability check also suggest potential areas for improvement in ensuring proper authorization and preventing unauthorized actions, especially if any future entry points are introduced.
In conclusion, while the plugin benefits from a minimal attack surface and robust SQL handling, the lack of output escaping is a glaring weakness that needs immediate attention. The clean vulnerability history is positive, but it does not negate the inherent risks identified in the current code. Addressing the output escaping issues is paramount to improving the plugin's security.
Key Concerns
- Unescaped output identified
AJAX Yandex.Metrika Security Vulnerabilities
AJAX Yandex.Metrika Code Analysis
Output Escaping
AJAX Yandex.Metrika Attack Surface
WordPress Hooks 6
Maintenance & Trust
AJAX Yandex.Metrika Maintenance & Trust
Maintenance Signals
Community Trust
AJAX Yandex.Metrika Alternatives
WP Views Counter
wpecounter
Fast, lightweight post views counter. Display views in admin, blocks or shortcodes — no tracking scripts required.
Ajax Archive Calendar
ajax-archive-calendar
Ajax Archive Calendar .
Nav Menu Item Duplicator
nav-menu-item-duplicate
A simple plugin that adds a duplicate button to each items on edit menu screen.
WP Search Suggest
wp-search-suggest
Provides title suggestions while typing a search query, using the built-in jQuery suggest script.
Infinite Scroll and Load More Ajax Pagination
infinite-scroll-and-load-more-ajax-pagination
No more page refresh for next page click. User can stay on same page to see all result with Infinite Scroll and Load More.
AJAX Yandex.Metrika Developer Profile
3 plugins · 80 total installs
How We Detect AJAX Yandex.Metrika
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ajax-yandex-metrika/jquery/ajax/counters/jquery.ajax.counters.js/wp-content/plugins/ajax-yandex-metrika/ajax-yandex-metrika.jshttp://mc.yandex.ru/resource/watch.jsajax-yandex-metrika/jquery/ajax/counters/jquery.ajax.counters.js?ver=ajax-yandex-metrika/ajax-yandex-metrika.js?ver=HTML / DOM Fingerprints
YaMetrikaConfig