AllFactors Security & Risk Analysis

wordpress.org/plugins/allfactors

AllFactors is a no-code all-in-one web marketing analytics tool to drive your marketing & growth.

0 active installs v0.8.0 PHP 7.4+ WP 5.7+ Updated Dec 21, 2024
analyticsinsightsmarketing-analyticsmeasurementweb-analytics
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AllFactors Safe to Use in 2026?

Generally Safe

Score 92/100

AllFactors has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The static analysis of allfactors v0.8.0 reveals a remarkably clean codebase with no identified vulnerabilities. The plugin demonstrates excellent security practices by not utilizing dangerous functions, performing all SQL queries with prepared statements, and properly escaping all outputs. Furthermore, it avoids file operations, external HTTP requests, and lacks any apparent vulnerabilities in taint analysis. This indicates a strong focus on secure coding standards and a low risk of common plugin exploits.

However, the absence of nonce checks and capability checks is a significant concern. While the current attack surface is zero, any future addition of AJAX handlers, REST API routes, or shortcodes without these critical security mechanisms would immediately introduce exploitable vulnerabilities. The plugin's vulnerability history being empty is a positive sign, suggesting past diligence, but it does not negate the inherent risks introduced by the missing authentication and authorization controls.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

AllFactors Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

AllFactors Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped4 total outputs
Attack Surface

AllFactors Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_initallfactors.php:20
actionadmin_menuallfactors.php:25
filterscript_loader_tagallfactors.php:74
actionwp_enqueue_scriptsallfactors.php:83
Maintenance & Trust

AllFactors Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 21, 2024
PHP min version7.4
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

AllFactors Developer Profile

AllFactors

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AllFactors

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/allfactors/allfactors.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about AllFactors