AlmaWeb AI Visitor Analytics Security & Risk Analysis

wordpress.org/plugins/almaweb-ai-visitor-analytics

Monitor AI bots visiting your site AND track real visitors coming FROM AI platforms like ChatGPT, Claude, and Perplexity.

30 active installs v1.2.0 PHP 7.4+ WP 5.0+ Updated Feb 1, 2026
aianalyticsbotseotraffic
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AlmaWeb AI Visitor Analytics Safe to Use in 2026?

Generally Safe

Score 100/100

AlmaWeb AI Visitor Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The almaweb-ai-visitor-analytics plugin v1.2.0 exhibits a generally good security posture based on the provided static analysis. The absence of any known CVEs, including critical or high severity ones, is a significant positive indicator. The code also demonstrates a strong reliance on prepared statements for SQL queries, with 86% of them utilizing this secure practice. Furthermore, the plugin includes a reasonable number of nonce and capability checks, suggesting an awareness of common WordPress security vulnerabilities.

However, there are areas for improvement. The plugin's output escaping is only properly handled in 52% of cases, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not consistently sanitized before being displayed. While the taint analysis found no critical or high severity issues, this lower percentage of proper output escaping warrants attention. The plugin also performs file operations and external HTTP requests, which, while not inherently insecure, introduce potential vectors that require careful implementation and validation.

Overall, almaweb-ai-visitor-analytics v1.2.0 appears to be a relatively secure plugin, especially given its lack of historical vulnerabilities. The developer has implemented several good security practices. The primary area of concern is the inconsistent output escaping, which could be a potential entry point for certain attacks. Addressing this would further strengthen the plugin's security.

Key Concerns

  • Only 52% of output properly escaped
Vulnerabilities
None known

AlmaWeb AI Visitor Analytics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AlmaWeb AI Visitor Analytics Code Analysis

Dangerous Functions
0
Raw SQL Queries
10
60 prepared
Unescaped Output
135
149 escaped
Nonce Checks
4
Capability Checks
2
File Operations
2
External Requests
1
Bundled Libraries
0

SQL Query Safety

86% prepared70 total queries

Output Escaping

52% escaped284 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
save_settings (admin\class-admin-settings.php:246)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

AlmaWeb AI Visitor Analytics Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_Almaweb_cleanupadmin\class-admin-settings.php:277
authwp_ajax_Almaweb_resetadmin\class-admin-settings.php:278
WordPress Hooks 7
actionplugins_loadedalmaweb-ai-visitor-analytics.php:50
actionadmin_initalmaweb-ai-visitor-analytics.php:51
actionadmin_noticesalmaweb-ai-visitor-analytics.php:52
actioninitalmaweb-ai-visitor-analytics.php:57
actionalmaweb_daily_cleanupalmaweb-ai-visitor-analytics.php:58
actionadmin_menualmaweb-ai-visitor-analytics.php:59
actionadmin_enqueue_scriptsalmaweb-ai-visitor-analytics.php:60

Scheduled Events 1

almaweb_daily_cleanup
Maintenance & Trust

AlmaWeb AI Visitor Analytics Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 1, 2026
PHP min version7.4
Downloads287

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

AlmaWeb AI Visitor Analytics Developer Profile

AlmaWeb

1 plugin · 30 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AlmaWeb AI Visitor Analytics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/almaweb-ai-visitor-analytics/admin/css/settings.css/wp-content/plugins/almaweb-ai-visitor-analytics/admin/js/settings.js/wp-content/plugins/almaweb-ai-visitor-analytics/admin/js/dashboard.js
Script Paths
/wp-content/plugins/almaweb-ai-visitor-analytics/assets/js/script.js
Version Parameters
almaweb-ai-visitor-analytics/admin/css/settings.css?ver=almaweb-ai-visitor-analytics/admin/js/settings.js?ver=almaweb-ai-visitor-analytics/admin/js/dashboard.js?ver=almaweb-ai-visitor-analytics/assets/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
almaweb-ai-visitor-analytics-dashboardalmaweb-ai-visitor-analytics-settings-page
HTML Comments
<!-- AlmaWeb AI Visitor Analytics Settings --><!-- AlmaWeb AI Visitor Analytics Dashboard -->
JS Globals
AlmaWebAIConfig
REST Endpoints
/wp-json/almaweb-ai-visitor-analytics/v1/settings
FAQ

Frequently Asked Questions about AlmaWeb AI Visitor Analytics