Amplitude – Analytics, Session Replay, A/B testing and CDP for your website Security & Risk Analysis

wordpress.org/plugins/amplitude

Grow your website with confidence using our award winning digital analytics platform now available on WordPress

800 active installs v0.2.3 PHP 5.6+ WP 5.2+ Updated Dec 19, 2025
amplitudeanalyticsgoogle-analyticstag-managerweb-analytics
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Amplitude – Analytics, Session Replay, A/B testing and CDP for your website Safe to Use in 2026?

Generally Safe

Score 100/100

Amplitude – Analytics, Session Replay, A/B testing and CDP for your website has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The 'amplitude' plugin v0.2.3 exhibits a very strong security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL queries executed without prepared statements, unescaped output, file operations, or external HTTP requests is highly commendable. Furthermore, the plugin demonstrates good practices by implementing capability checks, even though the overall attack surface is reported as zero. The taint analysis also reveals no critical or high-severity vulnerabilities, indicating that data flows within the plugin are likely well-sanitized.

The plugin's vulnerability history is also clean, with no recorded CVEs across any severity levels. This lack of past vulnerabilities, combined with the robust static analysis, suggests a developer who prioritizes security. The plugin appears to be well-written and does not present any immediate or obvious security risks based on the data. However, it's worth noting that a zero attack surface can sometimes indicate limited functionality, and the absence of nonce checks on the reported zero AJAX handlers doesn't inherently mean a vulnerability, but it's a pattern to be aware of in plugins with more active entry points.

In conclusion, 'amplitude' v0.2.3 is exceptionally secure according to this analysis. Its adherence to best practices in handling data and its clean vulnerability history are significant strengths. There are no apparent weaknesses directly identifiable from the provided data that would warrant significant deductions. The plugin appears to be a safe choice from a security perspective.

Vulnerabilities
None known

Amplitude – Analytics, Session Replay, A/B testing and CDP for your website Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Amplitude – Analytics, Session Replay, A/B testing and CDP for your website Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
31 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped31 total outputs
Attack Surface

Amplitude – Analytics, Session Replay, A/B testing and CDP for your website Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_menuamplitude.php:65
actionadmin_enqueue_scriptsamplitude.php:67
actionadmin_initamplitude.php:68
actionadmin_headamplitude.php:69
actionadmin_noticesamplitude.php:70
actionwp_enqueue_scriptsamplitude.php:96
actionplugins_loadedamplitude.php:433
Maintenance & Trust

Amplitude – Analytics, Session Replay, A/B testing and CDP for your website Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 19, 2025
PHP min version5.6
Downloads6K

Community Trust

Rating100/100
Number of ratings1
Active installs800
Developer Profile

Amplitude – Analytics, Session Replay, A/B testing and CDP for your website Developer Profile

amplitudegrowth

1 plugin · 800 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Amplitude – Analytics, Session Replay, A/B testing and CDP for your website

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/amplitude/styles/amplitude-styles.css/wp-content/plugins/amplitude/templates/api-key-banner.php/wp-content/plugins/amplitude/scripts/amplitude-configure.js/wp-content/plugins/amplitude/templates/amplitude-general.php/wp-content/plugins/amplitude/templates/settings.php
Script Paths
https://cdn.amplitude.com/libs/analytics-browser-2.32.2-min.js.gzhttps://cdn.amplitude.com/libs/plugin-session-replay-browser-1.25.2-min.js.gzhttps://*.amplitude.com/script/*.experiment.js
Version Parameters
amplitude-styles.css?ver=amplitude-configure.js?ver=

HTML / DOM Fingerprints

CSS Classes
amplitude-api-key-banner
HTML Comments
This is an Amplitude banner to inform users to configure their API key.
Data Attributes
data-amplitude-api-keydata-amplitude-session-replaydata-amplitude-sample-ratedata-amplitude-change-librarydata-amplitude-eu-server-zonedata-amplitude-api-key-required
JS Globals
amplitudeamplitudeConfigaampliPlgScrPayload
FAQ

Frequently Asked Questions about Amplitude – Analytics, Session Replay, A/B testing and CDP for your website