Analytics Cat – Google Analytics Made Easy Security & Risk Analysis

wordpress.org/plugins/analytics-cat

Analytics Cat - Google Analytics Lets You Add Your Google Analytics / Universal Analytics Tracking Code To Your Site With Ease.

6K active installs v1.1.3 PHP + WP 4.0+ Updated Dec 5, 2024
gagoogle-analyticsgoogle-analytics-plugingoogle-analytics-wordpressuniversal-analytics
88
A · Safe
CVEs total4
Unpatched0
Last CVEDec 29, 2024
Safety Verdict

Is Analytics Cat – Google Analytics Made Easy Safe to Use in 2026?

Generally Safe

Score 88/100

Analytics Cat – Google Analytics Made Easy has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

4 known CVEsLast CVE: Dec 29, 2024Updated 1yr ago
Risk Assessment

The "analytics-cat" plugin v1.1.3 presents a mixed security posture. On the positive side, static analysis reveals no dangerous functions, raw SQL queries, file operations, or external HTTP requests originating from the plugin itself. It also employs prepared statements for all SQL queries and has a sufficient number of nonce checks. However, a significant concern is the low rate of proper output escaping (49%), which indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of capability checks on entry points is also a notable weakness, though the limited attack surface might mitigate this to some extent.

The plugin's vulnerability history is a major red flag. With three known CVEs, including a past high-severity XSS vulnerability and medium-severity CSRF issues, the plugin has a track record of security flaws. While there are currently no unpatched CVEs, the recurring nature of these vulnerability types suggests potential for new undiscovered issues or a systemic weakness in how user input is handled. The most recent vulnerability was reported in late 2024, indicating ongoing discovery of issues.

In conclusion, while the "analytics-cat" plugin demonstrates some good security practices like using prepared statements and nonces, the high proportion of unescaped output and its historical vulnerability patterns present a considerable risk. The lack of capability checks on its entry points adds to this concern. Users should exercise caution and ensure the plugin is kept updated to the latest versions, as well as monitor for any new security advisories.

Key Concerns

  • Significant amount of unescaped output
  • History of high and medium severity CVEs
  • No capability checks on entry points
  • Bundled library (Select2) may be outdated
Vulnerabilities
4 published

Analytics Cat – Google Analytics Made Easy Security Vulnerabilities

CVEs by Year

2 CVEs in 2022
2022
2 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

High
1
Medium
3

4 total CVEs

CVE-2025-24615medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Analytics Cat <= 1.1.2 - Reflected Cross-Site Scripting

Dec 29, 2024 Patched in 1.1.3 (473d)
CVE-2024-12072medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Analytics Cat – Google Analytics Made Easy <= 1.1.2 - Reflected Cross-Site Scripting

Dec 11, 2024 Patched in 1.1.3 (78d)
CVE-2022-40311medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Analytics Cat – Google Analytics Made Easy <= 1.0.9 - Authenticated (Admin+) Stored Cross-Site Scripting

Sep 29, 2022 Patched in 1.1.0 (481d)
CVE-2022-27855high · 8.8Cross-Site Request Forgery (CSRF)

Fatcat Apps Analytics Cat <= 1.0.9 - Cross-Site Request Forgery

Mar 8, 2022 Patched in 1.1.0 (685d)
Version History

Analytics Cat – Google Analytics Made Easy Release Timeline

Code Analysis
Analyzed Mar 16, 2026

Analytics Cat – Google Analytics Made Easy Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
22
21 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

49% escaped43 total outputs
Attack Surface

Analytics Cat – Google Analytics Made Easy Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_fca_ga_uninstallincludes\api.php:38
WordPress Hooks 9
actionwp_headfca-ga.php:66
actioninitfca-ga.php:87
actionadmin_menuincludes\editor\editor.php:16
actionadmin_noticesincludes\notices\notices.php:19
actionadmin_noticesincludes\notices\notices.php:83
actionfca_ga_schedule_review_noticeincludes\notices\notices.php:89
actionadmin_noticesincludes\notices\notices.php:144
actionfca_ga_schedule_ga4_noticeincludes\notices\notices.php:150
actionadmin_enqueue_scriptsincludes\notices\notices.php:194

Scheduled Events 3

fca_ga_schedule_review_notice
fca_ga_schedule_review_notice
fca_ga_schedule_ga4_notice
Maintenance & Trust

Analytics Cat – Google Analytics Made Easy Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedDec 5, 2024
PHP min version
Downloads215K

Community Trust

Rating98/100
Number of ratings15
Active installs6K
Developer Profile

Analytics Cat – Google Analytics Made Easy Developer Profile

fatcatapps

13 plugins · 66K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
250 days
View full developer profile
Detection Fingerprints

How We Detect Analytics Cat – Google Analytics Made Easy

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/analytics-cat/includes/select2/select2.min.js/wp-content/plugins/analytics-cat/includes/select2/select2.min.css/wp-content/plugins/analytics-cat/includes/tooltipster/tooltipster.bundle.min.css/wp-content/plugins/analytics-cat/includes/tooltipster/tooltipster-borderless.min.css/wp-content/plugins/analytics-cat/includes/tooltipster/tooltipster.bundle.min.js/wp-content/plugins/analytics-cat/includes/editor/admin.min.js/wp-content/plugins/analytics-cat/includes/editor/admin.min.css/wp-content/plugins/analytics-cat/assets/googlecat_icon128_128_360.png
Script Paths
https://www.googletagmanager.com/gtag/js?id=
Version Parameters
fca_ga_select2fca_ga_tooltipster_stylesheetfca_ga_tooltipster_borderless_cssfca_ga_tooltipster_jsfca_ga_admin_jsfca_ga_admin_stylesheet

HTML / DOM Fingerprints

CSS Classes
fca_ga_setting_tablefca_ga_hint
HTML Comments
<!-- Global site tag (gtag.js) - Google Analytics -->
Data Attributes
name="fca_ga[nonce]"
JS Globals
window.dataLayergtagadminData
FAQ

Frequently Asked Questions about Analytics Cat – Google Analytics Made Easy