Analytics for Cloudflare Security & Risk Analysis

wordpress.org/plugins/analytics-for-cloudflare

A WordPress plugin to connect your WordPress dashboard to your CloudFlare account to display some key analytics data.

10 active installs v1.1 PHP + WP 3.8+ Updated Feb 9, 2017
adminanalyticsdashboard
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Analytics for Cloudflare Safe to Use in 2026?

Generally Safe

Score 85/100

Analytics for Cloudflare has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The analytics-for-cloudflare plugin v1.1 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any identified attack surface entry points like AJAX handlers, REST API routes, shortcodes, or cron events is a significant strength, indicating that the plugin is designed to minimize external interaction points that could be exploited.

Furthermore, the code analysis reveals good practices in critical areas. There are no dangerous functions used, and all SQL queries are properly prepared, eliminating common SQL injection vulnerabilities. The high percentage of properly escaped output (90%) also suggests a conscious effort to prevent Cross-Site Scripting (XSS) attacks. The plugin's lack of known CVEs and historical vulnerabilities further reinforces its apparent security. The presence of external HTTP requests, while not inherently a risk, is an area to monitor for potential supply chain attacks or misconfigurations.

Overall, this plugin appears to be securely developed and maintained. The limited attack surface and adherence to secure coding practices for SQL and output handling are commendable. The main area for potential minor concern lies in the external HTTP requests, which should be reviewed for proper validation and sanitization of any data exchanged, though no specific issues were flagged in the taint analysis.

Key Concerns

  • No Nonce checks found
  • No capability checks found
  • External HTTP requests present
Vulnerabilities
None known

Analytics for Cloudflare Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Analytics for Cloudflare Release Timeline

v1.1Current
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

Analytics for Cloudflare Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
114 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

90% escaped126 total outputs
Attack Surface

Analytics for Cloudflare Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionwp_dashboard_setupincludes\class-analytics-for-cloudflare-admin-dashboard.php:29
actionadmin_enqueue_scriptsincludes\class-analytics-for-cloudflare-admin-dashboard.php:30
actionadmin_initincludes\class-analytics-for-cloudflare-admin-settings.php:50
actionadmin_menuincludes\class-analytics-for-cloudflare-admin-settings.php:51
actioncmd_analytics_for_cloudflare_admin_settings_after_descincludes\class-analytics-for-cloudflare-admin-settings.php:274
actioncmd_analytics_for_cloudflare_admin_settings_after_descincludes\class-analytics-for-cloudflare-admin-settings.php:278
actioninitincludes\class-analytics-for-cloudflare.php:49
actionplugins_loadedincludes\class-analytics-for-cloudflare.php:86
actionwp_dashboard_setuptrunk\includes\class-analytics-for-cloudflare-admin-dashboard.php:29
actionadmin_enqueue_scriptstrunk\includes\class-analytics-for-cloudflare-admin-dashboard.php:30
actionadmin_inittrunk\includes\class-analytics-for-cloudflare-admin-settings.php:50
actionadmin_menutrunk\includes\class-analytics-for-cloudflare-admin-settings.php:51
actioncmd_analytics_for_cloudflare_admin_settings_after_desctrunk\includes\class-analytics-for-cloudflare-admin-settings.php:274
actioncmd_analytics_for_cloudflare_admin_settings_after_desctrunk\includes\class-analytics-for-cloudflare-admin-settings.php:278
actioninittrunk\includes\class-analytics-for-cloudflare.php:49
actionplugins_loadedtrunk\includes\class-analytics-for-cloudflare.php:86
Maintenance & Trust

Analytics for Cloudflare Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedFeb 9, 2017
PHP min version
Downloads3K

Community Trust

Rating96/100
Number of ratings4
Active installs10
Developer Profile

Analytics for Cloudflare Developer Profile

Chuck Mac

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Analytics for Cloudflare

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/analytics-for-cloudflare/assets/css/admin.css/wp-content/plugins/analytics-for-cloudflare/lib/Moment.js-2.10.6/moment.js/wp-content/plugins/analytics-for-cloudflare/lib/Chart.js-1.0.2/Chart.min.js
Version Parameters
analytics-for-cloudflare/assets/css/admin.css?ver=analytics-for-cloudflare/lib/Moment.js-2.10.6/moment.js?ver=analytics-for-cloudflare/lib/Chart.js-1.0.2/Chart.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
cmd-analytics-for-cloudflare-dashboard
HTML Comments
ENTERPRISE PLAN PRO PLAN PRO PLAN
Data Attributes
data-cmd-analytics-for-cloudflare-current-userdata-cmd-analytics-for-cloudflare-dashboard-rangedata-cmd-analytics-for-cloudflare-dashboard-type
JS Globals
CMD_Analytics_For_CloudflaremomentChart
FAQ

Frequently Asked Questions about Analytics for Cloudflare