Analytics Integration for PostHog, WP, & WC Security & Risk Analysis

wordpress.org/plugins/analytics-integration-for-posthog-wp-wc

Integrate PostHog with WordPress and WooCommerce for detailed user behavior tracking, product analytics, experimentation, and more.

20 active installs v1.5.3 PHP 7.2+ WP 5.0+ Updated Sep 3, 2025
analyticsecommerceposthogtrackingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Analytics Integration for PostHog, WP, & WC Safe to Use in 2026?

Generally Safe

Score 100/100

Analytics Integration for PostHog, WP, & WC has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The analytics-integration-for-posthog-wp-wc plugin, v1.5.3, exhibits a generally strong security posture, with no recorded vulnerabilities or CVEs. The static analysis reveals a limited attack surface, consisting of two AJAX handlers, with no apparent authentication checks missing for these entry points. Notably, the plugin demonstrates excellent practices regarding SQL queries, utilizing prepared statements exclusively, and avoids potentially risky file operations and external HTTP requests. The presence of a nonce check on one of the entry points is also a positive indicator of security awareness. However, a significant area for concern is the output escaping, where only 62% of outputs are properly escaped. This indicates a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully before being rendered in the browser.

Key Concerns

  • Insufficient output escaping detected
  • Missing capability checks on AJAX handlers
Vulnerabilities
None known

Analytics Integration for PostHog, WP, & WC Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Analytics Integration for PostHog, WP, & WC Release Timeline

v1.5.3Current
v1.5.2
v1.5.1
Code Analysis
Analyzed Mar 16, 2026

Analytics Integration for PostHog, WP, & WC Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
21 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

62% escaped34 total outputs
Attack Surface

Analytics Integration for PostHog, WP, & WC Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_get_product_dataanalytics-integration-for-posthog-wp-wc.php:751
noprivwp_ajax_get_product_dataanalytics-integration-for-posthog-wp-wc.php:752
WordPress Hooks 25
actionadmin_menuanalytics-integration-for-posthog-wp-wc.php:20
actionadmin_initanalytics-integration-for-posthog-wp-wc.php:21
actionwp_loginanalytics-integration-for-posthog-wp-wc.php:22
actioninitanalytics-integration-for-posthog-wp-wc.php:25
actionwp_enqueue_scriptsanalytics-integration-for-posthog-wp-wc.php:28
actionwp_enqueue_scriptsanalytics-integration-for-posthog-wp-wc.php:29
actionadmin_enqueue_scriptsanalytics-integration-for-posthog-wp-wc.php:32
actionadmin_enqueue_scriptsanalytics-integration-for-posthog-wp-wc.php:33
actionwp_enqueue_scriptsanalytics-integration-for-posthog-wp-wc.php:36
actionplugins_loadedanalytics-integration-for-posthog-wp-wc.php:39
actionwoocommerce_thankyouanalytics-integration-for-posthog-wp-wc.php:76
actionwoocommerce_add_to_cartanalytics-integration-for-posthog-wp-wc.php:724
actionwoocommerce_after_single_productanalytics-integration-for-posthog-wp-wc.php:796
actionwoocommerce_before_shop_loopanalytics-integration-for-posthog-wp-wc.php:818
actionwoocommerce_cart_updatedanalytics-integration-for-posthog-wp-wc.php:850
actionwoocommerce_before_cartanalytics-integration-for-posthog-wp-wc.php:914
actionwoocommerce_add_to_cartanalytics-integration-for-posthog-wp-wc.php:923
actionwpanalytics-integration-for-posthog-wp-wc.php:994
actionwoocommerce_before_checkout_formanalytics-integration-for-posthog-wp-wc.php:999
actionwp_footeranalytics-integration-for-posthog-wp-wc.php:1000
actionwoocommerce_checkout_update_order_reviewanalytics-integration-for-posthog-wp-wc.php:1001
actionwoocommerce_checkout_order_processedanalytics-integration-for-posthog-wp-wc.php:1002
filterinfnet_posthog_wc_purchase_dataanalytics-integration-for-posthog-wp-wc.php:1060
actionenqueue_block_editor_assetsanalytics-integration-for-posthog-wp-wc.php:1106
filterrender_blockanalytics-integration-for-posthog-wp-wc.php:1132
Maintenance & Trust

Analytics Integration for PostHog, WP, & WC Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 3, 2025
PHP min version7.2
Downloads824

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Analytics Integration for PostHog, WP, & WC Developer Profile

Constantin Oesterling

3 plugins · 2K total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Analytics Integration for PostHog, WP, & WC

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/analytics-integration-for-posthog-wp-wc/assets/css/admin-style.css/wp-content/plugins/analytics-integration-for-posthog-wp-wc/assets/js/posthog-script.js
Script Paths
/wp-content/plugins/analytics-integration-for-posthog-wp-wc/assets/js/posthog-script.js
Version Parameters
analytics-integration-for-posthog-wp-wc/assets/css/admin-style.css?ver=analytics-integration-for-posthog-wp-wc/assets/js/posthog-script.js?ver=

HTML / DOM Fingerprints

JS Globals
infnet_posthog_settings
FAQ

Frequently Asked Questions about Analytics Integration for PostHog, WP, & WC