Analytics Tracker Security & Risk Analysis

wordpress.org/plugins/analytics-tracker

Analytics Tracker makes it super easy to add Google Analytics tracking code on your site

1K active installs v3.0.1 PHP + WP 4.6+ Updated Mar 20, 2026
analyticsga4google-analyticsgoogle-tagmeasurement-id
100
A · Safe
CVEs total1
Unpatched0
Last CVEJun 22, 2017
Safety Verdict

Is Analytics Tracker Safe to Use in 2026?

Generally Safe

Score 100/100

Analytics Tracker has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Jun 22, 2017Updated 1mo ago
Risk Assessment

The static analysis of the 'analytics-tracker' plugin v3.0.0 reveals a generally strong security posture. There are no identified attack surface entry points, dangerous functions, raw SQL queries, or external HTTP requests. All output is properly escaped, and file operations are absent. This indicates a good practice in secure coding and avoiding common vulnerabilities.

However, the absence of nonce checks and capability checks across all entry points (which are zero) is a significant concern, even if the attack surface is currently nil. While taint analysis shows no issues, this is likely due to the lack of identified input vectors. The plugin's vulnerability history is a notable weakness. It has one known CVE, a medium severity Cross-Site Scripting vulnerability from 2017, which is currently unpatched. The fact that a past vulnerability existed, even if addressed by updates (implied by 'currently unpatched: 0'), suggests potential for future discoveries if coding practices are not consistently maintained.

In conclusion, the current code is remarkably clean regarding common static analysis findings. The primary risk lies in the historical presence of a medium-severity XSS vulnerability and the lack of explicit authorization checks, which could become a concern if the plugin's functionality or attack surface expands in future versions or if the existing code is not diligently maintained. The plugin benefits from a clean codebase but is somewhat undermined by its past vulnerability.

Key Concerns

  • Past medium severity XSS vulnerability
  • No nonce checks for entry points
  • No capability checks for entry points
Vulnerabilities
1 published

Analytics Tracker Security Vulnerabilities

CVEs by Year

1 CVE in 2017
2017
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2017-18554medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Analytics Tracker <= 1.1.0 - Cross-Site Scripting

Jun 22, 2017 Patched in 1.1.1 (2406d)
Version History

Analytics Tracker Release Timeline

v3.0.1Current
v3.0.0
v2.0.1
v2.0.0
v1.1.1
v1.1.01 CVE
v1.0.51 CVE
v1.0.41 CVE
v1.0.31 CVE
v1.0.21 CVE
v1.0.11 CVE
v1.0.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Analytics Tracker Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
43 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped43 total outputs
Attack Surface

Analytics Tracker Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actioninitanalytics-tracker.php:49
actionwp_enqueue_scriptsanalytics-tracker.php:55
actionadmin_menuanalytics-tracker.php:58
actionadmin_initanalytics-tracker.php:61
actionadmin_enqueue_scriptsanalytics-tracker.php:64
actionwp_insert_commentanalytics-tracker.php:67
Maintenance & Trust

Analytics Tracker Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 20, 2026
PHP min version
Downloads37K

Community Trust

Rating100/100
Number of ratings2
Active installs1K
Developer Profile

Analytics Tracker Developer Profile

Valeriu Tihai

3 plugins · 1K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
2406 days
View full developer profile
Detection Fingerprints

How We Detect Analytics Tracker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/analytics-tracker/assets/js/backend-script.js/wp-content/plugins/analytics-tracker/assets/css/backend-style.css/wp-content/plugins/analytics-tracker/assets/js/frontend-script.js
Script Paths
https://kinsta.com/plans/?kaid=NDINHGAQXILShttps://i2.wp.com/valeriu.files.wordpress.com/2018/02/kinsta-dark.pnghttps://wordpress.org/support/plugin/analytics-trackerhttps://valeriu.tihai.ca/https://paypal.me/valeriu/25https://www.gnu.org/licenses/gpl-2.0.html+11 more
Version Parameters
analytics-tracker/assets/js/backend-script.js?ver=analytics-tracker/assets/css/backend-style.css?ver=analytics-tracker/assets/js/frontend-script.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Analytics Tracker