Analytify – Dashboard Widget for Google Analytics Security & Risk Analysis

wordpress.org/plugins/analytify-analytics-dashboard-widget

Google Analytics Dashboard widget is a Free Add-on for Google Analytics by Analytify plugin to show Google Analytics widget at WordPress dashboard.

10K active installs v7.1.2 PHP + WP 4.0+ Updated Feb 27, 2026
analyticsgoogle-analyticsgoogle-analytics-4google-analytics-dashboardwordpress-analytics
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Analytify – Dashboard Widget for Google Analytics Safe to Use in 2026?

Generally Safe

Score 100/100

Analytify – Dashboard Widget for Google Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin "analytify-analytics-dashboard-widget" v7.1.2 presents a mixed security posture. On the positive side, the code analysis reveals excellent practices regarding SQL queries, utilizing prepared statements exclusively. Furthermore, a high percentage of output is properly escaped, and there are no recorded vulnerabilities in its history, suggesting a generally well-maintained codebase. The absence of dangerous functions, file operations, and external HTTP requests also contributes to a safer profile.

However, significant concerns arise from the plugin's attack surface. With two identified entry points, both an AJAX handler and a REST API route lack authentication and permission checks. This is a critical oversight that exposes these functionalities to unauthorized access and potential exploitation. While taint analysis and vulnerability history show no current issues, the unprotected entry points represent a substantial inherent risk that could be exploited by attackers if a vulnerability were to be introduced or discovered.

In conclusion, while the plugin demonstrates good practices in its internal code handling, the exposed, unprotected AJAX and REST API endpoints are a major security weakness. Developers should prioritize implementing robust authentication and capability checks for these entry points to mitigate the risk of unauthorized access and potential compromise. The lack of historical vulnerabilities is a positive indicator, but it does not negate the immediate risks presented by the unprotected attack surface.

Key Concerns

  • AJAX handler without auth checks
  • REST API routes without permission callbacks
Vulnerabilities
None known

Analytify – Dashboard Widget for Google Analytics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Analytify – Dashboard Widget for Google Analytics Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
33 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

97% escaped34 total outputs
Attack Surface
2 unprotected

Analytify – Dashboard Widget for Google Analytics Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 1

authwp_ajax_AnalytifyWidgetAddonclasses\class-analytify-widget-addon.php:120

REST API Routes 1

GET/wp-json/wp-analytify/v1/get_widget_report/(?P<request_type>[a-zA-Z0-9-]+)classes\class-analytify-widget-rest-api.php:102
WordPress Hooks 12
actionadmin_enqueue_scriptsclasses\class-analytify-widget-addon.php:116
actionwp_dashboard_setupclasses\class-analytify-widget-addon.php:117
actionrest_api_initclasses\class-analytify-widget-rest-api.php:88
filteranalytify_widget_formate_general_statisticsclasses\class-analytify-widget-rest-api.php:91
actionadmin_enqueue_scriptswp-analytify-dashboard.php:44
actionadmin_noticeswp-analytify-dashboard.php:47
actionwp_dashboard_setupwp-analytify-dashboard.php:48
actionadmin_noticeswp-analytify-dashboard.php:53
actionwp_dashboard_setupwp-analytify-dashboard.php:54
actionplugins_loadedwp-analytify-dashboard.php:61
actionadmin_enqueue_scriptswp-analytify-dashboard.php:289
actionadmin_headwp-analytify-dashboard.php:313
Maintenance & Trust

Analytify – Dashboard Widget for Google Analytics Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 27, 2026
PHP min version
Downloads479K

Community Trust

Rating100/100
Number of ratings4
Active installs10K
Developer Profile

Analytify – Dashboard Widget for Google Analytics Developer Profile

Adnan

11 plugins · 660K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
526 days
View full developer profile
Detection Fingerprints

How We Detect Analytify – Dashboard Widget for Google Analytics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/analytify-analytics-dashboard-widget/assets/js/wp-analytify-dashboard-layout.js
Script Paths
/wp-content/plugins/analytify-analytics-dashboard-widget/assets/js/wp-analytify-dashboard-layout.js
Version Parameters
analytify-analytics-dashboard-widget/assets/js/wp-analytify-dashboard-layout.js?ver=

HTML / DOM Fingerprints

CSS Classes
analytify-active-card-button
FAQ

Frequently Asked Questions about Analytify – Dashboard Widget for Google Analytics