
JSON-LD Schema for Yandex Metrica Security & Risk Analysis
wordpress.org/plugins/antoniolite-yandex-metrica-json-ld-schemaInsert the needed JSON-LD Schema in your post pages so you can use the content reports in Yandex Metrica
Is JSON-LD Schema for Yandex Metrica Safe to Use in 2026?
Generally Safe
Score 100/100JSON-LD Schema for Yandex Metrica has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "antoniolite-yandex-metrica-json-ld-schema" v1.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points indicates a minimal attack surface. Furthermore, the code signals show no dangerous functions, no direct SQL queries (all using prepared statements), and no file operations, all of which are positive security indicators. The plugin also avoids bundled libraries and shows no taint analysis findings, suggesting a lack of common vulnerabilities related to data flow manipulation.
However, a significant concern arises from the output escaping. With 31 total outputs and only 19% properly escaped, a substantial portion of the plugin's output is at risk of Cross-Site Scripting (XSS) vulnerabilities. While there are no identified vulnerabilities in its history, this lack of historical issues might be due to its relatively simple functionality or a lack of prior thorough analysis rather than inherent invulnerability. The plugin also performs an external HTTP request, which, while not inherently a vulnerability, warrants review for secure implementation to prevent potential man-in-the-middle attacks or data exfiltration if the external endpoint is compromised.
In conclusion, while the plugin demonstrates good practices in limiting its attack surface and avoiding risky coding patterns like raw SQL, the low rate of proper output escaping is a critical weakness that needs immediate attention. The presence of an external HTTP request also adds a minor point of concern. The absence of historical vulnerabilities is a positive sign, but it should not overshadow the identified risks in the static analysis.
Key Concerns
- Low percentage of properly escaped output
- External HTTP request made
JSON-LD Schema for Yandex Metrica Security Vulnerabilities
JSON-LD Schema for Yandex Metrica Code Analysis
Output Escaping
JSON-LD Schema for Yandex Metrica Attack Surface
WordPress Hooks 4
Maintenance & Trust
JSON-LD Schema for Yandex Metrica Maintenance & Trust
Maintenance Signals
Community Trust
JSON-LD Schema for Yandex Metrica Alternatives
DCO Insert Analytics Code
dco-insert-analytics-code
Allows you to insert analytics code before </head> or after <body> or before </body>
Komito Analytics
komito-analytics
Komito Analytics is a free, open-source enhancement for the most popular web analytics software.
Multi Counter
multi-counter
This plugin allows you to add four counters on the site: Google Analytics, Yandex Metrics, StatCounter, Openstat!
Yandex Metrica
yandex-metrica
Easy way to use Yandex Metrica on your WordPress site.
Яндекс Метрика
yandex-metrika
Яндекс Метрика для вашего сайта на WordPress.
JSON-LD Schema for Yandex Metrica Developer Profile
2 plugins · 10 total installs
How We Detect JSON-LD Schema for Yandex Metrica
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/antoniolite-yandex-metrica-json-ld-schema/css/admin.css/wp-content/plugins/antoniolite-yandex-metrica-json-ld-schema/js/admin.jsHTML / DOM Fingerprints
<!-- JSON-LD Schema for Yandex Metrica -->