AnyComment Analytics Security & Risk Analysis

wordpress.org/plugins/anycomment-analytics

AnyComment Analytics is a premium advanced analytics for AnyComment.

40 active installs v0.2 PHP 5.4+ WP 4.4+ Updated Dec 25, 2019
analyticsanycommentanycomment-analyticscomment-analytics
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AnyComment Analytics Safe to Use in 2026?

Generally Safe

Score 85/100

AnyComment Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "anycomment-analytics" v0.2 plugin exhibits a concerning security posture due to a significant number of unprotected entry points. While the plugin demonstrates good practices in its handling of SQL queries by exclusively using prepared statements and not making external HTTP requests, the lack of authentication and capability checks on its AJAX handler and REST API route creates a substantial attack surface. The taint analysis reveals a flow with unsanitized paths, which, although not classified as critical or high severity, still points to a potential risk of sensitive data being exposed or manipulated if an attacker can trigger this flow.

The plugin's vulnerability history is a positive sign, showing no known CVEs. This suggests that past versions have been relatively secure. However, the current version's analysis highlights immediate concerns that overshadow the historical lack of vulnerabilities. The combination of unprotected endpoints and the identified unsanitized taint flow presents a clear and present risk that needs to be addressed to prevent potential exploitation.

Key Concerns

  • Unprotected AJAX handler
  • Unprotected REST API route
  • Flows with unsanitized paths
  • Low output escaping percentage
  • No nonce checks on AJAX
  • No capability checks
Vulnerabilities
None known

AnyComment Analytics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

AnyComment Analytics Release Timeline

v0.2.1
v0.2Current
Code Analysis
Analyzed Apr 16, 2026

AnyComment Analytics Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
53 prepared
Unescaped Output
56
18 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared53 total queries

Output Escaping

24% escaped74 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<graphs> (templates/graphs.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

AnyComment Analytics Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 1

authwp_ajax_anycomment_analytics_send_reportincludes/Ajax/AnyCommentAnalyticsAjaxReport.php:21

REST API Routes 1

GET/wp-json/anycomment-analytics/v1/chartanycomment-analytics.php:157
WordPress Hooks 8
actionanycomment/loadedanycomment-analytics.php:61
actionadmin_enqueue_scriptsanycomment-analytics.php:63
filteranycomment/admin/tabsanycomment-analytics.php:146
actionrest_api_initanycomment-analytics.php:156
filtercron_schedulesincludes/Cron/AnyCommentAnalyticsReport.php:29
actioninitincludes/Cron/AnyCommentAnalyticsReport.php:31
actionanycomment_analytics_queue_reportincludes/Cron/AnyCommentAnalyticsReport.php:33
actionwp_set_comment_statusincludes/Hooks/AnyCommentAnalyticComment.php:18

Scheduled Events 1

anycomment_analytics_queue_report
Maintenance & Trust

AnyComment Analytics Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedDec 25, 2019
PHP min version5.4
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs40
Developer Profile

AnyComment Analytics Developer Profile

Alexander

3 plugins · 3K total installs

52
trust score
Avg Security Score
62/100
Avg Patch Time
1062 days
View full developer profile
Detection Fingerprints

How We Detect AnyComment Analytics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/anycomment-analytics/assets/js/charts.js/wp-content/plugins/anycomment-analytics/assets/js/common.js/wp-content/plugins/anycomment-analytics/assets/scss/core.css/wp-content/plugins/anycomment-analytics/assets/css/jquery-ui.css
Script Paths
/wp-content/plugins/anycomment-analytics/assets/js/charts.js/wp-content/plugins/anycomment-analytics/assets/js/common.js
Version Parameters
anycomment-analytics/assets/js/charts.js?ver=anycomment-analytics/assets/js/common.js?ver=anycomment-analytics/assets/scss/core.css?ver=anycomment-analytics/assets/css/jquery-ui.css?ver=

HTML / DOM Fingerprints

Data Attributes
data-widget-iddata-widget-typedata-widget-titledata-widget-data
JS Globals
anycommentAnalytics
REST Endpoints
/wp-json/anycomment-analytics/v1/chart
FAQ

Frequently Asked Questions about AnyComment Analytics