
Apollo Site Tools Security & Risk Analysis
wordpress.org/plugins/apollo-site-toolsEasily add Google Analytics, Facebook Pixel, and other tracking codes to your WordPress site, plus contact form functionality and more.
Is Apollo Site Tools Safe to Use in 2026?
Generally Safe
Score 92/100Apollo Site Tools has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "apollo-site-tools" plugin v3.0 demonstrates a generally good security posture with several positive indicators. Notably, there are no known CVEs in its history, suggesting a history of stable and secure development or that vulnerabilities, if any, have been promptly addressed. The plugin also shows a strong emphasis on security checks, with nonce checks and capability checks present on its entry points. However, the code analysis reveals areas for improvement. While the presence of prepared statements is good, 71% of SQL queries are not using them, which can be a significant risk if not handled with extreme care. Furthermore, 34% of output escaping is not properly handled, posing a potential cross-site scripting (XSS) risk. The single file operation also warrants attention, as it could be a vector for unauthorized file modifications if not secured properly.
Despite the absence of critical taint flows and dangerous functions, the percentage of unescaped outputs and non-prepared SQL queries are the primary concerns. The plugin's attack surface is relatively small, and all identified entry points appear to have authentication checks, which is a significant strength. The lack of external HTTP requests is also a positive sign, reducing the risk of supply chain attacks or compromised external dependencies. In conclusion, while "apollo-site-tools" v3.0 has a clean vulnerability history and implements some good security practices, the unaddressed SQL queries and output escaping present tangible risks that should be mitigated to further harden the plugin's security.
Key Concerns
- SQL queries not using prepared statements
- Output not properly escaped
Apollo Site Tools Security Vulnerabilities
Apollo Site Tools Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Apollo Site Tools Attack Surface
AJAX Handlers 1
Shortcodes 3
WordPress Hooks 11
Maintenance & Trust
Apollo Site Tools Maintenance & Trust
Maintenance Signals
Community Trust
Apollo Site Tools Alternatives
Insert Headers And Footers
wp-headers-and-footers
Include inline javascript, stylesheets, CSS code or anything you want in Header and Footer areas of your WordPress with ease.
Pixel Manager for WooCommerce – Conversion Tracking, Google Ads, GA4, TikTok, Dynamic Remarketing
woocommerce-google-adwords-conversion-tracking-tag
Conversion tracking for WooCommerce. Google Ads, GA4, Meta/Facebook Pixel, TikTok & more. Recover 30% more conversions with server-side tracking!
Tag Manager – Header, Body And Footer
tag-manager-header-body-footer
Simple plugin that allow you add head, body and footer codes for google tag manager, analytics & facebook pixel codes.
Controls for Contact Form 7 (Redirects, Analytics & Tracking)
contact-form-7-extras
Analytics, tracking, redirects and storage for Contact Form 7.
Conversios: Google Analytics (GA4), Google Ads, Conversion and Analytics Tracking for Multi-Channels
enhanced-e-commerce-for-woocommerce-store
Track GA4 Analytics, Google Ads, Microsoft Ads, & Conversion with server-side tracking (CAPI) & product feed to improve ROAS, reports for WooCommerce.
Apollo Site Tools Developer Profile
1 plugin · 10 total installs
How We Detect Apollo Site Tools
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/apollo-site-tools/js/apollo-admin.js/wp-content/plugins/apollo-site-tools/js/apollo-frontend.js/wp-content/plugins/apollo-site-tools/css/apollo-frontend.css/wp-content/plugins/apollo-site-tools/js/apollo-admin.js/wp-content/plugins/apollo-site-tools/js/apollo-frontend.js/wp-content/plugins/apollo-site-tools/js/apollo-admin.js?ver=/wp-content/plugins/apollo-site-tools/js/apollo-frontend.js?ver=/wp-content/plugins/apollo-site-tools/css/apollo-frontend.css?ver=HTML / DOM Fingerprints
apollo-site-tools-custom-cssApollo Site Tools Contact FormApollo Site Tools Instagram FeedApollo Site Tools Include Fileapollo_frontend_params/wp-json/apollo-site-tools/v1/get_instagram_posts[apollo_form][apollo_instagram_feed][include_file]