Audience Analytics – by Quantcast Security & Risk Analysis

wordpress.org/plugins/audience-analytics-by-quantcast

Provides statistics about visitors to every page of your site: traffic, age, gender, shopping patterns, general interests and much more.

1K active installs v1.0.1 PHP + WP 4.0+ Updated Nov 26, 2018
analyticsaudience-analyticsdemographicsquantcastweb-analytics
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Audience Analytics – by Quantcast Safe to Use in 2026?

Generally Safe

Score 85/100

Audience Analytics – by Quantcast has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "audience-analytics-by-quantcast" plugin version 1.0.1 exhibits a generally positive security posture from a static analysis perspective. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a strong indicator of a well-defined and secured attack surface. Furthermore, the complete absence of dangerous functions, file operations, external HTTP requests, and the exclusive use of prepared statements for SQL queries are excellent security practices.

However, a significant concern arises from the output escaping. With 7 total outputs and 0% properly escaped, this presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any data processed and displayed by this plugin, if not meticulously sanitized on the client-side, could be exploited by attackers to inject malicious scripts. The lack of nonce and capability checks also means that even if entry points were to exist, there might be limited protection against unauthorized actions or data manipulation.

The plugin's vulnerability history is also a strong point, with zero recorded CVEs across all severities. This suggests that the developers have either been diligent in maintaining secure code or the plugin's limited functionality has not attracted widespread vulnerability research. Overall, while the plugin excels in its structured entry points and SQL handling, the critical deficiency in output escaping poses a notable security risk that needs immediate attention.

Key Concerns

  • Unescaped output found
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Audience Analytics – by Quantcast Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Audience Analytics – by Quantcast Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped7 total outputs
Attack Surface

Audience Analytics – by Quantcast Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actioninitaudience-analytics.php:39
actionadmin_menuaudience-analytics.php:44
actionadmin_initaudience-analytics.php:45
actionwp_footeraudience-analytics.php:46
actionadmin_noticesaudience-analytics.php:48
Maintenance & Trust

Audience Analytics – by Quantcast Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedNov 26, 2018
PHP min version
Downloads26K

Community Trust

Rating60/100
Number of ratings2
Active installs1K
Developer Profile

Audience Analytics – by Quantcast Developer Profile

Quantcast

2 plugins · 4K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Audience Analytics – by Quantcast

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/audience-analytics-by-quantcast/assets/logo-black.png

HTML / DOM Fingerprints

CSS Classes
quantcast-plugin-logo
HTML Comments
<!-- Quantcast Tag --><!-- End Quantcast tag -->
Data Attributes
data-setting-name="wp-quantcast_settings"data-setting-value-field="qc-pcode"
JS Globals
_qevents
FAQ

Frequently Asked Questions about Audience Analytics – by Quantcast