
Analytics by BestWebSoft – Google Analytics Dashboard and Statistic Plugin for WordPress Security & Risk Analysis
wordpress.org/plugins/bws-google-analyticsAdd Google Analytics code to WordPress website and track basic stats.
Is Analytics by BestWebSoft – Google Analytics Dashboard and Statistic Plugin for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100Analytics by BestWebSoft – Google Analytics Dashboard and Statistic Plugin for WordPress has a strong security track record. Known vulnerabilities have been patched promptly.
The bws-google-analytics plugin version 2.0 exhibits a generally strong security posture based on the static analysis. The plugin has a small attack surface with all identified entry points (AJAX handlers) protected by authentication checks. The code demonstrates good practices with a high percentage of properly escaped output and a healthy number of nonce and capability checks. The absence of critical or high-severity taint flows, as well as unsanitized paths, further indicates a focus on secure coding.
However, there are a few areas that warrant attention. While the percentage of SQL queries using prepared statements is 50%, this still means half of the queries are not properly protected against SQL injection if the inputs feeding them are not rigorously sanitized elsewhere. The presence of 2 file operations, while not inherently insecure, represents a potential avenue for manipulation if not handled with extreme care. The plugin's vulnerability history shows one past medium-severity cross-site scripting (XSS) vulnerability, though it is currently patched. This indicates that while the developers have addressed past issues, historical vulnerabilities can sometimes resurface or lead to similar types of weaknesses if not thoroughly mitigated.
In conclusion, bws-google-analytics v2.0 is in a relatively good security state with robust protections on its exposed interfaces. The main areas for improvement lie in ensuring all SQL queries are prepared and maintaining vigilance against potential XSS vulnerabilities, even with a good track record of addressing them. The use of a bundled library like Guzzle also requires ongoing monitoring for any security advisories related to it.
Key Concerns
- SQL queries not using prepared statements
- Past medium severity XSS vulnerability
Analytics by BestWebSoft – Google Analytics Dashboard and Statistic Plugin for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Analytics <= 1.7.0 - Multiple Cross-Site Scripting
Analytics by BestWebSoft – Google Analytics Dashboard and Statistic Plugin for WordPress Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Analytics by BestWebSoft – Google Analytics Dashboard and Statistic Plugin for WordPress Attack Surface
AJAX Handlers 3
WordPress Hooks 19
Maintenance & Trust
Analytics by BestWebSoft – Google Analytics Dashboard and Statistic Plugin for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Analytics by BestWebSoft – Google Analytics Dashboard and Statistic Plugin for WordPress Alternatives
ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin)
google-analytics-dashboard-for-wp
Connects Google Analytics with your WordPress site. Displays stats to help you understand your users and site content on a whole new level!
GAinWP Google Analytics Integration for WordPress
ga-in
Enable Google Analytics tracking and reporting dashboards in your WordPress site in just seconds.
Lara's Google Analytics (GA4)
lara-google-analytics
Full width Google Analytics dashboard widget for Wordpress admin interface, which also inserts latest Google Analytics (GA4) tracking code to your pag …
Analytics Cat – Google Analytics Made Easy
analytics-cat
Analytics Cat - Google Analytics Lets You Add Your Google Analytics / Universal Analytics Tracking Code To Your Site With Ease.
HT Easy GA4 – Google Analytics WordPress Plugin
ht-easy-google-analytics
HT Easy GA4 - Google Analytics WordPress Plugin enables tracking user behavior and viewing Google Analytics dashboard reports from your website.
Analytics by BestWebSoft – Google Analytics Dashboard and Statistic Plugin for WordPress Developer Profile
32 plugins · 17K total installs
How We Detect Analytics by BestWebSoft – Google Analytics Dashboard and Statistic Plugin for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bws-google-analytics/js/gglnltcs-admin-scripts.js/wp-content/plugins/bws-google-analytics/js/gglnltcs-frontend-scripts.js/wp-content/plugins/bws-google-analytics/css/gglnltcs-admin-styles.csshttps://www.googletagmanager.com/gtag/js?id=bws-google-analytics/css/gglnltcs-admin-styles.css?ver=bws-google-analytics/js/gglnltcs-admin-scripts.js?ver=bws-google-analytics/js/gglnltcs-frontend-scripts.js?ver=HTML / DOM Fingerprints
gglnltcs-settings-tabsgglnltcs-analytics-settings-contentgglnltcs-main-navigationgglnltcs-wrapgglnltcs-admin-wrap© Copyright 2021 BestWebSoft ( https://support.bestwebsoft.com )data-gglnltcs-tracking-iddata-gglnltcs-property-idsgglnltcs_datagglnltcs_optionsdataLayer