
Clicky by Yoast Security & Risk Analysis
wordpress.org/plugins/clickyIntegrates the Clicky web analytics service into your blog and adds features for comment tracking & more.
Is Clicky by Yoast Safe to Use in 2026?
Generally Safe
Score 85/100Clicky by Yoast has a strong security track record. Known vulnerabilities have been patched promptly.
The "clicky" plugin v2.0 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified entry points without authentication checks, coupled with all SQL queries using prepared statements, are significant strengths. The plugin also shows good practices in output escaping, with a high percentage of outputs being properly handled. However, a notable concern is the complete lack of nonce checks, which can be a critical security measure for preventing CSRF attacks, especially if any user-initiated actions were present. The external HTTP requests, while not inherently a vulnerability, warrant attention as they could be a vector for attack if not properly validated or secured against certain types of attacks. The plugin's vulnerability history, while dated, shows a past issue with Cross-site Scripting, indicating that input sanitization is an area that requires ongoing diligence. Overall, the current version appears well-secured against common direct attack vectors, but the absence of nonce checks is a notable weakness. It is crucial to ensure that any future updates address the potential risks associated with external requests and maintain the current high standards for input sanitization and output escaping.
Key Concerns
- Missing nonce checks
- External HTTP requests present
- Past XSS vulnerability history
Clicky by Yoast Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Clicky by Yoast <= 1.5 - Stored Cross-Site Scripting
Clicky by Yoast Code Analysis
Output Escaping
Clicky by Yoast Attack Surface
WordPress Hooks 14
Maintenance & Trust
Clicky by Yoast Maintenance & Trust
Maintenance Signals
Community Trust
Clicky by Yoast Alternatives
Clicky Analytics
clicky-analytics
This plugin will display Clicky Web Analytics data and statistics inside your WordPress Administration Dashboard.
Easy ToolBox
easy-toolbox
This plugin is simple, all in one and really simplifies your life (SEO, Social networks, Google adsense, GetClicky, button +1, plusone, plus one, Twit …
Clicky Frontend Stats
frontend-stats-for-clicky
It enables you to use a shortcode that looks like this: [clickystats siteid="" sitekey=""] All you have to do is fill out you …
GA Google Analytics – Connect Google Analytics to WordPress
ga-google-analytics
Adds Google Analytics tracking code to your WordPress site. Supports many tracking features.
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)
burst-statistics
Analytics you'll actually use. Privacy-friendly, zero config, and designed to be actionable. Get insights, not just raw data.
Clicky by Yoast Developer Profile
8 plugins · 9K total installs
How We Detect Clicky by Yoast
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/clicky/css/dist/clicky_admin.css/wp-content/plugins/clicky/js/admin.min.jsjs/admin.min.jsclicky_admin.css?ver=admin.min.js?ver=HTML / DOM Fingerprints
yoast_boxinsideyoast Clicky Web Analytics - https://clicky.com, WordPress Plugin by Yoast - https://yoast.com/wordpress/plugins/clicky/ Clicky tracking not shown because you're an administrator andyoast_i18n