Cliredas – Client Dashboard for Google Analytics (GA4) Security & Risk Analysis

wordpress.org/plugins/cliredas-analytics-dashboard

Client-friendly Google Analytics 4 (GA4) dashboard inside wp-admin with real GA4 data, caching, and clear setup steps.

0 active installs v1.0.0 PHP 7.4+ WP 6.0+ Updated Feb 20, 2026
analyticsdashboardga4google-analyticsreporting
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Cliredas – Client Dashboard for Google Analytics (GA4) Safe to Use in 2026?

Generally Safe

Score 100/100

Cliredas – Client Dashboard for Google Analytics (GA4) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The cliredas-analytics-dashboard plugin v1.0.0 exhibits a generally good security posture with a minimal attack surface, consisting of only one AJAX handler with no readily apparent authentication bypass vulnerabilities indicated by the static analysis. The absence of raw SQL queries and a history of zero known CVEs further contribute to its positive security profile. However, a notable concern lies in the output escaping, where only 57% of outputs are properly escaped, leaving a significant portion potentially vulnerable to cross-site scripting (XSS) attacks if user-supplied data is directly rendered without sanitization. While taint analysis shows no critical or high-severity issues, this incomplete output escaping could still be exploited in certain scenarios.

The plugin's strengths include its lack of REST API routes, shortcodes, and cron events, which effectively limits potential entry points. The presence of nonce and capability checks on all identified entry points is also a positive indicator of security consciousness. Despite the promising overall results, the identified weakness in output escaping warrants attention and mitigation to prevent potential XSS vulnerabilities that could arise from unescaped dynamic content.

Key Concerns

  • Unescaped output identified
Vulnerabilities
None known

Cliredas – Client Dashboard for Google Analytics (GA4) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Cliredas – Client Dashboard for Google Analytics (GA4) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
97
127 escaped
Nonce Checks
10
Capability Checks
14
File Operations
0
External Requests
9
Bundled Libraries
0

Output Escaping

57% escaped224 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
render_settings_page (includes\class-cliredas-settings.php:320)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Cliredas – Client Dashboard for Google Analytics (GA4) Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_cliredas_get_reportincludes\class-cliredas-dashboard-page.php:43
WordPress Hooks 15
actionadmin_menuincludes\class-cliredas-admin-menu.php:53
actionadmin_post_cliredas_clear_cacheincludes\class-cliredas-cache-manager.php:28
actionadmin_enqueue_scriptsincludes\class-cliredas-dashboard-page.php:42
actionadmin_post_cliredas_ga4_connectincludes\class-cliredas-ga4-auth.php:35
actionadmin_post_cliredas_ga4_oauth_callbackincludes\class-cliredas-ga4-auth.php:36
actionadmin_post_cliredas_ga4_disconnectincludes\class-cliredas-ga4-auth.php:37
actionadmin_post_cliredas_ga4_clear_secretincludes\class-cliredas-ga4-auth.php:38
filterallowed_redirect_hostsincludes\class-cliredas-ga4-auth.php:100
actionplugins_loadedincludes\class-cliredas-plugin.php:94
actioninitincludes\class-cliredas-plugin.php:95
actioninitincludes\class-cliredas-plugin.php:102
actionadmin_initincludes\class-cliredas-plugin.php:107
actionadmin_initincludes\class-cliredas-settings.php:53
actionadmin_menuincludes\class-cliredas-settings.php:54
actionadmin_enqueue_scriptsincludes\class-cliredas-settings.php:55
Maintenance & Trust

Cliredas – Client Dashboard for Google Analytics (GA4) Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 20, 2026
PHP min version7.4
Downloads113

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Cliredas – Client Dashboard for Google Analytics (GA4) Developer Profile

vzisis

2 plugins · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Cliredas – Client Dashboard for Google Analytics (GA4)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cliredas-analytics-dashboard/assets/css/cliredas-dashboard.css/wp-content/plugins/cliredas-analytics-dashboard/assets/js/cliredas-dashboard.js/wp-content/plugins/cliredas-analytics-dashboard/assets/vendor/chartjs/chart.umd.min.js/wp-content/plugins/cliredas-analytics-dashboard/assets/js/cliredas-settings.js
Version Parameters
cliredas-analytics-dashboard/assets/css/cliredas-dashboard.css?ver=cliredas-analytics-dashboard/assets/js/cliredas-dashboard.js?ver=cliredas-analytics-dashboard/assets/vendor/chartjs/chart.umd.min.js?ver=cliredas-analytics-dashboard/assets/js/cliredas-settings.js?ver=

HTML / DOM Fingerprints

JS Globals
cliredasDashboard
FAQ

Frequently Asked Questions about Cliredas – Client Dashboard for Google Analytics (GA4)