
CP Analytics pro Security & Risk Analysis
wordpress.org/plugins/cp-analytics-prokeywords, Page Referrals, demographics, bounce rate, SEO, conversions, Analytics Plugin, browser sources, Audience Overview, Authentication, Tracking …
Is CP Analytics pro Safe to Use in 2026?
Generally Safe
Score 85/100CP Analytics pro has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'cp-analytics-pro' v1.0.0 exhibits significant security weaknesses, primarily stemming from its unprotected AJAX handlers and the presence of dangerous functions without adequate security measures. While the plugin boasts zero known CVEs and uses prepared statements for SQL queries, these strengths are overshadowed by critical concerns in its attack surface and code handling.
The static analysis reveals a concerning lack of authorization checks on all three identified AJAX entry points, making them highly susceptible to unauthorized access and execution of potentially malicious actions. The use of the `unserialize` function, a known risk if not handled with extreme caution and strict input validation, is also a red flag, especially when combined with the identified unsanitized flows from taint analysis. Furthermore, the complete absence of proper output escaping for all identified outputs means that any data processed and displayed by the plugin could be vulnerable to cross-site scripting (XSS) attacks.
Despite the lack of historical vulnerabilities, which might suggest a currently clean record, this does not negate the inherent risks identified in the current codebase. The absence of nonces on AJAX handlers and the limited capability checks further compound the security issues. The outdated bundled libraries also present potential entry points for attackers. In conclusion, while the plugin has some positive aspects like prepared SQL statements, its overall security posture is poor due to critical vulnerabilities in its attack surface, input sanitization, and output handling.
Key Concerns
- Unprotected AJAX handlers
- Dangerous function 'unserialize' used
- No output escaping
- Unsanitized flows from taint analysis
- No nonce checks on AJAX
- Bundled outdated library: Select2 v3.4.8
- Bundled library: DataTables
- Bundled library: Guzzle
CP Analytics pro Security Vulnerabilities
CP Analytics pro Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Data Flow Analysis
CP Analytics pro Attack Surface
AJAX Handlers 3
WordPress Hooks 5
Maintenance & Trust
CP Analytics pro Maintenance & Trust
Maintenance Signals
Community Trust
CP Analytics pro Alternatives
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)
google-analytics-for-wordpress
The best free Google Analytics plugin for WordPress. See how visitors find and use your website so you can grow your business with powerful analytics.
ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin)
google-analytics-dashboard-for-wp
Connects Google Analytics with your WordPress site. Displays stats to help you understand your users and site content on a whole new level!
Independent Analytics – Google Analytics Alternative for WordPress
independent-analytics
A simple WordPress analytics plugin that is privacy-friendly, fast, and an alternative to Google Analytics.
Beehive Analytics – Google Analytics Dashboard
beehive-analytics
View visitor stats and track user behavior from within WordPress. A Google Analytics plugin with dashboard reports and Google Tag Manager support.
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking)
wp-analytify
Analytify is the must-have Plugin for Google Analytics 4 Integration, Tracking, & Reporting in WordPress. Enhanced eCommerce, Events, & Call Analytics
CP Analytics pro Developer Profile
3 plugins · 120 total installs
How We Detect CP Analytics pro
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cp-analytics-pro/assets/css/cp-analytics-pro.css/wp-content/plugins/cp-analytics-pro/assets/js/modernizr.custom.js/wp-content/plugins/cp-analytics-pro/assets/js/select2.js/wp-content/plugins/cp-analytics-pro/assets/js/custom.js/wp-content/plugins/cp-analytics-pro/assets/js/chart.js/wp-content/plugins/cp-analytics-pro/assets/js/bootstrap.min.js/wp-content/plugins/cp-analytics-pro/classes/gap_dashboard.php/wp-content/plugins/cp-analytics-pro/classes/gap_option_settings.phpassets/js/modernizr.custom.jsassets/js/select2.jsassets/js/custom.jsassets/js/chart.jsassets/js/bootstrap.min.jscp-analytics-pro/assets/css/cp-analytics-pro.css?ver=1.0.0cp-analytics-pro/assets/js/modernizr.custom.js?ver=1.0.0cp-analytics-pro/assets/js/select2.js?ver=1.0.0cp-analytics-pro/assets/js/custom.js?ver=1.0.0cp-analytics-pro/assets/js/chart.js?ver=1.0.0cp-analytics-pro/assets/js/bootstrap.min.js?ver=1.0.0HTML / DOM Fingerprints
nav-tab-wrappernav-tabnav-tab-activenavnav-tabsactivefa-cogdata-toggledata-targetcpa_global_data/wp-json/cp-analytics-pro/v1/settings