
CTCL Analytics Security & Risk Analysis
wordpress.org/plugins/ctcl-analyticsCT Commerce Lite addon to display store analytics
Is CTCL Analytics Safe to Use in 2026?
Generally Safe
Score 100/100CTCL Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ctcl-analytics" v1.1.0 plugin presents a generally positive security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength. Furthermore, the plugin demonstrates good practices by using prepared statements for all SQL queries and performing no external HTTP requests or file operations, which mitigates common attack vectors.
However, a notable concern lies in the output escaping, where only 25% of outputs are properly escaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, especially if sensitive data is handled and displayed without adequate sanitization. The lack of any recorded vulnerability history, while positive, also means there's no historical data to gauge past security diligence or patterns.
In conclusion, while the plugin has strong defenses against many common WordPress vulnerabilities due to its limited attack surface and secure data handling for SQL and external requests, the insufficient output escaping is a clear area of risk. This weakness could be exploited to inject malicious scripts into the website, impacting users or administrators.
Key Concerns
- Insufficient output escaping
CTCL Analytics Security Vulnerabilities
CTCL Analytics Code Analysis
SQL Query Safety
Output Escaping
CTCL Analytics Attack Surface
WordPress Hooks 4
Maintenance & Trust
CTCL Analytics Maintenance & Trust
Maintenance Signals
Community Trust
CTCL Analytics Alternatives
CTCL Floating Cart
ctcl-floating-cart
🚀 Floating Cart for CT Commerce Lite 🛒
CTCL Phone Pay
ctcl-phone-pay
CTC Lite add-on to charge customer with phone call
WooCommerce
woocommerce
Everything you need to launch an online store in days and keep it growing for years. From your first sale to millions in revenue, Woo is with you.
Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation
optinmonster
🤩 Make popups & optin forms to get more email newsletter subscribers, leads, and sales - #1 most popular popup builder plugin! 🚀
WooCommerce PayPal Payments
woocommerce-paypal-payments
PayPal's latest payment processing solution. Accept PayPal, Pay Later, credit/debit cards, alternative digital wallets and bank accounts.
CTCL Analytics Developer Profile
17 plugins · 2K total installs
How We Detect CTCL Analytics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ctcl-analytics/css/analytics.css/wp-content/plugins/ctcl-analytics/js/chart.js/wp-content/plugins/ctcl-analytics/js/analytics.js/wp-content/plugins/ctcl-analytics/js/chart.js/wp-content/plugins/ctcl-analytics/js/analytics.jsHTML / DOM Fingerprints
ctcl-analytics-tab-mainctcl-basic-info-headerctcl-analytics-tabctclAChartctcla-sales-exportctclASalesctcla-export-csvctclAnalyticsObjectcustom/v1/create-csv/<h3 class=" dashicons-before dashicons-chart-line ctcl-basic-info-header">Store Analytics</h3>