
DanP Google Analytics Pageview Sync Security & Risk Analysis
wordpress.org/plugins/danp-google-analytics-pageview-syncSync pageview data from Google Analytics to your WordPress Database, enabling you to sort posts, view pageview data in the WordPress Dashboard, and ou …
Is DanP Google Analytics Pageview Sync Safe to Use in 2026?
Generally Safe
Score 85/100DanP Google Analytics Pageview Sync has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The danp-google-analytics-pageview-sync plugin, version 1.0.1, exhibits a generally positive security posture with some notable concerns. The absence of known CVEs and the plugin's limited attack surface, with only one shortcode and no unprotected entry points, are strong indicators of good development practices. Furthermore, all SQL queries are properly prepared, and the majority of output is escaped, mitigating common web vulnerabilities.
However, the static analysis reveals potential risks. The presence of the `move_uploaded_file` function, while not explicitly shown to be vulnerable in this analysis, represents a high-risk operation if not carefully managed. The taint analysis, although reporting no critical or high severity flows, did identify three flows with unsanitized paths. This suggests a potential for path traversal vulnerabilities if these paths are user-supplied or not properly validated before being used in file operations.
In conclusion, the plugin benefits from a clean vulnerability history and a focused attack surface. The key areas for improvement lie in the careful sanitization of paths used in file operations and a review of how `move_uploaded_file` is implemented to ensure it does not become a vector for malicious activity. While no immediate critical vulnerabilities are apparent, these identified code signals warrant further investigation.
Key Concerns
- Unsanitized paths in taint flows
- Dangerous function move_uploaded_file used
- Missing nonce checks
- Missing capability checks
- Output escaping is not 100%
DanP Google Analytics Pageview Sync Security Vulnerabilities
DanP Google Analytics Pageview Sync Release Timeline
DanP Google Analytics Pageview Sync Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Data Flow Analysis
DanP Google Analytics Pageview Sync Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
DanP Google Analytics Pageview Sync Maintenance & Trust
Maintenance Signals
Community Trust
DanP Google Analytics Pageview Sync Alternatives
Weblix – Online Users
weblix
Display online users and page views in the last 30 minutes, just like Google Analytics, but without slowing down your website.
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)
google-analytics-for-wordpress
The best free Google Analytics plugin for WordPress. See how visitors find and use your website so you can grow your business with powerful analytics.
GTM4WP – A Google Tag Manager (GTM) plugin for WordPress
duracelltomi-google-tag-manager
Advanced tag management for WordPress with Google Tag Manager
WP Statistics – Simple, privacy-friendly Google Analytics alternative
wp-statistics
Get website traffic insights with GDPR/CCPA compliant, privacy-friendly analytics. Includes visitor data, stunning graphs, and no data sharing.
PixelYourSite – Your smart PIXEL (TAG) & API Manager
pixelyoursite
Add Meta Pixel with Conversion API, Google Analytics (GA4) + Consent Mode, Google Tag Manager, and Head & Footer scripts.
DanP Google Analytics Pageview Sync Developer Profile
2 plugins · 0 total installs
How We Detect DanP Google Analytics Pageview Sync
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/danp-google-analytics-pageview-sync/google-api-php-client-PHP8/vendor/autoload.phpHTML / DOM Fingerprints
post_meta_key='danp-dot-net-ga-page-views'danp-ga-pageviews