Data Insights – Analytics SDK for WordPress Plugin Developers Security & Risk Analysis

wordpress.org/plugins/data-collector-insights

Analytics SDK for WordPress plugin developers. Track user behavior, analyze competitors, boost conversions. 2-line integration.

0 active installs v1.6.0 PHP 7.4+ WP 5.5+ Updated Aug 24, 2025
competitor-analysisplugin-analyticsplugin-insightsplugin-metricswordpress-sdk
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Data Insights – Analytics SDK for WordPress Plugin Developers Safe to Use in 2026?

Generally Safe

Score 100/100

Data Insights – Analytics SDK for WordPress Plugin Developers has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The data-collector-insights plugin v1.6.0 demonstrates a generally good security posture with several strong points. The plugin effectively uses prepared statements for the majority of its SQL queries and has a high percentage of properly escaped output, indicating an awareness of common web vulnerabilities. Furthermore, the absence of any known CVEs or recorded vulnerabilities, coupled with the lack of critical or high severity taint flows, suggests a mature and relatively secure codebase. The plugin also avoids bundling external libraries, which can often introduce their own security risks.

However, there are notable areas for concern that detract from its overall security. The presence of 3 AJAX handlers without authentication checks represents a significant attack surface. These unprotected entry points could potentially be leveraged for unauthorized actions if not properly secured at the application level. While the plugin performs some capability checks, the lack of these on a subset of its AJAX handlers is a missed opportunity for robust access control.

In conclusion, data-collector-insights v1.6.0 is a plugin with a solid foundation in secure coding practices, particularly regarding SQL and output handling. Its clean vulnerability history is a positive sign. The primary weakness lies in the exposed AJAX endpoints, which should be addressed to achieve a more secure and robust implementation. A focused effort to implement proper nonce and capability checks on these handlers would significantly mitigate the identified risks.

Key Concerns

  • Unprotected AJAX handlers
  • SQL queries without prepared statements
  • Output not properly escaped
Vulnerabilities
None known

Data Insights – Analytics SDK for WordPress Plugin Developers Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Data Insights – Analytics SDK for WordPress Plugin Developers Code Analysis

Dangerous Functions
0
Raw SQL Queries
26
72 prepared
Unescaped Output
16
147 escaped
Nonce Checks
13
Capability Checks
11
File Operations
0
External Requests
3
Bundled Libraries
0

SQL Query Safety

73% prepared98 total queries

Output Escaping

90% escaped163 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
dci_sdk_insights (dci\insights.php:567)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

Data Insights – Analytics SDK for WordPress Plugin Developers Attack Surface

Entry Points8
Unprotected3

AJAX Handlers 8

authwp_ajax_dci_sdk_insightsdci\insights.php:40
authwp_ajax_dci_sdk_dismiss_noticedci\insights.php:41
authwp_ajax_dci_sdk_insights_deactivate_feedbackdci\insights.php:42
authwp_ajax_dci_add_apikeyincludes\Admin\Classes\class-api.php:36
authwp_ajax_dci_render_api_key_by_idincludes\Admin\Classes\class-api.php:41
authwp_ajax_dci_update_api_keyincludes\Admin\Classes\class-api.php:46
authwp_ajax_dci_render_apiincludes\Admin\Classes\class-api.php:51
authwp_ajax_dci_delete_api_by_idincludes\Admin\Classes\class-api.php:56
WordPress Hooks 23
actioninitdata-collector-insights.php:58
actioninitdata-collector-insights.php:94
actionadmin_initdata-collector-insights.php:148
actionadmin_enqueue_scriptsdci\insights.php:207
actionadmin_noticesdci\insights.php:215
actionadmin_noticesdci\insights.php:227
actionin_admin_headerdci\insights.php:233
actionadmin_enqueue_scriptsdci\insights.php:261
actionin_admin_headerdci\insights.php:270
actionadmin_menuincludes\Admin\class-menu.php:29
actionrest_api_initincludes\Admin\Classes\class-clients.php:32
actionrest_api_initincludes\Admin\Classes\class-dashboard.php:35
actionrest_api_initincludes\Admin\Classes\class-plugin-usage.php:31
actionrest_api_initincludes\Admin\Classes\class-products.php:47
actionrest_api_initincludes\Admin\Classes\class-query-builder.php:76
actionrest_api_initincludes\Admin\Classes\class-settings.php:37
actionrest_api_initincludes\Admin\Classes\class-theme-usage.php:31
filtercron_schedulesincludes\Classes\class-crm.php:50
filterwp_kses_allowed_htmlincludes\Classes\class-input.php:247
actionrest_api_initincludes\public\class-api.php:24
filteradmin_body_classplugin.php:31
actionadmin_enqueue_scriptsplugin.php:92
actionadmin_enqueue_scriptsplugin.php:93
Maintenance & Trust

Data Insights – Analytics SDK for WordPress Plugin Developers Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 24, 2025
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Alternatives

Data Insights – Analytics SDK for WordPress Plugin Developers Alternatives

No alternatives data available yet.

Developer Profile

Data Insights – Analytics SDK for WordPress Plugin Developers Developer Profile

wowDevs

7 plugins · 2K total installs

99
trust score
Avg Security Score
98/100
Avg Patch Time
6 days
View full developer profile
Detection Fingerprints

How We Detect Data Insights – Analytics SDK for WordPress Plugin Developers

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/data-collector-insights/dci/assets/css/dci.css
Version Parameters
dci-sdk-wd

HTML / DOM Fingerprints

Data Attributes
data-dci-feedback-nonce
JS Globals
dci_dynamic_initdci_sdk_initwp_localize_script
REST Endpoints
/wp-json/dci/v1/data-insights
FAQ

Frequently Asked Questions about Data Insights – Analytics SDK for WordPress Plugin Developers