
Divvit e-commerce analytics Security & Risk Analysis
wordpress.org/plugins/divvit-ecommerce-analyticsDivvit e-commerce analytics tool presents insights in dashboards and KPIs to boost your shop's performance.
Is Divvit e-commerce analytics Safe to Use in 2026?
Generally Safe
Score 85/100Divvit e-commerce analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'divvit-ecommerce-analytics' plugin version 1.0.4 exhibits a mixed security posture. On the positive side, there are no known vulnerabilities in its history, indicating a generally well-maintained codebase. The absence of external HTTP requests and dangerous functions is also a good sign. However, the static analysis reveals significant areas of concern. The fact that 100% of the 27 identified output points are not properly escaped poses a high risk of Cross-Site Scripting (XSS) vulnerabilities. Additionally, the taint analysis shows two flows with unsanitized paths, even though they are not categorized as critical or high severity, these represent potential risks that require investigation. The plugin also lacks any nonces or capability checks, which, combined with the identified unsanitized paths, could allow for unauthorized actions if these paths were exploitable.
While the plugin has a clean vulnerability history and a small attack surface, the lack of output escaping is a critical weakness that could be exploited by attackers to inject malicious scripts into the website. The unsanitized taint flows, though not currently rated as severe, should not be overlooked and could potentially become exploitable in future versions or in combination with other weaknesses. The absence of any authentication or authorization checks on entry points (AJAX, REST API, shortcodes, cron events) is concerning, especially given the taint flow issues, as it means any potential vulnerability could be accessed without any prior authentication. This plugin requires immediate attention to address the unescaped outputs and investigate the unsanitized taint flows to ensure a secure environment.
Key Concerns
- 0% of 27 outputs are properly escaped
- 2 taint flows with unsanitized paths
- No nonce checks implemented
- No capability checks implemented
Divvit e-commerce analytics Security Vulnerabilities
Divvit e-commerce analytics Release Timeline
Divvit e-commerce analytics Code Analysis
Output Escaping
Data Flow Analysis
Divvit e-commerce analytics Attack Surface
WordPress Hooks 8
Maintenance & Trust
Divvit e-commerce analytics Maintenance & Trust
Maintenance Signals
Community Trust
Divvit e-commerce analytics Alternatives
Analytics Code Option
fullestop-analytics-code-option
In Analytics Code Option you can add Google Analytic Code ID. Also you can select where Analytic code will be inserted (header, footer) in the page.
Lean GA4 Tracker
lean-ga4-tracker
Lightweight Google Analytics 4 (GA4) plugin for WordPress with WooCommerce tracking, Consent Mode, and Google Tag Manager support.
Easy UTM Builder
easy-utm-builder
Easy to build trackable URLs with UTM parameters in Bulk (complete site or specific post type) for Google Analytics!
Putler – Simple WooCommerce Analytics for your Store
woocommerce-putler-connector
A simple WooCommerce analytics plugin that provides detailed reports, insights, exports, segments, subscriptions & GA4 integration all in one place.
Metrics Query
metrics-query
Connects Google Analytics with your WordPress site. Displays stats to help you understand your users and site content on a whole new level!
Divvit e-commerce analytics Developer Profile
1 plugin · 10 total installs
How We Detect Divvit e-commerce analytics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/divvit-ecommerce-analytics/public/css/divvit-ecommerce-analytics-public.css/wp-content/plugins/divvit-ecommerce-analytics/public/js/divvit-ecommerce-analytics-public.js/wp-content/plugins/divvit-ecommerce-analytics/public/js/divvit-ecommerce-analytics-public.jsdivvit-ecommerce-analytics/public/css/divvit-ecommerce-analytics-public.css?ver=divvit-ecommerce-analytics/public/js/divvit-ecommerce-analytics-public.js?ver=HTML / DOM Fingerprints
divvit-ecommerce-analytics-public-cssdivvit_ecommerce_analytics_public_object