Evergage for WordPress Security & Risk Analysis

wordpress.org/plugins/evergage

Evergage for Wordpress provides a seamless way to integrate Evergage’s cloud-based personalization platform with Wordpress install(s).

10 active installs v1.0.4 PHP + WP 3.3+ Updated Apr 20, 2015
analyticspersonalizationstatisticsstatstracking
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Evergage for WordPress Safe to Use in 2026?

Generally Safe

Score 85/100

Evergage for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "evergage" plugin v1.0.4 exhibits a generally good security posture based on the provided static analysis. The absence of identified CVEs and a clean vulnerability history are positive indicators. Furthermore, the code signals show no dangerous functions, no raw SQL queries, and no file operations, which are all strong security practices. The plugin also demonstrates an awareness of security by including a capability check and making external HTTP requests in a controlled manner.

However, there are some areas that warrant attention. The most significant concern is the very low percentage of properly escaped output (6%). This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where attacker-controlled data could be injected into the output without proper sanitization, potentially leading to malicious script execution within the user's browser. The presence of a single external HTTP request without further context on its handling also introduces a potential risk if not properly validated or secured. The taint analysis, while showing no critical or high severity issues, still analyzed a limited number of flows, meaning there could be unexamined vulnerabilities.

In conclusion, while the plugin benefits from a lack of known vulnerabilities and a secure approach to core functionalities like SQL and file operations, the significant lack of output escaping is a critical weakness that exposes users to XSS attacks. This, coupled with the limited scope of the taint analysis, suggests that while the plugin is not actively known to be compromised, there are tangible coding practices that significantly elevate its risk profile.

Key Concerns

  • Low percentage of properly escaped output (6%)
  • Limited taint analysis scope
Vulnerabilities
None known

Evergage for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Evergage for WordPress Release Timeline

v1.0.4Current
Code Analysis
Analyzed Mar 17, 2026

Evergage for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
15
1 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

6% escaped16 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
evergage_config (admin.php:80)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Evergage for WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
actionadmin_menuadmin.php:2
actionadmin_initadmin.php:5
actionadmin_noticesadmin.php:53
actionadmin_initadmin.php:67
filterplugin_action_linksadmin.php:77
actionadmin_noticesadmin.php:194
actionjetpack_admin_menuadmin.php:259
actionwp_print_scriptsevergage.php:23
actionwp_headevergage.php:26
actioninitevergage.php:32
actionuser_registerevergage.php:351
actiondelete_userevergage.php:367
actionwp_authenticateevergage.php:386
actionwp_logoutevergage.php:404
actioncomment_postevergage.php:420
actiondelete_commentevergage.php:436
actionsave_postevergage.php:455
actiondelete_postevergage.php:474
actioncreate_categoryevergage.php:495
actiondelete_categoryevergage.php:516
Maintenance & Trust

Evergage for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedApr 20, 2015
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Evergage for WordPress Developer Profile

ghinkle

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Evergage for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/evergage/evergage.js
Script Paths
/wp-content/plugins/evergage/evergage.js
Version Parameters
ver=1.0.4

HTML / DOM Fingerprints

HTML Comments
<!-- Evergage settings not complete -->
Data Attributes
data-evergage-accountdata-evergage-datasetdata-evergage-url
JS Globals
window._aaqwindow.evergageItem
FAQ

Frequently Asked Questions about Evergage for WordPress