
Evergage for WordPress Security & Risk Analysis
wordpress.org/plugins/evergageEvergage for Wordpress provides a seamless way to integrate Evergage’s cloud-based personalization platform with Wordpress install(s).
Is Evergage for WordPress Safe to Use in 2026?
Generally Safe
Score 85/100Evergage for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "evergage" plugin v1.0.4 exhibits a generally good security posture based on the provided static analysis. The absence of identified CVEs and a clean vulnerability history are positive indicators. Furthermore, the code signals show no dangerous functions, no raw SQL queries, and no file operations, which are all strong security practices. The plugin also demonstrates an awareness of security by including a capability check and making external HTTP requests in a controlled manner.
However, there are some areas that warrant attention. The most significant concern is the very low percentage of properly escaped output (6%). This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where attacker-controlled data could be injected into the output without proper sanitization, potentially leading to malicious script execution within the user's browser. The presence of a single external HTTP request without further context on its handling also introduces a potential risk if not properly validated or secured. The taint analysis, while showing no critical or high severity issues, still analyzed a limited number of flows, meaning there could be unexamined vulnerabilities.
In conclusion, while the plugin benefits from a lack of known vulnerabilities and a secure approach to core functionalities like SQL and file operations, the significant lack of output escaping is a critical weakness that exposes users to XSS attacks. This, coupled with the limited scope of the taint analysis, suggests that while the plugin is not actively known to be compromised, there are tangible coding practices that significantly elevate its risk profile.
Key Concerns
- Low percentage of properly escaped output (6%)
- Limited taint analysis scope
Evergage for WordPress Security Vulnerabilities
Evergage for WordPress Release Timeline
Evergage for WordPress Code Analysis
Output Escaping
Data Flow Analysis
Evergage for WordPress Attack Surface
WordPress Hooks 20
Maintenance & Trust
Evergage for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Evergage for WordPress Alternatives
Connect Matomo – Analytics Dashboard for WordPress
wp-piwik
Adds Matomo (former Piwik) statistics to your WordPress dashboard and is also able to add the Matomo Tracking Code to your blog.
User Activity Tracking and Log
user-activity-tracking-and-log
Track time and monitor user activity & history on your website, LMS online learning system, membership or WooCommerce site.
Trace My IP – Visitor IP Tracker, Stats Analytics & Page Views Counter with Email Alerts
tracemyip-visitor-analytics-ip-tracking-control
Comprehensive visitor IP tracking and website analytics solution with real-time statistics, page view counting, and customizable email alerts.
Simple Webstats
simple-webstats
Privacy-focused cookie-free web analytics for WordPress.
Stetic
stetic
Privacy-friendly web analytics with a dashboard widget, stats page, and automatic tracking code for your site.
Evergage for WordPress Developer Profile
1 plugin · 10 total installs
How We Detect Evergage for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/evergage/evergage.js/wp-content/plugins/evergage/evergage.jsver=1.0.4HTML / DOM Fingerprints
<!-- Evergage settings not complete -->data-evergage-accountdata-evergage-datasetdata-evergage-urlwindow._aaqwindow.evergageItem