AH Google Analytics Code Security & Risk Analysis

wordpress.org/plugins/evolution-google-analytics-code

With this plugin you can add the Google Analytics Code in no time to the header or footer of your theme.

600 active installs v1.0.7 PHP + WP 4.7+ Updated Sep 23, 2017
analyticsanalytics-codegooglegoogle-analyticsgoogle-analytics-code
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AH Google Analytics Code Safe to Use in 2026?

Generally Safe

Score 85/100

AH Google Analytics Code has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "evolution-google-analytics-code" plugin, at version 1.0.7, exhibits a generally strong security posture based on the provided static analysis. The absence of identified dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), file operations, external HTTP requests, and a complete lack of any recorded vulnerabilities in its history are significant positive indicators. The plugin also boasts a very small attack surface, with zero identified entry points across AJAX, REST API, shortcodes, and cron events. However, there are areas for improvement. The code analysis reveals that only 50% of its output is properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is rendered without sufficient sanitization. Furthermore, the complete absence of nonce and capability checks across all identified entry points (though none were found) indicates a potential oversight in security implementation that would be critical if any new entry points were introduced or discovered.

Key Concerns

  • Half of outputs are not properly escaped
  • No nonce checks present
  • No capability checks present
Vulnerabilities
None known

AH Google Analytics Code Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AH Google Analytics Code Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped4 total outputs
Attack Surface

AH Google Analytics Code Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuevolution-google-analytics-code.php:25
actionadmin_initevolution-google-analytics-code.php:26
actionwp_headevolution-google-analytics-code.php:174
actionwp_footerevolution-google-analytics-code.php:190
Maintenance & Trust

AH Google Analytics Code Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedSep 23, 2017
PHP min version
Downloads14K

Community Trust

Rating100/100
Number of ratings5
Active installs600
Developer Profile

AH Google Analytics Code Developer Profile

Andreas Hecht

8 plugins · 10K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AH Google Analytics Code

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
evolution-google-analytics-code
Data Attributes
id="evolution_analytics_head"id="evolution_analytics_footer"
FAQ

Frequently Asked Questions about AH Google Analytics Code