Fast Yandex Metrika Security & Risk Analysis

wordpress.org/plugins/fast-yandex-metrika

Plugin for configuring the counter and Yandex Metrica goals.

200 active installs v1.1.5 PHP 8.1+ WP 6.8+ Updated Apr 15, 2025
%d1%8f%d0%bd%d0%b4%d0%b5%d0%ba%d1%81%d0%bc%d0%b5%d1%82%d1%80%d0%b8%d0%ba%d0%b0metricametrikayandex
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Fast Yandex Metrika Safe to Use in 2026?

Generally Safe

Score 100/100

Fast Yandex Metrika has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The 'fast-yandex-metrika' plugin version 1.1.5 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The code analysis reveals a complete absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests. Crucially, all SQL queries are prepared, and a high percentage of output is properly escaped, minimizing risks of injection and cross-site scripting vulnerabilities. The presence of nonce and capability checks, although limited in scope due to the lack of identified entry points, indicates an awareness of basic security practices.

The taint analysis shows no identified flows with unsanitized paths, and the vulnerability history is clean with zero known CVEs. This suggests that the plugin has been developed with security in mind and has not historically suffered from significant security flaws. The plugin's attack surface is also reported as zero for AJAX handlers, REST API routes, shortcodes, and cron events, meaning there are no obvious direct entry points for attackers to exploit. This lack of exposed entry points is a significant strength.

While the plugin demonstrates excellent security practices in its current state, the absence of any identified entry points in the static analysis is notable. If there are indeed no functional entry points, this would explain the clean taint analysis and lack of vulnerabilities. However, in a real-world scenario, even seemingly simple plugins often have some form of interaction point. The current data suggests a highly secure plugin, but it's always prudent to maintain vigilance and ensure that all components, even those not immediately apparent, are secured. Overall, the plugin appears robust and well-secured.

Vulnerabilities
None known

Fast Yandex Metrika Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Fast Yandex Metrika Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
64 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

93% escaped69 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
fast_yandex_metrika_options_list (fast-yandex-metrika.php:297)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Fast Yandex Metrika Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionwp_headfast-yandex-metrika.php:225
actionwp_body_openfast-yandex-metrika.php:239
actionwp_body_openfast-yandex-metrika.php:243
actionwp_footerfast-yandex-metrika.php:251
actioninitfast-yandex-metrika.php:260
actionplugins_loadedfast-yandex-metrika.php:730
actionadmin_menufast-yandex-metrika.php:737
Maintenance & Trust

Fast Yandex Metrika Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 15, 2025
PHP min version8.1
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

Fast Yandex Metrika Developer Profile

Sergey Parshin

1 plugin · 200 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Fast Yandex Metrika

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fast-yandex-metrika/style.css/wp-content/plugins/fast-yandex-metrika/js/fast-yandex-metrika.js
Script Paths
https://mc.yandex.ru/metrika/tag.js
Version Parameters
fast-yandex-metrika/style.css?ver=fast-yandex-metrika/js/fast-yandex-metrika.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Yandex.Metrika counter --><!-- /Yandex.Metrika counter -->
Data Attributes
data-ym-counter
JS Globals
ymfast_yandex_metrika_reach_goal_insert_jsfast_yandex_metrika_goal_error_jsfast_yandex_metrika_choosefast_yandex_metrika_insert_js
FAQ

Frequently Asked Questions about Fast Yandex Metrika