Fathom Analytics for WP Security & Risk Analysis

wordpress.org/plugins/fathom-analytics

Fathom is a simple, GDPR compliant Google Analytics alternative.

10K active installs v3.3.1 PHP 5.4+ WP 4.5+ Updated Nov 18, 2025
analyticsgoogle-analyticsprivacyprivacy-friendlystats
99
A · Safe
CVEs total2
Unpatched0
Last CVEOct 25, 2023
Download
Safety Verdict

Is Fathom Analytics for WP Safe to Use in 2026?

Generally Safe

Score 99/100

Fathom Analytics for WP has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Oct 25, 2023Updated 4mo ago
Risk Assessment

The Fathom Analytics plugin version 3.3.1 presents a generally good security posture with no identified entry points in the static analysis, meaning there are no direct paths for unauthenticated or unauthorized access through AJAX, REST API, shortcodes, or cron jobs. The code also demonstrates strong practices by exclusively using prepared statements for SQL queries and having no file operations or external HTTP requests, which significantly reduces the risk of common web vulnerabilities. The absence of critical or high-severity taint flows further reinforces its current security. However, a notable concern is the 42% rate of proper output escaping. While not critically low, this suggests a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not consistently neutralized before being displayed in the browser.

The vulnerability history reveals two past medium-severity Cross-Site Scripting vulnerabilities, with the last one occurring in October 2023. While there are currently no unpatched vulnerabilities, the pattern of past XSS issues, coupled with the imperfect output escaping identified in the static analysis, indicates a persistent area of risk. This suggests that although the developers have addressed past vulnerabilities, the implementation of output sanitization might require further attention and rigorous testing to ensure all user-generated content is safely rendered.

In conclusion, Fathom Analytics v3.3.1 has a strong foundation with no direct attack surface and secure database interactions. The primary weakness lies in the incomplete output escaping, which, combined with its history of XSS vulnerabilities, warrants careful monitoring and potential updates. Users should ensure they are running the latest version and that the developers continue to prioritize robust input sanitization and output escaping.

Key Concerns

  • Output escaping is not consistently proper
  • Past medium severity XSS vulnerabilities
Vulnerabilities
2

Fathom Analytics for WP Security Vulnerabilities

CVEs by Year

1 CVE in 2021
2021
1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

WF-d3343d96-ca52-46a6-b464-cd2e5375d10f-fathom-analyticsmedium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Fathom Analytics <= 3.0.7 - Authenticated(Administrator+) Stored Cross-Site Scripting

Oct 25, 2023 Patched in 3.1.0 (90d)
CVE-2021-41836medium · 4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Fathom Analytics <= 3.0.4 - Stored Cross-Site Scripting

Dec 8, 2021 Patched in 3.0.5 (775d)
Code Analysis
Analyzed Mar 16, 2026

Fathom Analytics for WP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

42% escaped24 total outputs
Attack Surface

Fathom Analytics for WP Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionwp_enqueue_scriptsfathom-analytics.php:324
filterscript_loader_tagfathom-analytics.php:325
actionadmin_menufathom-analytics.php:331
actionadmin_menufathom-analytics.php:334
filterplugin_action_linksfathom-analytics.php:392
filterrocket_minify_excluded_external_jsfathom-analytics.php:408
filtersgo_javascript_combine_excluded_external_pathsfathom-analytics.php:424
filterwphb_minify_resourcefathom-analytics.php:446
filterwphb_combine_resourcefathom-analytics.php:447
filterlitespeed_optimize_js_excludesfathom-analytics.php:464
filterop3_script_is_allowed_in_blank_templatefathom-analytics.php:484
Maintenance & Trust

Fathom Analytics for WP Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 18, 2025
PHP min version5.4
Downloads102K

Community Trust

Rating96/100
Number of ratings23
Active installs10K
Developer Profile

Fathom Analytics for WP Developer Profile

Conva Ventures

1 plugin · 10K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
433 days
View full developer profile
Detection Fingerprints

How We Detect Fathom Analytics for WP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fathom-analytics/fathom-stats-iframe.js/wp-content/plugins/fathom-analytics/iframeResizer.min.js
Script Paths
https://cdn.usefathom.com/script.js

HTML / DOM Fingerprints

Data Attributes
data-sitedata-canonicaldata-no-minify
FAQ

Frequently Asked Questions about Fathom Analytics for WP