Finteza Analytics Security & Risk Analysis

wordpress.org/plugins/finteza-analytics

Finteza web analytics plugin for WordPress websites

200 active installs v1.3 PHP 5.6+ WP 4.7+ Updated Jul 26, 2021
analyticsfintezagoogle-analyticsstatisticstracking
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Finteza Analytics Safe to Use in 2026?

Generally Safe

Score 85/100

Finteza Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The finteza-analytics v1.3 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of known CVEs and the clean vulnerability history suggest a well-maintained and secure codebase over time. The plugin also demonstrates good practices by not exposing a large attack surface with unprotected entry points and by utilizing prepared statements for all SQL queries. This significantly mitigates risks associated with SQL injection.

However, there are specific areas of concern. The low percentage of properly escaped output (40%) is a significant risk, potentially leading to cross-site scripting (XSS) vulnerabilities if user-supplied data is displayed without adequate sanitization. Additionally, the presence of a single taint flow with an unsanitized path, even without a critical or high severity classification, warrants attention as it indicates a potential for unauthorized data handling or manipulation. The lack of nonce checks and capability checks across all identified entry points further elevates the risk of unauthorized actions if any entry points were to be discovered or added in the future.

In conclusion, while the plugin benefits from a clean historical record and secure data handling for SQL, the insufficient output escaping and the observed unsanitized taint flow are critical weaknesses that need immediate attention. The absence of checks for nonces and capabilities on any entry points also presents a latent risk. Addressing these issues would greatly improve the overall security of the plugin.

Key Concerns

  • Insufficient output escaping
  • Unsanitized path in taint flow
  • Lack of nonce checks
  • Lack of capability checks
Vulnerabilities
None known

Finteza Analytics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Finteza Analytics Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
27
18 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
3
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

40% escaped45 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<finteza-analytics> (finteza-analytics.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Finteza Analytics Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actioninitfinteza-analytics.php:41
actionadmin_initfinteza-analytics.php:42
actionadmin_menufinteza-analytics.php:43
actionadmin_enqueue_scriptsfinteza-analytics.php:44
actionwp_headfinteza-analytics.php:45
actionpre_update_option_finteza_registerfinteza-analytics.php:46
actionpre_update_option_finteza_settingsfinteza-analytics.php:47
actionparse_requestfinteza-analytics.php:48
filtermce_buttonstr\main.php:8
filtermce_external_pluginstr\main.php:15
filtermce_external_languagestr\main.php:22
actionprint_default_editor_scriptstr\main.php:42
Maintenance & Trust

Finteza Analytics Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedJul 26, 2021
PHP min version5.6
Downloads12K

Community Trust

Rating100/100
Number of ratings2
Active installs200
Developer Profile

Finteza Analytics Developer Profile

Finteza Analytics

1 plugin · 200 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Finteza Analytics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/finteza-analytics/css/settings.css/wp-content/plugins/finteza-analytics/js/settings.js
Script Paths
https://content.mql5.com/core.js
Version Parameters
finteza-analytics/css/settings.css?ver=finteza-analytics/js/settings.js?ver=

HTML / DOM Fingerprints

Data Attributes
finteza_domain-idfinteza_offset-idfinteza_name-idfinteza_company-idfinteza_email-idfinteza_password-id+4 more
JS Globals
finteza_analytics_apifinteza_analytics_trackingfinteza_analytics_proxy_tokenfinteza_analytics_domainfinteza_analytics_offsetfinteza_analytics_name+4 more
FAQ

Frequently Asked Questions about Finteza Analytics