FoxMetrics Security & Risk Analysis

wordpress.org/plugins/foxmetrics

FoxMetrics is software that helps you overcome the challenges with siloed systems and products. It captures, stores, and unlocks data generated from t …

0 active installs v1.0.1 PHP + WP 3.0+ Updated Oct 21, 2021
analyticsfoxmetricsstatisticsstatstracking
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FoxMetrics Safe to Use in 2026?

Generally Safe

Score 85/100

FoxMetrics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The foxmetrics plugin v1.0.1 exhibits a concerning security posture due to its significant unprotected attack surface. All six identified AJAX handlers lack authentication checks, presenting a direct pathway for unauthorized actions if these handlers perform sensitive operations. While the absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests are positive indicators, the lack of nonce and capability checks on AJAX endpoints is a critical oversight. The taint analysis shows two flows with unsanitized paths, though they are not classified as critical or high severity, they still warrant attention as they could potentially lead to unexpected behavior if exploited. The plugin's vulnerability history is clean, which is a good sign, but this does not mitigate the risks identified in the static analysis, especially the unprotected AJAX endpoints. The plugin has some strengths in its data handling but is severely weakened by its exposure of AJAX endpoints without proper security.

Key Concerns

  • AJAX handlers without auth checks
  • AJAX handlers without nonce checks
  • AJAX handlers without capability checks
  • Taint flows with unsanitized paths
  • Insufficient output escaping (31% unescaped)
Vulnerabilities
None known

FoxMetrics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

FoxMetrics Release Timeline

v1.0.1Current
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

FoxMetrics Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
27 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

69% escaped39 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
wc_analytics_tracking_order_received (woocommerce\class-foxmetrics-analytics-woocommerce-support.php:185)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
6 unprotected

FoxMetrics Attack Surface

Entry Points6
Unprotected6

AJAX Handlers 6

authwp_ajax_foxmetrics_tracking_cart_remove_itemincludes\class-foxmetrics-analytics.php:210
noprivwp_ajax_foxmetrics_tracking_cart_remove_itemincludes\class-foxmetrics-analytics.php:211
authwp_ajax_foxmetrics_tracking_cart_add_itemincludes\class-foxmetrics-analytics.php:212
noprivwp_ajax_foxmetrics_tracking_cart_add_itemincludes\class-foxmetrics-analytics.php:213
authwp_ajax_foxmetrics_tracking_update_cartincludes\class-foxmetrics-analytics.php:215
noprivwp_ajax_foxmetrics_tracking_update_cartincludes\class-foxmetrics-analytics.php:216
WordPress Hooks 12
actionplugins_loadedfoxmetrics-analytics.php:89
actionplugins_loadedincludes\class-foxmetrics-analytics.php:156
actionadmin_enqueue_scriptsincludes\class-foxmetrics-analytics.php:171
actionadmin_enqueue_scriptsincludes\class-foxmetrics-analytics.php:172
actionadmin_menuincludes\class-foxmetrics-analytics.php:174
actionadmin_initincludes\class-foxmetrics-analytics.php:175
actionwp_enqueue_scriptsincludes\class-foxmetrics-analytics.php:190
actionwp_enqueue_scriptsincludes\class-foxmetrics-analytics.php:191
actionwp_headincludes\class-foxmetrics-analytics.php:192
actionwc_analytics_tracking_productviewincludes\class-foxmetrics-analytics.php:206
actionwc_analytics_tracking_order_receivedincludes\class-foxmetrics-analytics.php:207
actionwp_enqueue_scriptsincludes\class-foxmetrics-analytics.php:208
Maintenance & Trust

FoxMetrics Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedOct 21, 2021
PHP min version
Downloads942

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

FoxMetrics Developer Profile

FoxMetrics Team

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect FoxMetrics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/foxmetrics/admin/css/foxmetrics-analytics-admin.css/wp-content/plugins/foxmetrics/admin/js/foxmetrics-analytics-admin.js
Script Paths
admin/js/foxmetrics-analytics-admin.js
Version Parameters
foxmetrics-analytics-admin.css?ver=foxmetrics-analytics-admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about FoxMetrics