
Friendly Analytics Security & Risk Analysis
wordpress.org/plugins/friendly-analyticsOfficial WordPress plugin for Friendly Analytics
Is Friendly Analytics Safe to Use in 2026?
Generally Safe
Score 85/100Friendly Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "friendly-analytics" v1.0.4 exhibits a strong security posture based on the provided static analysis results. There are no identified vulnerabilities in its code, such as dangerous functions, raw SQL queries, unescaped output, or file operations. The absence of any recorded CVEs in its history further reinforces this positive assessment. The plugin also demonstrates a remarkably small attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that could be exploited.
However, the complete lack of capability checks and nonce checks across all entry points (even though the attack surface is zero) presents a theoretical concern. While there are no current exploitable paths due to the minimal attack surface, if future development were to introduce any entry points without implementing proper authorization and validation, it could lead to vulnerabilities. This suggests a potential for oversight in security best practices during development if the codebase were to expand.
In conclusion, "friendly-analytics" v1.0.4 appears to be a very secure plugin in its current state, primarily due to its limited functionality and lack of exposed attack vectors. The absence of vulnerabilities and a clean history are significant strengths. The only notable weakness is the complete absence of capability and nonce checks, which, while not currently an issue, highlights a potential area for improvement in adhering to standard WordPress security practices.
Key Concerns
- No capability checks implemented
- No nonce checks implemented
Friendly Analytics Security Vulnerabilities
Friendly Analytics Release Timeline
Friendly Analytics Code Analysis
Friendly Analytics Attack Surface
Maintenance & Trust
Friendly Analytics Maintenance & Trust
Maintenance Signals
Community Trust
Friendly Analytics Alternatives
Plausible Analytics
plausible-analytics
Plausible Analytics is a privacy-friendly web analytics plugin for WordPress that is an easy-to-use, lightweight and more accurate alternative to Goo …
Usermaven
usermaven
Usermaven's web analytics product is a Google Analytics alternative that provides a real-time view of your website traffic metrics.
Trackboxx Analytics
trackboxx-analytics
A simple, GDPR compliant Google Analytics alternative.
OpenPanel
openpanel
OpenPanel WordPress plugin - Privacy-friendly analytics with ad-blocker resistance. Inline tracking scripts and proxy API calls through your domain.
Vemetric
vemetric
Vemetric is a lightweight, privacy-first analytics tool that helps you understand how your users are interacting with your website.
Friendly Analytics Developer Profile
2 plugins · 10 total installs
How We Detect Friendly Analytics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/friendly-analytics/build/main.css/wp-content/plugins/friendly-analytics/build/main.js/wp-content/plugins/friendly-analytics/build/main.jsfriendly-analytics/build/main.css?ver=friendly-analytics/build/main.js?ver=HTML / DOM Fingerprints
friendly-analytics-containerdata-friendly-analytics-idwindow.friendly_analyticsfriendly_analytics[friendly_analytics]