Friendly Analytics Security & Risk Analysis

wordpress.org/plugins/friendly-analytics

Official WordPress plugin for Friendly Analytics

10 active installs v1.0.4 PHP 7.1+ WP 4.8+ Updated Feb 2, 2022
analyticsanonymizationprivacytracking-codeweb-analytics
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Friendly Analytics Safe to Use in 2026?

Generally Safe

Score 85/100

Friendly Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The plugin "friendly-analytics" v1.0.4 exhibits a strong security posture based on the provided static analysis results. There are no identified vulnerabilities in its code, such as dangerous functions, raw SQL queries, unescaped output, or file operations. The absence of any recorded CVEs in its history further reinforces this positive assessment. The plugin also demonstrates a remarkably small attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that could be exploited.

However, the complete lack of capability checks and nonce checks across all entry points (even though the attack surface is zero) presents a theoretical concern. While there are no current exploitable paths due to the minimal attack surface, if future development were to introduce any entry points without implementing proper authorization and validation, it could lead to vulnerabilities. This suggests a potential for oversight in security best practices during development if the codebase were to expand.

In conclusion, "friendly-analytics" v1.0.4 appears to be a very secure plugin in its current state, primarily due to its limited functionality and lack of exposed attack vectors. The absence of vulnerabilities and a clean history are significant strengths. The only notable weakness is the complete absence of capability and nonce checks, which, while not currently an issue, highlights a potential area for improvement in adhering to standard WordPress security practices.

Key Concerns

  • No capability checks implemented
  • No nonce checks implemented
Vulnerabilities
None known

Friendly Analytics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Friendly Analytics Release Timeline

v1.0.5
v1.0.4Current
v1.0.3
v1.0.2
v1.0.1
v1.0
Code Analysis
Analyzed Mar 17, 2026

Friendly Analytics Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Friendly Analytics Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Friendly Analytics Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedFeb 2, 2022
PHP min version7.1
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Friendly Analytics Developer Profile

Friendly

2 plugins · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Friendly Analytics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/friendly-analytics/build/main.css/wp-content/plugins/friendly-analytics/build/main.js
Script Paths
/wp-content/plugins/friendly-analytics/build/main.js
Version Parameters
friendly-analytics/build/main.css?ver=friendly-analytics/build/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
friendly-analytics-container
Data Attributes
data-friendly-analytics-id
JS Globals
window.friendly_analyticsfriendly_analytics
Shortcode Output
[friendly_analytics]
FAQ

Frequently Asked Questions about Friendly Analytics