Lytics Personalization Engine (Official) Security & Risk Analysis

wordpress.org/plugins/lytics-wp

Integrate Lytics' personalization engine with WordPress for segmentation, personalized content, recommendations, and more.

30 active installs v1.0.5 PHP 7.4+ WP 6.0+ Updated Mar 17, 2025
analyticsblockcdpgutenbergpersonalization
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Lytics Personalization Engine (Official) Safe to Use in 2026?

Generally Safe

Score 92/100

Lytics Personalization Engine (Official) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The lytics-wp plugin version 1.0.5 exhibits a strong security posture based on the provided static analysis and vulnerability history. The code demonstrates excellent practices regarding SQL query sanitization, with 100% of queries using prepared statements. Furthermore, output escaping is highly effective, with 98% of outputs properly escaped, minimizing the risk of cross-site scripting (XSS) vulnerabilities. The presence of 6 nonce checks and 10 capability checks indicates a conscientious approach to securing its entry points. The complete absence of known CVEs and a clean vulnerability history strongly suggests the plugin has been well-maintained and has not historically presented significant security risks. The limited attack surface, consisting of only 2 shortcodes and no unprotected entry points, further enhances its security profile. The taint analysis also revealed no critical or high severity flows with unsanitized paths, which is a very positive indicator. While there are no significant concerns based on the provided data, the presence of 6 external HTTP requests could be an area to monitor for potential future vulnerabilities if the external services become compromised or introduce their own security issues. Overall, this plugin appears to be a secure and well-developed option.

Vulnerabilities
None known

Lytics Personalization Engine (Official) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Lytics Personalization Engine (Official) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
80 escaped
Nonce Checks
6
Capability Checks
10
File Operations
0
External Requests
6
Bundled Libraries
0

Output Escaping

98% escaped82 total outputs
Data Flows
All sanitized

Data Flow Analysis

4 flows
lyticswp_settings_handle_form_submission (admin\class-lytics-admin.php:189)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Lytics Personalization Engine (Official) Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[lyticswp_greeting] includes\class-lytics.php:128
[lyticswp_greeting] trunk\includes\class-lytics.php:128
WordPress Hooks 40
filterscript_loader_tagadmin\class-lytics-admin.php:104
filterpost_row_actionsadmin\class-lytics-admin.php:324
filterscript_loader_tagadmin\class-lytics-admin.php:582
actionplugins_loadedincludes\class-lytics.php:87
actionadmin_enqueue_scriptsincludes\class-lytics.php:98
actionadmin_enqueue_scriptsincludes\class-lytics.php:99
actionadmin_enqueue_scriptsincludes\class-lytics.php:100
actionadmin_menuincludes\class-lytics.php:101
actionadmin_post_lyticswp_process_formincludes\class-lytics.php:103
actionadmin_initincludes\class-lytics.php:104
actionadmin_post_delete_lyticswp_settingsincludes\class-lytics.php:105
actioninitincludes\class-lytics.php:108
actioninitincludes\class-lytics.php:109
actionadd_meta_boxesincludes\class-lytics.php:110
actionsave_postincludes\class-lytics.php:111
actioninitincludes\class-lytics.php:114
actionwp_enqueue_scriptsincludes\class-lytics.php:125
actionwp_enqueue_scriptsincludes\class-lytics.php:126
actionwp_enqueue_scriptsincludes\class-lytics.php:127
filterscript_loader_tagpublic\class-lytics-public.php:85
filterscript_loader_tagtrunk\admin\class-lytics-admin.php:104
filterpost_row_actionstrunk\admin\class-lytics-admin.php:324
filterscript_loader_tagtrunk\admin\class-lytics-admin.php:582
actionplugins_loadedtrunk\includes\class-lytics.php:87
actionadmin_enqueue_scriptstrunk\includes\class-lytics.php:98
actionadmin_enqueue_scriptstrunk\includes\class-lytics.php:99
actionadmin_enqueue_scriptstrunk\includes\class-lytics.php:100
actionadmin_menutrunk\includes\class-lytics.php:101
actionadmin_post_lyticswp_process_formtrunk\includes\class-lytics.php:103
actionadmin_inittrunk\includes\class-lytics.php:104
actionadmin_post_delete_lyticswp_settingstrunk\includes\class-lytics.php:105
actioninittrunk\includes\class-lytics.php:108
actioninittrunk\includes\class-lytics.php:109
actionadd_meta_boxestrunk\includes\class-lytics.php:110
actionsave_posttrunk\includes\class-lytics.php:111
actioninittrunk\includes\class-lytics.php:114
actionwp_enqueue_scriptstrunk\includes\class-lytics.php:125
actionwp_enqueue_scriptstrunk\includes\class-lytics.php:126
actionwp_enqueue_scriptstrunk\includes\class-lytics.php:127
filterscript_loader_tagtrunk\public\class-lytics-public.php:85
Maintenance & Trust

Lytics Personalization Engine (Official) Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedMar 17, 2025
PHP min version7.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Lytics Personalization Engine (Official) Developer Profile

markjhayden

1 plugin · 30 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Lytics Personalization Engine (Official)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lytics-wp/admin/css/lytics-admin.css/wp-content/plugins/lytics-wp/admin/js/lytics-admin.js/wp-content/plugins/lytics-wp/admin/js/lytics-widget-wizard.js/wp-content/plugins/lytics-wp/admin/js/lytics-recommendation-render.js
Script Paths
/wp-content/plugins/lytics-wp/admin/js/lytics-admin.js/wp-content/plugins/lytics-wp/admin/js/lytics-widget-wizard.js/wp-content/plugins/lytics-wp/admin/js/lytics-recommendation-render.js
Version Parameters
lytics-admin.css?ver=lytics-admin.js?ver=lytics-widget-wizard.js?ver=lytics-recommendation-render.js?ver=

HTML / DOM Fingerprints

JS Globals
lytics-wp-config-editor
FAQ

Frequently Asked Questions about Lytics Personalization Engine (Official)