
MetricRiv Security & Risk Analysis
wordpress.org/plugins/metricrivProvides overall stats and metrics for your site and also provides the ability to create a connection with MetricRiv.com.
Is MetricRiv Safe to Use in 2026?
Generally Safe
Score 85/100MetricRiv has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "metricriv" plugin version 1.1.1 demonstrates a generally strong security posture in several key areas. The static analysis shows a complete absence of direct SQL injection vulnerabilities, as all identified SQL queries utilize prepared statements. Furthermore, the plugin exhibits a high level of output escaping, with only a small percentage of outputs potentially being unescaped. The plugin also avoids risky operations like file manipulation and external HTTP requests, and the limited presence of nonce checks is a positive sign of secure handling for any potential internal operations.
However, the taint analysis reveals a potential concern. There is one flow with an unsanitized path identified as high severity. This suggests that user-controlled data might be used in a way that could lead to unintended consequences, such as path traversal or other file system vulnerabilities, even though the static analysis reported no direct file operations. The absence of any recorded vulnerabilities in its history is a positive indicator, suggesting the plugin has been developed with security in mind or that past issues have been effectively addressed. The lack of capability checks is a minor concern, as it implies that some operations, if they existed and were exploitable, might not be properly restricted by user roles.
In conclusion, "metricriv" 1.1.1 is reasonably secure due to its diligent use of prepared statements and output escaping. The primary area for improvement lies in addressing the high-severity taint flow identified in the analysis. While the vulnerability history is clean, proactive remediation of the identified taint flow is crucial to maintain this positive record and ensure the plugin's continued security.
Key Concerns
- High severity taint flow with unsanitized path
- Some outputs may be unescaped
- No capability checks detected
MetricRiv Security Vulnerabilities
MetricRiv Release Timeline
MetricRiv Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
MetricRiv Attack Surface
WordPress Hooks 18
Maintenance & Trust
MetricRiv Maintenance & Trust
Maintenance Signals
Community Trust
MetricRiv Alternatives
NumbersQ
numbersq
Provides overall stats and numbers for your site and also provides the ability to create a connection with NumbersQ.com.
Sales Analytics for WooCommerce
sales-analytics-for-woocommerce
Sales Analytics for WooCommerce: detailed reports, payment analytics, AI-based insights, CSV/PDF export, multi-currency, and chart visuals.
Metorik – Reports & Email Automation for WooCommerce
metorik-helper
The Metorik Helper helps provide your WooCommerce store with powerful analytics, reports, and tools.
Ninjalytics: Sales Reports & Order Export for WooCommerce and EDD
product-sales-report-for-woocommerce
Create sales reports and order exports for WooCommerce with product analytics, order fulfillment data, filtering, charts, and 15+ templates.
Piwik PRO
piwik-pro
Piwik PRO - Web & App Analytics, Tag Manager, CDP and Consent Manager
MetricRiv Developer Profile
3 plugins · 1K total installs
How We Detect MetricRiv
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/metricriv/css/admin_ajax_form.css/wp-content/plugins/metricriv/js/admin_ajax_form.js/wp-content/plugins/metricriv/js/admin_ajax_form.jsmetricriv/css/admin_ajax_form.css?ver=metricriv/js/admin_ajax_form.js?ver=HTML / DOM Fingerprints
wp-list-tablewidefatfixedstripeddata-numq-copy/wp-json/metricriv_data