MetricRiv Security & Risk Analysis

wordpress.org/plugins/metricriv

Provides overall stats and metrics for your site and also provides the ability to create a connection with MetricRiv.com.

0 active installs v1.1.1 PHP 7.4+ WP 4.0+ Updated Mar 5, 2024
metricsreportrevenuestatswoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MetricRiv Safe to Use in 2026?

Generally Safe

Score 85/100

MetricRiv has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "metricriv" plugin version 1.1.1 demonstrates a generally strong security posture in several key areas. The static analysis shows a complete absence of direct SQL injection vulnerabilities, as all identified SQL queries utilize prepared statements. Furthermore, the plugin exhibits a high level of output escaping, with only a small percentage of outputs potentially being unescaped. The plugin also avoids risky operations like file manipulation and external HTTP requests, and the limited presence of nonce checks is a positive sign of secure handling for any potential internal operations.

However, the taint analysis reveals a potential concern. There is one flow with an unsanitized path identified as high severity. This suggests that user-controlled data might be used in a way that could lead to unintended consequences, such as path traversal or other file system vulnerabilities, even though the static analysis reported no direct file operations. The absence of any recorded vulnerabilities in its history is a positive indicator, suggesting the plugin has been developed with security in mind or that past issues have been effectively addressed. The lack of capability checks is a minor concern, as it implies that some operations, if they existed and were exploitable, might not be properly restricted by user roles.

In conclusion, "metricriv" 1.1.1 is reasonably secure due to its diligent use of prepared statements and output escaping. The primary area for improvement lies in addressing the high-severity taint flow identified in the analysis. While the vulnerability history is clean, proactive remediation of the identified taint flow is crucial to maintain this positive record and ensure the plugin's continued security.

Key Concerns

  • High severity taint flow with unsanitized path
  • Some outputs may be unescaped
  • No capability checks detected
Vulnerabilities
None known

MetricRiv Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

MetricRiv Release Timeline

v1.1.1Current
Code Analysis
Analyzed Apr 16, 2026

MetricRiv Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
13 prepared
Unescaped Output
4
152 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared13 total queries

Output Escaping

97% escaped156 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
ajaxSettings (metricriv.php:287)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

MetricRiv Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 18
actioninitclasses/class-metricriv-column.php:21
filtermonths_dropdown_resultsclasses/class-metricriv-column.php:76
filtermonths_dropdown_resultsclasses/class-metricriv-column.php:78
filterpost_row_actionsclasses/class-metricriv-column.php:188
filterpage_row_actionsclasses/class-metricriv-column.php:189
actionadmin_initclasses/class-metricriv-column.php:192
filterparse_queryclasses/class-metricriv-column.php:202
filterparse_queryclasses/class-metricriv-column.php:268
filterparse_queryclasses/class-metricriv-column.php:300
actioninitclasses/class-metricriv-type.php:98
filterenter_title_hereclasses/class-metricriv-type.php:229
actionadmin_enqueue_scriptsclasses/class-metricriv-type.php:232
actionadmin_print_scriptsclasses/class-metricriv-type.php:233
actioninitmetricriv.php:52
actionadmin_initmetricriv.php:82
actionadmin_enqueue_scriptsmetricriv.php:83
actionadmin_menumetricriv.php:84
filterpre_get_postsmetricriv.php:90
Maintenance & Trust

MetricRiv Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedMar 5, 2024
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

MetricRiv Developer Profile

agraddy

3 plugins · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MetricRiv

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/metricriv/css/admin_ajax_form.css/wp-content/plugins/metricriv/js/admin_ajax_form.js
Script Paths
/wp-content/plugins/metricriv/js/admin_ajax_form.js
Version Parameters
metricriv/css/admin_ajax_form.css?ver=metricriv/js/admin_ajax_form.js?ver=

HTML / DOM Fingerprints

CSS Classes
wp-list-tablewidefatfixedstriped
Data Attributes
data-numq-copy
REST Endpoints
/wp-json/metricriv_data
FAQ

Frequently Asked Questions about MetricRiv