Modovisa Analytics Security & Risk Analysis

wordpress.org/plugins/modovisa-analytics

Injects the Modovisa real-time tracking script into your site’s .

0 active installs v1.0.4 PHP 7.4+ WP 6.0+ Updated Mar 25, 2026
analyticsconversionsprivacyreal-timevisitor-tracking
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Modovisa Analytics Safe to Use in 2026?

Generally Safe

Score 100/100

Modovisa Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

Based on the provided static analysis, "modovisa-analytics" v1.0.3 exhibits a generally strong security posture. The absence of identified dangerous functions, SQL queries without prepared statements, file operations, and external HTTP requests is commendable. Furthermore, the high percentage of properly escaped output suggests good development practices for preventing common cross-site scripting (XSS) vulnerabilities. The lack of any known CVEs in its history also points to a plugin that has likely been maintained with security in mind.

However, the analysis reveals a significant concern: the complete lack of any capability checks or nonce checks across all identified entry points, which are zero. While the current attack surface is reported as zero, this absence of security controls is a critical weakness. Should any new entry points be introduced or discovered in future versions, they would likely be vulnerable by default. The taint analysis also reported zero flows, which is good, but this could be a result of limited testability or a very simple codebase, rather than a guarantee of no latent issues.

In conclusion, while "modovisa-analytics" v1.0.3 demonstrates good coding hygiene in many areas and has a clean vulnerability history, the complete omission of authentication and authorization checks represents a substantial inherent risk. If the plugin's functionality evolves or if the reported attack surface is an underestimation, this lack of protection could lead to severe security breaches.

Key Concerns

  • Missing nonce checks on all entry points
  • Missing capability checks on all entry points
  • Unescaped output detected (11% of outputs)
Vulnerabilities
None known

Modovisa Analytics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Modovisa Analytics Release Timeline

v1.0.4Current
v1.0.3
v1.0.2
Code Analysis
Analyzed Mar 17, 2026

Modovisa Analytics Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
17 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

89% escaped19 total outputs
Attack Surface

Modovisa Analytics Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_initmodovisa-analytics.php:47
actionadmin_menumodovisa-analytics.php:48
actionadmin_enqueue_scriptsmodovisa-analytics.php:49
actionwp_enqueue_scriptsmodovisa-analytics.php:52
actioninitmodovisa-analytics.php:55
filterautoptimize_filter_js_excludemodovisa-analytics.php:63
filterrocket_delay_js_exclusionsmodovisa-analytics.php:69
filterscript_loader_tagmodovisa-analytics.php:301
Maintenance & Trust

Modovisa Analytics Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 25, 2026
PHP min version7.4
Downloads318

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Modovisa Analytics Developer Profile

modovisa

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Modovisa Analytics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/modovisa-analytics/assets/1-wordpress-tracking-token.webp/wp-content/plugins/modovisa-analytics/assets/modovisa-analytics-admin.css/wp-content/plugins/modovisa-analytics/assets/modovisa-analytics-admin.js/wp-content/plugins/modovisa-analytics/assets/modovisa-analytics-frontend.js
Script Paths
/wp-content/plugins/modovisa-analytics/assets/modovisa-analytics-frontend.js
Version Parameters
modovisa-analytics/assets/modovisa-analytics-admin.css?ver=modovisa-analytics/assets/modovisa-analytics-admin.js?ver=modovisa-analytics/assets/modovisa-analytics-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
mv-togglemv-pillmv-switchmv-switch-slidermv-switch-labelmodovisa-widemodovisa-help-shot
Data Attributes
aria-label="Enable tracking"aria-describedbyaria-hidden="true"
FAQ

Frequently Asked Questions about Modovisa Analytics