
Seoatl On Site Google Analytics Security & Risk Analysis
wordpress.org/plugins/on-site-google-analyticsThis plugin provides WP admin's valuable data from Google Analytics on site without having to login to Google Analytics to get the information.
Is Seoatl On Site Google Analytics Safe to Use in 2026?
Generally Safe
Score 100/100Seoatl On Site Google Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'on-site-google-analytics' vv0.1 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals no identified attack surface (AJAX handlers, REST API routes, shortcodes, cron events) that are unprotected by authentication or permission checks. This significantly limits potential direct entry points for malicious actors. However, the code analysis reveals several concerning areas. A notable weakness is the presence of SQL queries that are not using prepared statements, which can lead to SQL injection vulnerabilities if user input is not properly sanitized. Furthermore, a low percentage of output escaping suggests a high risk of cross-site scripting (XSS) vulnerabilities, where malicious scripts could be injected into the website's output. The taint analysis, while not revealing critical or high-severity issues, did identify flows with unsanitized paths, indicating a potential for data leakage or manipulation if these paths are exploited. The plugin's vulnerability history is clean, with no known CVEs, which is a positive indicator of past security diligence or simply a lack of past exploitation. However, the code quality concerns, particularly around SQL and output escaping, suggest that this clean history may be due to a lack of thorough security testing or a low profile rather than robust security practices.
In conclusion, while the plugin's lack of direct entry points is commendable, the identified code-level weaknesses in SQL handling and output escaping present significant risks. The 100% of SQL queries not using prepared statements and the low rate of output escaping are direct red flags for potential vulnerabilities. The unsanitized paths in taint analysis, though not critically severe, further emphasize the need for more robust input validation and output sanitization. The absence of vulnerability history is a positive, but it should not overshadow the critical need to address the evident code quality issues to prevent future security incidents.
Key Concerns
- SQL queries without prepared statements
- Low percentage of output escaping
- Flows with unsanitized paths
- No nonce checks
- No capability checks
Seoatl On Site Google Analytics Security Vulnerabilities
Seoatl On Site Google Analytics Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Seoatl On Site Google Analytics Attack Surface
WordPress Hooks 4
Maintenance & Trust
Seoatl On Site Google Analytics Maintenance & Trust
Maintenance Signals
Community Trust
Seoatl On Site Google Analytics Alternatives
Koko Analytics – Privacy Friendly Statistics for WordPress
koko-analytics
Koko Analytics is a privacy-friendly statistics plugin for WordPress that is an easy to use alternative to Google Analytics.
Multiple Google Analytics Trackers
multi-google-analytics
Add one or more Google Analytics trackers to your website.
Seoatl On Site Google Analytics
onsite-google-analytics-plugin
This plugin provides WP admin's valuable data from Google Analytics on site without having to login to Google Analytics to get the information.
WP Statistics – Simple, privacy-friendly Google Analytics alternative
wp-statistics
Get website traffic insights with GDPR/CCPA compliant, privacy-friendly analytics. Includes visitor data, stunning graphs, and no data sharing.
GA Google Analytics – Connect Google Analytics to WordPress
ga-google-analytics
Adds Google Analytics tracking code to your WordPress site. Supports many tracking features.
Seoatl On Site Google Analytics Developer Profile
3 plugins · 110 total installs
How We Detect Seoatl On Site Google Analytics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/on-site-google-analytics/images/admin-loader.gifHTML / DOM Fingerprints
wrapid="profile_loader"id="seoatlGaUsername"id="seoatlGaPassword"id="seoatlGaProfileId"id="seoatlGaDateRange"name="seoatlGaUsername"+5 more