
Page Visit Counter Analytics – Google Analytics Alternative for WordPress Security & Risk Analysis
wordpress.org/plugins/page-visit-counter-analyticsA fast, privacy-first WordPress analytics plugin that tracks views, sessions, bounce rate, traffic, and UTMs—no cookies or external scripts.
Is Page Visit Counter Analytics – Google Analytics Alternative for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100Page Visit Counter Analytics – Google Analytics Alternative for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "page-visit-counter-analytics" v3.1.0 plugin exhibits a generally strong security posture, with excellent practices observed in output escaping and a high percentage of prepared SQL statements. The absence of any recorded vulnerabilities in its history is also a positive indicator. However, the static analysis reveals a significant area of concern regarding the attack surface. While most entry points are secured, one REST API route is identified as lacking permission callbacks, which presents a potential security weakness.
Furthermore, the taint analysis indicates that all ten flows analyzed have unsanitized paths and ten of these are of high severity. This is a critical finding that, despite the absence of specific dangerous functions or raw SQL, suggests that data processed by the plugin may be vulnerable to injection attacks if not properly handled within the application context. The presence of file operations and an external HTTP request also warrants careful review in conjunction with the taint analysis to ensure these operations are not exploited.
In conclusion, while the plugin demonstrates good coding practices in several key areas, the identified unprotected REST API route and the high number of high-severity unsanitized taint flows are significant risks that need immediate attention. These findings overshadow the otherwise positive aspects of the code and vulnerability history, suggesting that the plugin's security needs further hardening before it can be considered truly robust.
Key Concerns
- REST API route without permission callbacks
- 10 high severity unsanitized taint flows
Page Visit Counter Analytics – Google Analytics Alternative for WordPress Security Vulnerabilities
Page Visit Counter Analytics – Google Analytics Alternative for WordPress Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Page Visit Counter Analytics – Google Analytics Alternative for WordPress Attack Surface
AJAX Handlers 3
REST API Routes 3
WordPress Hooks 25
Scheduled Events 5
Maintenance & Trust
Page Visit Counter Analytics – Google Analytics Alternative for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Page Visit Counter Analytics – Google Analytics Alternative for WordPress Alternatives
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)
google-analytics-for-wordpress
The best free Google Analytics plugin for WordPress. See how visitors find and use your website so you can grow your business with powerful analytics.
Independent Analytics – Google Analytics Alternative for WordPress
independent-analytics
A simple WordPress analytics plugin that is privacy-friendly, fast, and an alternative to Google Analytics.
Beehive Analytics – Google Analytics Dashboard
beehive-analytics
View visitor stats and track user behavior from within WordPress. A Google Analytics plugin with dashboard reports and Google Tag Manager support.
Aurora Heatmap
aurora-heatmap
Beautiful like an aurora! A simple WordPress heatmap that can be completed with just a plugin.
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking)
wp-analytify
Analytify is the must-have Plugin for Google Analytics 4 Integration, Tracking, & Reporting in WordPress. Enhanced eCommerce, Events, & Call Analytics
Page Visit Counter Analytics – Google Analytics Alternative for WordPress Developer Profile
7 plugins · 21K total installs
How We Detect Page Visit Counter Analytics – Google Analytics Alternative for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/page-visit-counter-analytics/assets/css/admin.css/wp-content/plugins/page-visit-counter-analytics/assets/js/chart.js/wp-content/plugins/page-visit-counter-analytics/assets/js/dashboard.js/wp-content/plugins/page-visit-counter-analytics/assets/js/chart-admin.jshttps://cdn.tailwindcss.com/?v=3.4.2https://cdn.jsdelivr.net/npm/jsvectormap@1.5.3/dist/css/jsvectormap.min.csspage-visit-counter-analytics/assets/css/admin.css?ver=page-visit-counter-analytics/assets/js/chart.js?ver=page-visit-counter-analytics/assets/js/dashboard.js?ver=page-visit-counter-analytics/assets/js/chart-admin.js?ver=HTML / DOM Fingerprints
pvca-promo-noticedata-pagevico-dashboardpagevicoTracker/pagevico/v1/realtime