Paste Analytics Security & Risk Analysis

wordpress.org/plugins/paste-analytics

Paste your Google Analytics script in wp-admin to track your site.

10 active installs v1.1 PHP + WP 4.0+ Updated Oct 26, 2014
analyticsgagooglegoogle-analyticsstatistics
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Paste Analytics Safe to Use in 2026?

Generally Safe

Score 85/100

Paste Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "paste-analytics" plugin v1.1 exhibits a surprisingly clean bill of health from a static analysis perspective, with no identified attack surface entry points, dangerous functions, or vulnerabilities in SQL queries, file operations, or external HTTP requests. The lack of taint analysis findings and zero recorded CVEs further contribute to a perception of strong security practices. However, a critical weakness lies in the complete absence of output escaping on all identified output points. This indicates that any data processed by the plugin could potentially be rendered directly to the user without sanitization, opening the door to cross-site scripting (XSS) vulnerabilities if untrusted data is involved. While the plugin demonstrates good practices in handling external interactions and data persistence, the unescaped output represents a significant oversight that could be exploited.

Key Concerns

  • Unescaped output found
Vulnerabilities
None known

Paste Analytics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Paste Analytics Release Timeline

v1.1Current
v1.0
Code Analysis
Analyzed Mar 16, 2026

Paste Analytics Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped4 total outputs
Attack Surface

Paste Analytics Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menupaste-analytics.php:15
actionadmin_initpaste-analytics.php:16
actionwp_headpaste-analytics.php:17
actionwp_footerpaste-analytics.php:18
Maintenance & Trust

Paste Analytics Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedOct 26, 2014
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Paste Analytics Developer Profile

Jenst

8 plugins · 290 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Paste Analytics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
large-textcode
HTML Comments
Paste Analytics is disabled for everyone!Only logged users will see this comment)Paste Analytics is not running when you are logged in!(Only logged users will see this comment)
Data Attributes
name='pasteanalytics[script]'name='pasteanalytics[active]'
FAQ

Frequently Asked Questions about Paste Analytics