Pk Google Analytics Security & Risk Analysis

wordpress.org/plugins/phpsword-google-analytics

Easily add Google Analytics code to your WordPress website. Also insert analytics or tracking codes of other website and services.

400 active installs v3.0 PHP 7.0+ WP 5.6+ Updated Jul 31, 2022
googlegoogle-analyticgoogle-analyticspktracking
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Pk Google Analytics Safe to Use in 2026?

Generally Safe

Score 85/100

Pk Google Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "phpsword-google-analytics" v3.0 plugin exhibits a seemingly strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a clean vulnerability history suggests a history of responsible development or a lack of targeted exploitation. The static analysis also shows a lack of dangerous functions, no SQL queries without prepared statements, no file operations, and no external HTTP requests, which are all positive indicators. Furthermore, there are no identified REST API routes, shortcodes, cron events, or AJAX handlers with potentially unprotected entry points, significantly reducing the plugin's attack surface. However, the analysis does highlight a critical concern: 100% of output is not properly escaped. This means that any dynamic data displayed by the plugin could be vulnerable to Cross-Site Scripting (XSS) attacks, allowing attackers to inject malicious scripts into the user's browser. While the overall attack surface is minimal and the plugin has no known vulnerabilities, this unescaped output presents a tangible risk that requires immediate attention.

Key Concerns

  • 100% of outputs are not properly escaped
Vulnerabilities
None known

Pk Google Analytics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Pk Google Analytics Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

Pk Google Analytics Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menuadmin\admin-menu.php:34
actionadmin_initincludes\class-pk-analytics.php:17
actionwp_footerincludes\class-pk-analytics.php:19
Maintenance & Trust

Pk Google Analytics Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJul 31, 2022
PHP min version7.0
Downloads14K

Community Trust

Rating100/100
Number of ratings3
Active installs400
Developer Profile

Pk Google Analytics Developer Profile

Pradnyankur Nikam

3 plugins · 910 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Pk Google Analytics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
phpsw_analytics_options[analytics_code]phpsw_analytics_options[phpsw_analytics_option]
FAQ

Frequently Asked Questions about Pk Google Analytics