Podcast Analytics for OP3 Security & Risk Analysis

wordpress.org/plugins/podcast-analytics-for-op3

Integrate OP3 open podcast analytics with WordPress: prefix your feed automatically and view download stats in your dashboard.

10 active installs v2.7.0 PHP 8.0+ WP 6.3+ Updated Jul 15, 2026
analyticsfeedop3podcaststatistics
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Podcast Analytics for OP3 Safe to Use in 2026?

Generally Safe

Score 100/100

Podcast Analytics for OP3 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "podcast-analytics-for-op3" plugin v2.0.7 exhibits a generally good security posture with a low risk profile based on the provided analysis. The plugin demonstrates strong adherence to secure coding practices, with a high percentage of properly escaped output and all SQL queries utilizing prepared statements. The absence of known vulnerabilities in its history further suggests a well-maintained and secure codebase. However, there is one significant area of concern: an unprotected AJAX handler represents a potential entry point for attackers. While the taint analysis found no critical or high-severity issues, and dangerous functions are minimal, the lack of authentication on an AJAX endpoint is a notable weakness that could be exploited if that handler performs sensitive operations or exposes information.

Key Concerns

  • AJAX handler without authentication
  • Presence of a dangerous function (preg_replace(/e))
Vulnerabilities
None known

Podcast Analytics for OP3 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Podcast Analytics for OP3 Release Timeline

v2.7.0Current
v2.6.4
v2.6.3
v2.6.0
v2.4.0
v2.3.1
v2.3.0
v2.2.0
v2.1.0
v2.0.8
v2.0.7
v2.0.6
v2.0.2
v1.0.2
Code Analysis
Analyzed Apr 16, 2026

Podcast Analytics for OP3 Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
2 prepared
Unescaped Output
2
157 escaped
Nonce Checks
2
Capability Checks
5
File Operations
0
External Requests
1
Bundled Libraries
0

Dangerous Functions Found

preg_replace(/e)preg_replace( '#^https://op3\.dev/eincludes/class-op3pa-api.php:234

SQL Query Safety

100% prepared2 total queries

Output Escaping

99% escaped159 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
handle_save (includes/class-op3pa-admin.php:146)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Podcast Analytics for OP3 Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 2

authwp_ajax_op3pa_refresh_statsincludes/class-op3pa-admin.php:23
authwp_ajax_op3pa_refresh_networkincludes/class-op3pa-admin.php:24
WordPress Hooks 11
actionadmin_menuincludes/class-op3pa-admin.php:19
actionadmin_initincludes/class-op3pa-admin.php:20
actionadmin_enqueue_scriptsincludes/class-op3pa-admin.php:21
actionwp_dashboard_setupincludes/class-op3pa-admin.php:22
actionadmin_noticesincludes/class-op3pa-admin.php:25
actionadmin_noticesincludes/class-op3pa-admin.php:186
actiontemplate_redirectincludes/class-op3pa-feed.php:28
actionshutdownincludes/class-op3pa-feed.php:39
actionplugins_loadedpodcast-analytics-for-op3.php:89
actionplugins_loadedpodcast-analytics-for-op3.php:90
actionplugins_loadedpodcast-analytics-for-op3.php:91
Maintenance & Trust

Podcast Analytics for OP3 Maintenance & Trust

Maintenance Signals

WordPress version tested7.0.2
Last updatedJul 15, 2026
PHP min version8.0
Downloads656

Community Trust

Rating100/100
Number of ratings6
Active installs10
Developer Profile

Podcast Analytics for OP3 Developer Profile

Miguel Angel Terrón

2 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Podcast Analytics for OP3

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/podcast-analytics-for-op3/admin/css/admin.css/wp-content/plugins/podcast-analytics-for-op3/admin/js/admin.js
Script Paths
/wp-content/plugins/podcast-analytics-for-op3/admin/js/admin.js
Version Parameters
podcast-analytics-for-op3/admin/css/admin.css?ver=podcast-analytics-for-op3/admin/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
op3-podcast-analyticsop3pa-settings-formop3pa-stats-widgetop3pa-network-stats-widget
HTML Comments
<!-- Admin UI: settings page, statistics subpage, and dashboard widget. --><!-- Settings --><!-- Statistics --><!-- OP3 Podcast Analytics Dashboard Widget -->+4 more
Data Attributes
data-nonce-key="op3pa_settings_nonce"data-nonce-action="op3pa_save_settings"data-refresh-stats-urldata-refresh-network-urldata-podcast-indexdata-podcast-name
JS Globals
op3pa_admin_varsop3pa_refresh_statsop3pa_refresh_network
REST Endpoints
/wp-json/op3pa/v1/refresh_stats/wp-json/op3pa/v1/refresh_network
FAQ

Frequently Asked Questions about Podcast Analytics for OP3