
Post-Analytics Security & Risk Analysis
wordpress.org/plugins/post-analyticsAdd Google Analytics Statistics on Admin Edit Screen for Posts and Pages.
Is Post-Analytics Safe to Use in 2026?
Generally Safe
Score 85/100Post-Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'post-analytics' plugin version 1.01 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by having zero reported CVEs, indicating a historical lack of significant security flaws. The static analysis also reveals a complete absence of dangerous functions, raw SQL queries, and taint flows, which are excellent indicators of secure coding. However, several concerning areas warrant attention. The complete lack of nonce checks and capability checks is a significant weakness, as it leaves potential entry points vulnerable to unauthorized access and manipulation. The low percentage of properly escaped output (19%) is another major concern, as it suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities where user-supplied data could be injected into the page. The presence of file operations and external HTTP requests without explicit security checks also introduces potential attack vectors. While the plugin has no recorded history of vulnerabilities and a seemingly small attack surface, the identified code signals of missing authentication and output sanitization present tangible risks that could be exploited if an attacker identifies specific functions to target. The plugin's strength lies in its lack of historical issues and clean query handling, but its weaknesses in input validation and output sanitization are critical concerns that outweigh its strengths.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Low output escaping rate (19%)
- File operations without apparent checks
- External HTTP requests without apparent checks
Post-Analytics Security Vulnerabilities
Post-Analytics Code Analysis
Output Escaping
Post-Analytics Attack Surface
WordPress Hooks 5
Maintenance & Trust
Post-Analytics Maintenance & Trust
Maintenance Signals
Community Trust
Post-Analytics Alternatives
WP-SEOstats
wp-seostats
Add SEO stats to the Admin Toolbar in every page/post and also in the edit page/post.
SEO SIMPLE PACK
seo-simple-pack
This is a very simple SEO plugin. You can easily set and customize meta tags and OGP tags for each page.
CallRail Phone Call Tracking
callrail-phone-call-tracking
Dynamically swap CallRail tracking phone numbers based on the visitor's referring source.
Website Optimization – Plerdy
plerdy-heatmap
Optimize your website with Plerdy by analyzing traffic sources, scroll depth, user clicks, and usability to enhance conversion and strategy.
SEO Engine
seo-engine
Made it through the SEO plugin wasteland? You've earned a coffee ☺️ Quietly powerful AI SEO that actually works. No bloat, just results. Enjoy! 💕
Post-Analytics Developer Profile
4 plugins · 50 total installs
How We Detect Post-Analytics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-analytics/css/stylesheet.css/css/stylesheet.css?ver=HTML / DOM Fingerprints
post-analtyics-titlecell