Profound Agent Analytics Security & Risk Analysis

wordpress.org/plugins/profound-agent-analytics

Profound Agent Analytics sends lightweight HTTP request logs to Profound's analytics platform for advanced bot detection and traffic analysis.

100 active installs v1.0.4 PHP 7.4+ WP 6.0+ Updated Mar 31, 2026
analyticsbot-detectionperformancesecuritytraffic-analysis
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Profound Agent Analytics Safe to Use in 2026?

Generally Safe

Score 100/100

Profound Agent Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The profound-agent-analytics plugin v1.0.3 exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates good adherence to secure coding practices, with a high percentage of SQL queries utilizing prepared statements and output being properly escaped. The absence of dangerous functions, file operations, and known vulnerabilities in its history are significant strengths. Furthermore, all identified entry points (AJAX handlers) have authentication checks, and there are no reported REST API routes or shortcodes that could pose immediate risks.

However, there are a few areas that warrant attention. The presence of 3 AJAX handlers, while protected by authentication, still represent potential attack vectors that require diligent maintenance. The single external HTTP request could be a point of vulnerability if not handled with strict validation and sanitization of any data it interacts with. The fact that no taint flows were detected is positive, but this is based on a static analysis that might not uncover all dynamic or complex vulnerabilities. The lack of any historical vulnerabilities is excellent, but it doesn't guarantee future security, and ongoing vigilance is always recommended.

Overall, the plugin is well-developed from a security perspective, with a solid foundation of secure coding. The identified strengths outweigh the minor potential concerns. Continued adherence to secure coding principles, particularly regarding external requests, and regular security reviews will help maintain this positive security profile.

Vulnerabilities
None known

Profound Agent Analytics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Profound Agent Analytics Release Timeline

v1.0.4Current
v1.0.3
v1.0.2
Code Analysis
Analyzed Mar 16, 2026

Profound Agent Analytics Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
13 prepared
Unescaped Output
6
66 escaped
Nonce Checks
5
Capability Checks
4
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

72% prepared18 total queries

Output Escaping

92% escaped72 total outputs
Attack Surface

Profound Agent Analytics Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_profound_agent_analytics_send_testincludes\class-admin.php:24
authwp_ajax_profound_agent_analytics_flush_queueincludes\class-admin.php:25
authwp_ajax_profound_agent_analytics_get_statusincludes\class-admin.php:26
WordPress Hooks 11
actionadmin_menuincludes\class-admin.php:19
actionadmin_initincludes\class-admin.php:20
actionadmin_enqueue_scriptsincludes\class-admin.php:21
actionadmin_noticesincludes\class-admin.php:22
actionplugins_loadedincludes\class-plugin.php:56
actionshutdownincludes\class-plugin.php:57
actionagent_analytics_send_logsincludes\class-plugin.php:60
actionagent_analytics_cleanup_queueincludes\class-plugin.php:67
filtercron_schedulesincludes\class-plugin.php:73
actionplugins_loadedprofound-agent-analytics.php:33
actioninitprofound-agent-analytics.php:38

Scheduled Events 4

agent_analytics_send_logs
agent_analytics_send_logs
agent_analytics_cleanup_queue
agent_analytics_send_logs
Maintenance & Trust

Profound Agent Analytics Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 31, 2026
PHP min version7.4
Downloads730

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Profound Agent Analytics Developer Profile

Profound

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Profound Agent Analytics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/profound-agent-analytics/assets/admin.css/wp-content/plugins/profound-agent-analytics/assets/admin.js
Script Paths
/wp-content/plugins/profound-agent-analytics/assets/admin.js
Version Parameters
profound-agent-analytics/assets/admin.css?ver=profound-agent-analytics/assets/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
nav-tab-wrappernav-tabnav-tab-active
Data Attributes
data-nonce
JS Globals
agentAnalytics
REST Endpoints
/wp-json/profound-agent-analytics/v1/log
FAQ

Frequently Asked Questions about Profound Agent Analytics