Quantcast Quantifier Security & Risk Analysis

wordpress.org/plugins/quantcast-quantifier

Allows you to easily add the necessary JavaScript code to enable Quantcast on your blog.

100 active installs v1.5.2 PHP + WP 2.5+ Updated Jun 17, 2011
quantcastquantifystatisticsstatstracking
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Quantcast Quantifier Safe to Use in 2026?

Generally Safe

Score 85/100

Quantcast Quantifier has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The static analysis of the "quantcast-quantifier" plugin version 1.5.2 reveals a generally good security posture with no identified critical or high severity issues in the code signals or taint analysis. The plugin demonstrates good practices by having no direct SQL queries that are not prepared statements and implementing a nonce check. Furthermore, the absence of recorded vulnerabilities in its history indicates a consistent track record of security. However, a significant concern arises from the extremely low percentage of properly escaped output (11%). This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data could potentially be rendered directly in the browser without proper sanitization. While the attack surface appears minimal and protected, the output escaping deficiency is a major weakness that needs immediate attention.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Quantcast Quantifier Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Quantcast Quantifier Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
1 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

11% escaped9 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
qq_options_page (quantcast-quantifier.php:86)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Quantcast Quantifier Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterplugin_action_linksquantcast-quantifier.php:350
actionadmin_menuquantcast-quantifier.php:353
actionwp_headquantcast-quantifier.php:356
actionwp_footerquantcast-quantifier.php:357
Maintenance & Trust

Quantcast Quantifier Maintenance & Trust

Maintenance Signals

WordPress version tested3.1.4
Last updatedJun 17, 2011
PHP min version
Downloads18K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Quantcast Quantifier Developer Profile

Jandal

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Quantcast Quantifier

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/quantcast-quantifier/js/quantcast-quantifier.js
Version Parameters
quantcast-quantifier/js/quantcast-quantifier.js?ver=

HTML / DOM Fingerprints

Data Attributes
id="qq_status"name="qq_status"id="qq_admin"name="qq_admin"id="qq_admin_role"name="qq_admin_role"+4 more
FAQ

Frequently Asked Questions about Quantcast Quantifier