Quick Analytics Security & Risk Analysis

wordpress.org/plugins/quick-analytics

A simple plugin that helps you to integrate quickly your analytics tracking IDs.

10 active installs v1.0.0 PHP 5.6+ WP 3.0+ Updated Sep 29, 2018
googlekissmetricsmixpanelwooprayandex-metrika
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Quick Analytics Safe to Use in 2026?

Generally Safe

Score 85/100

Quick Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

Based on the static analysis and vulnerability history, the "quick-analytics" plugin v1.0.0 presents a generally good security posture with no known vulnerabilities or critical code signals detected. The absence of dangerous functions, file operations, external HTTP requests, and SQL queries not using prepared statements are all positive indicators. The presence of capability checks and proper output escaping for a majority of outputs further reinforces this. However, the complete lack of nonces and the fact that all entry points (AJAX, REST API, shortcodes, cron) are zero, and therefore have no auth checks, is a significant concern. While no vulnerabilities are currently evident, this lack of specific authorization mechanisms on potential future entry points or within the current limited code could become a weakness if the plugin evolves or new attack vectors are discovered. The absence of any recorded vulnerabilities in its history is positive, suggesting a proactive approach to security from the developers or a lack of attention from attackers, but this should not be solely relied upon for long-term security.

Key Concerns

  • No nonce checks implemented
  • No unprotected entry points found, but no auth checks evident on zero entry poin
  • Only 65% of output is properly escaped
Vulnerabilities
None known

Quick Analytics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Quick Analytics Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
23
42 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

65% escaped65 total outputs
Attack Surface

Quick Analytics Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_menuincludes\admin\class-qa-admin.php:52
actionadmin_initincludes\admin\class-qa-admin.php:53
actionafter_setup_themeincludes\public\class-qa-public.php:53
actionquick_analytics_beforeincludes\public\class-qa-public.php:72
actionwp_headincludes\public\class-qa-public.php:76
actionwp_footerincludes\public\class-qa-public.php:80
actionplugins_loadedquick-analytics.php:64
actioninitquick-analytics.php:65
Maintenance & Trust

Quick Analytics Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedSep 29, 2018
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Quick Analytics Developer Profile

Thibault Crouzet

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Quick Analytics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

HTML Comments
<!-- Google Analytics --><!-- End Google Analytics --><!-- Yandex Metrika --><!-- End Yandex Metrika -->+3 more
JS Globals
window.yaCounterwindow.mixpanelwindow.analytics
FAQ

Frequently Asked Questions about Quick Analytics