
Referrer Analytics Security & Risk Analysis
wordpress.org/plugins/referrer-analyticsTrack & store where users come from for enhanced reporting in Google Analytics, on-site statistics, conversion tracking & more.
Is Referrer Analytics Safe to Use in 2026?
Generally Safe
Score 85/100Referrer Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The referrer-analytics plugin v2.0.1 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any identified attack surface entry points like AJAX handlers, REST API routes, shortcodes, or cron events is a significant strength, indicating a well-contained plugin. Furthermore, the code signals are largely positive, with a high percentage of properly escaped outputs and a commendable use of prepared statements for SQL queries. The presence of nonce and capability checks, even though limited, suggests an awareness of secure coding practices.
However, a closer look reveals a few minor areas for improvement. While the overall output escaping is high, there's a small chance that the 9% of outputs not properly escaped could lead to cross-site scripting (XSS) vulnerabilities if sensitive data is handled and not escaped. The single nonce check might be insufficient depending on the plugin's functionality, and while the capability checks are present, their coverage is not specified. The fact that no taint flows were identified is excellent, reinforcing the plugin's good handling of user-supplied data. The clean vulnerability history with zero recorded CVEs further solidifies its secure reputation.
In conclusion, referrer-analytics v2.0.1 appears to be a secure plugin with a robust design that minimizes its attack surface. Its development team seems to follow good security practices, as evidenced by the low risk indicators in the static analysis and the absence of past vulnerabilities. The primary, albeit minor, concern lies in the potential for XSS from the unescaped outputs. For a plugin with no other identified weaknesses, this is a very positive assessment, but continuous vigilance is always recommended.
Key Concerns
- Potential for XSS from unescaped output
Referrer Analytics Security Vulnerabilities
Referrer Analytics Release Timeline
Referrer Analytics Code Analysis
SQL Query Safety
Output Escaping
Referrer Analytics Attack Surface
WordPress Hooks 8
Maintenance & Trust
Referrer Analytics Maintenance & Trust
Maintenance Signals
Community Trust
Referrer Analytics Alternatives
GA Google Analytics – Connect Google Analytics to WordPress
ga-google-analytics
Adds Google Analytics tracking code to your WordPress site. Supports many tracking features.
Independent Analytics
independent-analytics
A simple WordPress analytics plugin that is privacy-friendly, fast, and an alternative to Google Analytics.
Koko Analytics – Privacy Friendly Statistics for WordPress
koko-analytics
Koko Analytics is a privacy-friendly statistics plugin for WordPress that is an easy to use alternative to Google Analytics.
Better Google Analytics
better-analytics
Track everything with Google Analytics (clicked links, emails opened, YouTube videos being watched, etc.). Includes real time Analytics dashboard.
Enhanced Ecommerce Google Analytics for WooCommerce
woo-ecommerce-tracking-for-google-and-facebook
Track sales analytics, conversions and understand consumer behavior using google analytics (with ecommerce tracking).
Referrer Analytics Developer Profile
5 plugins · 20K total installs
How We Detect Referrer Analytics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/referrer-analytics/assets/css/frontend.css/wp-content/plugins/referrer-analytics/assets/js/frontend.js/wp-content/plugins/referrer-analytics/assets/js/vendor/jquery.cookie.min.js/wp-content/plugins/referrer-analytics/assets/js/frontend.js/wp-content/plugins/referrer-analytics/assets/js/vendor/jquery.cookie.min.jsreferrer-analytics/assets/css/frontend.css?ver=referrer-analytics/assets/js/frontend.js?ver=referrer-analytics/assets/js/vendor/jquery.cookie.min.js?ver=HTML / DOM Fingerprints
<!-- Referrer Analytics tracking snippet -->data-referrer-analytics-trackingreferrerAnalyticsConfig