Romiltec Analytics Tracking Security & Risk Analysis

wordpress.org/plugins/romiltec-analytics-tracking

Professional Matomo analytics integration with automatic Post ID tracking as custom dimensions.

30 active installs v1.0.0 PHP 7.4+ WP 5.0+ Updated Feb 9, 2026
analyticsmatomometricsstatisticstracking
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Romiltec Analytics Tracking Safe to Use in 2026?

Generally Safe

Score 100/100

Romiltec Analytics Tracking has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'romiltec-analytics-tracking' v1.0.0 plugin exhibits a generally good security posture. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the analysis shows no dangerous functions, no SQL queries without prepared statements, and no file operations or external HTTP requests, all of which are positive indicators. However, a notable concern is the presence of capability checks without corresponding nonce checks, which could potentially expose functionality if not properly implemented elsewhere or if the capability check itself is insufficient. The limited output escaping (73%) also presents a minor risk, as it leaves a portion of outputs vulnerable to cross-site scripting (XSS) attacks if sensitive data is displayed without proper sanitization. The plugin's vulnerability history is clean, with no recorded CVEs, which suggests a history of secure development or minimal public exposure of its codebase. Overall, while the plugin has a small attack surface and good practices in critical areas like SQL, the lack of comprehensive nonce checks and imperfect output escaping represent areas for improvement.

Key Concerns

  • Capability checks without nonce checks
  • Output escaping is not 100%
Vulnerabilities
None known

Romiltec Analytics Tracking Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Romiltec Analytics Tracking Release Timeline

v1.0.0Current
Code Analysis
Analyzed Mar 16, 2026

Romiltec Analytics Tracking Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
16 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

73% escaped22 total outputs
Attack Surface

Romiltec Analytics Tracking Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionwp_enqueue_scriptsincludes\class-romiltec-analytics-tracker.php:52
actionadmin_initincludes\class-romiltec-analytics-tracker.php:55
actionadmin_menuincludes\class-romiltec-analytics-tracker.php:56
actionadmin_enqueue_scriptsincludes\class-romiltec-analytics-tracker.php:57
actionplugins_loadedromiltec-analytics-tracking.php:43
Maintenance & Trust

Romiltec Analytics Tracking Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 9, 2026
PHP min version7.4
Downloads181

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Romiltec Analytics Tracking Developer Profile

romiltecsrl

1 plugin · 30 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Romiltec Analytics Tracking

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/romiltec-analytics-tracking/assets/js/romiltec-analytics-tracking.js
Script Paths
/wp-content/plugins/romiltec-analytics-tracking/assets/js/romiltec-analytics-tracking.js
Version Parameters
romiltec-analytics-tracking/assets/js/romiltec-analytics-tracking.js?ver=

HTML / DOM Fingerprints

HTML Comments
/* track post id custom dimension 1 */
JS Globals
window._paq
FAQ

Frequently Asked Questions about Romiltec Analytics Tracking