
Search Analytics for WP Security & Risk Analysis
wordpress.org/plugins/search-analyticsSearch Analytics for WP will store and display the search terms used on your website. No third-party service is used!
Is Search Analytics for WP Safe to Use in 2026?
Generally Safe
Score 97/100Search Analytics for WP has a strong security track record. Known vulnerabilities have been patched promptly.
The "search-analytics" plugin version 1.4.16 exhibits a mixed security posture. While it demonstrates good practices such as a high percentage of prepared SQL statements and properly escaped outputs, significant concerns arise from the taint analysis and its historical vulnerability record. The static analysis reveals a low attack surface with no apparent unprotected entry points, and the presence of nonce and capability checks, though the latter are notably absent (0 checks). However, the taint analysis shows a concerning 4 high-severity flows with unsanitized paths, indicating potential for input manipulation leading to vulnerabilities. The plugin's history of 4 medium-severity CVEs, primarily related to Cross-site Scripting and Missing Authorization, further exacerbates these concerns. The fact that the last vulnerability was recent (September 30, 2024) and that all previously reported CVEs are now patched is a positive sign, but the persistent nature of certain vulnerability types in the past suggests a need for ongoing vigilance and robust input validation. Overall, while the current version shows some improvements, the taint analysis findings and historical context warrant careful consideration and mitigation efforts.
Key Concerns
- High severity unsanitized taint flows
- History of medium severity CVEs
- No capability checks detected
- File operations detected
- External HTTP requests detected
Search Analytics for WP Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
WP Search Analytics <= 1.4.10 - Reflected Cross-Site Scripting
WP Search Analytics <= 1.4.9 - Missing Authorization
WP Search Analytics <= 1.4.7 - Reflected Cross-Site Scripting via 'render_stats_page'
WP Search Analytics <= 1.4.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
Search Analytics for WP Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Search Analytics for WP Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 19
Maintenance & Trust
Search Analytics for WP Maintenance & Trust
Maintenance Signals
Community Trust
Search Analytics for WP Alternatives
Search Insights – Privacy-Friendly Search Analytics
wp-search-insights
Uncover exactly what visitors search for on your site. Stop guessing what content to create, fix content gaps, and boost engagement.
PureDevs Customer History for WooCommerce
puredevs-customer-history-for-woocommerce
Track your WooCommerce customers' order history, spending, and behaviour from a clean admin dashboard.
Site Kit by Google – Analytics, Search Console, AdSense, Speed
google-site-kit
Site Kit is a one-stop solution for WordPress users to use everything Google has to offer to make them successful on the web.
GA Google Analytics – Connect Google Analytics to WordPress
ga-google-analytics
Adds Google Analytics tracking code to your WordPress site. Supports many tracking features.
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)
burst-statistics
Analytics you'll actually use. Privacy-friendly, zero config, and designed to be actionable. Get insights, not just raw data.
Search Analytics for WP Developer Profile
1 plugin · 3K total installs
How We Detect Search Analytics for WP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/search-analytics/admin/assets/js/chart.bundle.min.js/wp-content/plugins/search-analytics/admin/assets/js/chart-controller.js/wp-content/plugins/search-analytics/admin/assets/js/chart.bundle.min.js/wp-content/plugins/search-analytics/admin/assets/js/chart-controller.jssearch-analytics/admin/assets/js/chart.bundle.min.js?ver=search-analytics/admin/assets/js/chart-controller.js?ver=HTML / DOM Fingerprints
mwtsa-chart-optionsid="chart-type"id="chart-ranges"mwtsa_chart_objMWTSA_OptionsMWTSAI/wp-json/mwtsa-search-analytics/v1/search[mwtsa_display_search_stats][mwtsa_display_latest_searches]