
SFR Analytics Security & Risk Analysis
wordpress.org/plugins/sfr-analyticsLightweight, privacy-focused WordPress analytics. Track pageviews, visitors, campaigns and more — all data stored locally in your own database.
Is SFR Analytics Safe to Use in 2026?
Generally Safe
Score 100/100SFR Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The sfr-analytics plugin v0.7.0 demonstrates a generally good security posture with a notable absence of historical vulnerabilities and a strong emphasis on secure coding practices. The plugin correctly implements nonce and capability checks for its entry points and utilizes prepared statements for the vast majority of its SQL queries. Furthermore, output escaping is also handled well, indicating a proactive approach to preventing common web vulnerabilities. However, the static analysis did identify three high-severity taint flows with unsanitized paths. While these flows did not directly lead to critical vulnerabilities in this analysis, they represent a potential risk that warrants careful investigation. The lack of any recorded CVEs, even for older versions, is a positive indicator of consistent security efforts, but the presence of high-severity taint flows suggests that continued vigilance and code review are necessary.
Key Concerns
- High severity taint flows with unsanitized paths
SFR Analytics Security Vulnerabilities
SFR Analytics Release Timeline
SFR Analytics Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
SFR Analytics Attack Surface
AJAX Handlers 9
REST API Routes 14
WordPress Hooks 16
Scheduled Events 2
Maintenance & Trust
SFR Analytics Maintenance & Trust
Maintenance Signals
Community Trust
SFR Analytics Alternatives
Statify
statify
Visitor statistics for WordPress with focus on data protection, transparency and clarity. Perfect as a widget in your WordPress Dashboard.
Simple Webstats
simple-webstats
Privacy-focused cookie-free web analytics for WordPress.
WEBFUL Analytics
webful
Ultra-lightweight and privacy-friendly traffic analytics system for your WordPress site.
Scoby Analytics
scoby-analytics
Privacy-focused analytics for WordPress — designed to minimize data protection risk under EU GDPR and ePrivacy.
Easy Media Statistics
easy-media-statistics
Get detailed insights into visitors behavior when they listen to audio or view videos on your site - privacy-friendly.
SFR Analytics Developer Profile
7 plugins · 70 total installs
How We Detect SFR Analytics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sfr-analytics/assets/css/admin.css/wp-content/plugins/sfr-analytics/assets/vendor/chart-js/chart.min.js/wp-content/plugins/sfr-analytics/assets/js/admin.js/wp-content/plugins/sfr-analytics/assets/js/admin.jssfr-analytics/assets/css/admin.css?ver=sfr-analytics/assets/js/admin.js?ver=HTML / DOM Fingerprints
SFRAN_PLUGIN_URLSFRAN_VERSION