
SFR Analytics Hub Security & Risk Analysis
wordpress.org/plugins/sfr-analytics-hubAggregate analytics from multiple WordPress sites into one central dashboard. Free for up to 3 sites — no third-party services required.
Is SFR Analytics Hub Safe to Use in 2026?
Generally Safe
Score 100/100SFR Analytics Hub has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sfr-analytics-hub" plugin v1.8.2 demonstrates a generally good security posture with several strengths. Notably, it exclusively uses prepared statements for all SQL queries and demonstrates a high rate of output escaping (95%), significantly mitigating common injection vulnerabilities. The presence of a substantial number of nonce and capability checks across its AJAX endpoints further indicates a commitment to securing its entry points. The plugin also has no recorded vulnerability history, which is a positive indicator of past security diligence.
However, the taint analysis reveals two high-severity flows with unsanitized paths. While the exact nature of these paths is not detailed, unsanitized paths are a significant concern as they can potentially lead to arbitrary file access or manipulation if user input is not properly validated before being used in file operations or other sensitive functions. The single file operation detected in the static analysis, combined with these tainted flows, warrants further investigation to ensure it's handled securely.
Overall, "sfr-analytics-hub" is built on a foundation of secure coding practices. The primary area of concern lies in the identified high-severity taint flows, which, despite the overall positive analysis, present a potential risk that needs to be addressed. The absence of past vulnerabilities is encouraging, but the current taint analysis highlights a specific area for improvement to maintain its strong security standing.
Key Concerns
- High severity taint flows with unsanitized paths
- Taint flows with unsanitized paths
SFR Analytics Hub Security Vulnerabilities
SFR Analytics Hub Release Timeline
SFR Analytics Hub Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
SFR Analytics Hub Attack Surface
AJAX Handlers 10
WordPress Hooks 18
Maintenance & Trust
SFR Analytics Hub Maintenance & Trust
Maintenance Signals
Community Trust
SFR Analytics Hub Alternatives
Independent Analytics
independent-analytics
A simple WordPress analytics plugin that is privacy-friendly, fast, and an alternative to Google Analytics.
NewStatPress
newstatpress
NewStatPress (Statpress plugin fork) is a real-time plugin to manage the visits' statistics about your blog (without external web analytics).
Post Word Counter – Content Insights Dashboard
doubledome-wordcount-details-dashboard
The Word Counter plugin offers a dedicated dashboard view that tracks the word count, post count, pages wordcount, and custom post types across your e …
Access Watch: Security and Traffic Insights
access-watch
Understand precisely the robot traffic on your website and take actions to improve performance and security.
Kin Visitantes
kin-visitantes
Track visitors to your website easily and effectively.
SFR Analytics Hub Developer Profile
7 plugins · 70 total installs
How We Detect SFR Analytics Hub
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sfr-analytics-hub/admin/css/sfranh-admin.css/wp-content/plugins/sfr-analytics-hub/admin/js/sfranh-admin.js/wp-content/plugins/sfr-analytics-hub/assets/css/sfranh-common.css/wp-content/plugins/sfr-analytics-hub/assets/js/sfranh-common.js/wp-content/plugins/sfr-analytics-hub/admin/js/sfranh-admin.js/wp-content/plugins/sfr-analytics-hub/assets/js/sfranh-common.jssfr-analytics-hub/admin/css/sfranh-admin.css?ver=sfr-analytics-hub/admin/js/sfranh-admin.js?ver=sfr-analytics-hub/assets/css/sfranh-common.css?ver=sfr-analytics-hub/assets/js/sfranh-common.js?ver=HTML / DOM Fingerprints
sfranh-dashboardsfranh-settings-pagesfranh-sites-pagesfranh-audit-log-pageSFR Analytics Hub Admin SettingsSFR Analytics Hub DashboardSFR Analytics Hub Sites ListSFR Analytics Hub Audit Logdata-sfranh-site-iddata-sfranh-site-urldata-sfranh-site-statussfranh_admin_paramssfranh_common_params/wp-json/sfr-analytics-hub/v1/settings/wp-json/sfr-analytics-hub/v1/sites