
Simple Yandex Metrika Security & Risk Analysis
wordpress.org/plugins/simple-yandex-metrikaEnables Yandex Metrika on all pages.
Is Simple Yandex Metrika Safe to Use in 2026?
Generally Safe
Score 85/100Simple Yandex Metrika has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'simple-yandex-metrika' plugin, in version 1.0.0, presents a generally positive security posture based on the provided static analysis and vulnerability history. The absence of any recorded CVEs, combined with the lack of critical or high-severity issues in taint analysis, suggests a well-developed and secure plugin. Furthermore, the plugin avoids dangerous functions and file operations, contributing to a reduced attack surface. The use of prepared statements for all SQL queries is a significant strength, mitigating the risk of SQL injection vulnerabilities.
However, a notable concern arises from the output escaping analysis. With one total output and 0% properly escaped, this indicates a potential for Cross-Site Scripting (XSS) vulnerabilities. Any data rendered to the user interface without proper sanitization could be exploited by attackers to inject malicious scripts. While the overall attack surface appears minimal with zero entry points found, this single instance of unescaped output represents a tangible risk that requires attention. The plugin's vulnerability history is clean, which is encouraging, but this does not negate the immediate risk identified in the current code analysis.
Key Concerns
- Unescaped output detected
Simple Yandex Metrika Security Vulnerabilities
Simple Yandex Metrika Code Analysis
Output Escaping
Simple Yandex Metrika Attack Surface
WordPress Hooks 3
Maintenance & Trust
Simple Yandex Metrika Maintenance & Trust
Maintenance Signals
Community Trust
Simple Yandex Metrika Alternatives
Counters Integration
counters-integration
You can add both are Google Analytics and Yandex Metrika counter's codes on all pages.
Web Worker Offloading
web-worker-offloading
Offloads select JavaScript execution to a Web Worker to reduce work on the main thread and improve the Interaction to Next Paint (INP) metric.
Yandex Metrica
yandex-metrica
Easy way to use Yandex Metrica on your WordPress site.
Яндекс Метрика
yandex-metrika
Яндекс Метрика для вашего сайта на WordPress.
Insert Headers and Footers Code – HT Script
insert-headers-and-footers-script
This plugin allows you to insert Google analytic code, Facebook pixel code, custom javascript, custom style in your website's header and footer.
Simple Yandex Metrika Developer Profile
7 plugins · 20 total installs
How We Detect Simple Yandex Metrika
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-yandex-metrika/js/simple-yandex-metrika.jssimple-yandex-metrika/js/simple-yandex-metrika.js?ver=HTML / DOM Fingerprints
ym