Simple Yandex Metrika Security & Risk Analysis

wordpress.org/plugins/simple-yandex-metrika

Enables Yandex Metrika on all pages.

10 active installs v1.0.0 PHP + WP 4.5.0+ Updated May 12, 2021
analyticsjavascriptyandexyandexmetrika
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Simple Yandex Metrika Safe to Use in 2026?

Generally Safe

Score 85/100

Simple Yandex Metrika has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The 'simple-yandex-metrika' plugin, in version 1.0.0, presents a generally positive security posture based on the provided static analysis and vulnerability history. The absence of any recorded CVEs, combined with the lack of critical or high-severity issues in taint analysis, suggests a well-developed and secure plugin. Furthermore, the plugin avoids dangerous functions and file operations, contributing to a reduced attack surface. The use of prepared statements for all SQL queries is a significant strength, mitigating the risk of SQL injection vulnerabilities.

However, a notable concern arises from the output escaping analysis. With one total output and 0% properly escaped, this indicates a potential for Cross-Site Scripting (XSS) vulnerabilities. Any data rendered to the user interface without proper sanitization could be exploited by attackers to inject malicious scripts. While the overall attack surface appears minimal with zero entry points found, this single instance of unescaped output represents a tangible risk that requires attention. The plugin's vulnerability history is clean, which is encouraging, but this does not negate the immediate risk identified in the current code analysis.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Simple Yandex Metrika Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Simple Yandex Metrika Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Simple Yandex Metrika Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_inityandexmetrika.php:82
actionadmin_menuyandexmetrika.php:83
actionwp_headyandexmetrika.php:95
Maintenance & Trust

Simple Yandex Metrika Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.0
Last updatedMay 12, 2021
PHP min version
Downloads815

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Simple Yandex Metrika Developer Profile

Hayk Chamyan

7 plugins · 20 total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple Yandex Metrika

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/simple-yandex-metrika/js/simple-yandex-metrika.js
Version Parameters
simple-yandex-metrika/js/simple-yandex-metrika.js?ver=

HTML / DOM Fingerprints

JS Globals
ym
FAQ

Frequently Asked Questions about Simple Yandex Metrika