SlyMetrics Security & Risk Analysis

wordpress.org/plugins/slymetrics

A comprehensive WordPress plugin that exports WordPress metrics in Prometheus format for monitoring and observability.

20 active installs v1.3.8 PHP 7.4+ WP 5.0+ Updated Feb 19, 2026
metricsmonitoringobservabilityperformanceprometheus
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SlyMetrics Safe to Use in 2026?

Generally Safe

Score 100/100

SlyMetrics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The slymetrics plugin v1.3.8 exhibits a strong security posture based on the provided static analysis and vulnerability history. The code adheres to several key security best practices, including the exclusive use of prepared statements for all SQL queries, a high percentage of properly escaped output, and the presence of nonce and capability checks. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, and bundled libraries further reduces the potential attack surface. The taint analysis showing zero flows with unsanitized paths is particularly encouraging, indicating a low risk of injection vulnerabilities. The plugin's history is clean, with no recorded vulnerabilities, which suggests a consistent commitment to security by the developers. This overall picture points to a well-secured plugin.

Vulnerabilities
None known

SlyMetrics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

SlyMetrics Release Timeline

v1.3.8Current
v1.3.7
v1.3.6
v1.3.5
v1.3.4
v1.3.3
v1.3.2
Code Analysis
Analyzed Mar 16, 2026

SlyMetrics Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
10 prepared
Unescaped Output
3
46 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared10 total queries

Output Escaping

94% escaped49 total outputs
Attack Surface

SlyMetrics Attack Surface

Entry Points1
Unprotected0

REST API Routes 1

GET/wp-json/slymetrics/v1/metricsslymetrics.php:91
WordPress Hooks 11
actionrest_api_initslymetrics.php:56
filterrest_pre_serve_requestslymetrics.php:58
actionadmin_menuslymetrics.php:63
actionadmin_initslymetrics.php:64
actionadmin_enqueue_scriptsslymetrics.php:65
actioninitslymetrics.php:71
filterquery_varsslymetrics.php:72
actionplugins_loadedslymetrics.php:76
actionparse_requestslymetrics.php:77
actioninitslymetrics.php:80
actionadmin_initslymetrics.php:83
Maintenance & Trust

SlyMetrics Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 19, 2026
PHP min version7.4
Downloads979

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

SlyMetrics Developer Profile

Timon

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SlyMetrics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/slymetrics/css/slymetrics-admin.css/wp-content/plugins/slymetrics/js/slymetrics-admin.js
Version Parameters
slymetrics/css/slymetrics-admin.css?ver=slymetrics/js/slymetrics-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
slymetrics-admin-wrap
HTML Comments
<!-- SlyMetrics Admin Settings -->
Data Attributes
data-slymetrics-nonce
JS Globals
slymetrics_admin_vars
REST Endpoints
/wp-json/slymetrics/v1/metrics
FAQ

Frequently Asked Questions about SlyMetrics