Smalk AI Analytics Security & Risk Analysis

wordpress.org/plugins/smalk-ai-analytics

Monitor AI Search visitors to your website and optimize content for AI-driven search engines like ChatGPT, Perplexity, Google AIO, etc...

40 active installs v1.0.14 PHP 7.0+ WP 5.0+ Updated Mar 10, 2026
ai-crawlersanswer-engine-optimizationgenerative-engine-optimization
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Smalk AI Analytics Safe to Use in 2026?

Generally Safe

Score 100/100

Smalk AI Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 24d ago
Risk Assessment

The 'smalk-ai-analytics' v1.0.14 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of identifiable entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code demonstrates good practices by exclusively using prepared statements for SQL queries and a high percentage of properly escaped output, indicating a focus on preventing common web vulnerabilities. The lack of recorded vulnerabilities in its history also suggests a well-maintained and secure development process.

However, there are a few areas that warrant attention. The absence of nonce checks on any entry points (though there are none) is a potential concern, as is the presence of file operations and external HTTP requests without explicit mention of their security handling. While no critical taint flows were identified, the limited taint analysis (0 flows analyzed) means that the effectiveness of sanitization for any potential flows remains unverified. The single capability check suggests that access control might be narrowly implemented, potentially leaving other actions exposed if new entry points were to be introduced without proper checks.

In conclusion, 'smalk-ai-analytics' v1.0.14 appears to be a secure plugin with minimal known risks. The core of its functionality seems well-protected. The primary weaknesses lie in the potential for future vulnerabilities if new entry points are added without robust security measures like nonce and capability checks, and the limited scope of the taint analysis. The lack of historical vulnerabilities is a significant positive indicator.

Key Concerns

  • No nonce checks on potential entry points
  • File operations present without explicit security context
  • External HTTP requests present without explicit security context
  • Limited taint analysis scope (0 flows analyzed)
Vulnerabilities
None known

Smalk AI Analytics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Smalk AI Analytics Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
52 escaped
Nonce Checks
0
Capability Checks
1
File Operations
2
External Requests
2
Bundled Libraries
0

Output Escaping

93% escaped56 total outputs
Attack Surface

Smalk AI Analytics Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 23
actioninitincludes\analytics.php:62
actionwp_headincludes\analytics.php:149
filterrocket_exclude_jsincludes\analytics.php:203
filterautoptimize_filter_js_excludeincludes\analytics.php:210
filterw3tc_minify_js_do_tag_minificationincludes\analytics.php:215
filterlitespeed_optimize_js_excludesincludes\analytics.php:225
filterwpfc_exclude_current_pageincludes\analytics.php:232
actionwp_headincludes\analytics.php:241
filtersgo_js_minify_excludeincludes\analytics.php:249
filterwp_hummingbird_is_minify_excluded_urlincludes\analytics.php:256
filterflying_press_exclude_jsincludes\analytics.php:264
filterwpacu_skip_assets_settings_callincludes\analytics.php:270
actioninitincludes\analytics.php:277
actionsend_headersincludes\analytics.php:294
actiontemplate_redirectincludes\analytics.php:303
filterscript_loader_tagincludes\analytics.php:313
filtercron_schedulesincludes\cron.php:14
actioninitincludes\cron.php:28
actionadmin_initincludes\settings.php:146
actionadmin_noticesincludes\settings.php:245
actionadmin_menuincludes\settings.php:286
actionadmin_enqueue_scriptsincludes\settings.php:302
actionupdate_optionincludes\variables.php:44
Maintenance & Trust

Smalk AI Analytics Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 10, 2026
PHP min version7.0
Downloads2K

Community Trust

Rating100/100
Number of ratings3
Active installs40
Developer Profile

Smalk AI Analytics Developer Profile

Smalker001

1 plugin · 40 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Smalk AI Analytics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/smalk-ai-analytics/assets/js/tracker.js
Version Parameters
smalk-ai-analytics/assets/js/tracker.js?ver=

HTML / DOM Fingerprints

HTML Comments
Smalk AI Agent Analytics - Enhanced Dynamic Loading
Data Attributes
data-no-minifydata-cfasyncdata-no-optimizedata-skip-minification
JS Globals
window.smalkAnalyticsLoadedwindow.smalkTrackerLoaded
REST Endpoints
/wp-json/smalk-ai-analytics/v1/settings
FAQ

Frequently Asked Questions about Smalk AI Analytics