Store Analytics Lite for WooCommerce (KPI Dashboard & Reports) Security & Risk Analysis

wordpress.org/plugins/store-analytics-woo-lite

WooCommerce analytics dashboard with 6 core KPIs, charts & reports. 100% private—processed locally.

0 active installs v2.2.3 PHP 7.4+ WP 6.0+ Updated Unknown
analyticsdashboardkpireportswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Store Analytics Lite for WooCommerce (KPI Dashboard & Reports) Safe to Use in 2026?

Generally Safe

Score 100/100

Store Analytics Lite for WooCommerce (KPI Dashboard & Reports) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "store-analytics-woo-lite" v2.2.3 plugin demonstrates a strong security posture based on the provided static analysis. The plugin has a minimal attack surface, with only one AJAX handler, and importantly, this handler includes authentication checks, indicating good practice for protecting entry points. The code also shows excellent adherence to secure coding standards, with all SQL queries utilizing prepared statements, no dangerous functions detected, and no file operations or external HTTP requests. Furthermore, the presence of both nonce and capability checks suggests a deliberate effort to implement proper authorization and validation mechanisms.

While the static analysis reveals no critical or high-severity issues in taint flows or unsanitized paths, the limited output escaping (only 67% properly escaped) is a potential concern. Although the number of outputs is small, any unescaped output could lead to cross-site scripting (XSS) vulnerabilities if user-controlled data is involved. The plugin's vulnerability history is also a positive indicator, with no recorded CVEs, suggesting a history of secure development and maintenance. Overall, this plugin appears to be well-secured, with the primary area for improvement being the complete elimination of unescaped output.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Store Analytics Lite for WooCommerce (KPI Dashboard & Reports) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Store Analytics Lite for WooCommerce (KPI Dashboard & Reports) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
2 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped3 total outputs
Attack Surface

Store Analytics Lite for WooCommerce (KPI Dashboard & Reports) Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_spd_get_metricsstore-performance-dashboard-lite.php:34
WordPress Hooks 3
actionplugins_loadedstore-performance-dashboard-lite.php:28
actionadmin_menustore-performance-dashboard-lite.php:32
actionadmin_enqueue_scriptsstore-performance-dashboard-lite.php:33
Maintenance & Trust

Store Analytics Lite for WooCommerce (KPI Dashboard & Reports) Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.4
Downloads239

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Store Analytics Lite for WooCommerce (KPI Dashboard & Reports) Developer Profile

Auscomp

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Store Analytics Lite for WooCommerce (KPI Dashboard & Reports)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/store-analytics-woo-lite/assets/css/admin.css/wp-content/plugins/store-analytics-woo-lite/assets/vendor/chartjs/chart.umd.js/wp-content/plugins/store-analytics-woo-lite/assets/vendor/jsvectormap/jsvectormap.min.css/wp-content/plugins/store-analytics-woo-lite/assets/vendor/jsvectormap/jsvectormap.min.js/wp-content/plugins/store-analytics-woo-lite/assets/vendor/jsvectormap/maps/world-merc.js/wp-content/plugins/store-analytics-woo-lite/assets/js/dashboard.js
Script Paths
/wp-content/plugins/store-analytics-woo-lite/assets/js/dashboard.js
Version Parameters
store-analytics-woo-lite/assets/css/admin.css?ver=store-analytics-woo-lite/assets/js/dashboard.js?ver=

HTML / DOM Fingerprints

CSS Classes
spd-wrapspd-darkspd-headerspd-titlespd-controlsspd-selectspd-gridspd-settings-panel+10 more
Data Attributes
id="spd-root"id="spd-period"id="spd-mode-toggle"id="spd-about-toggle"id="spd-settings-toggle"id="spd-grid"+8 more
JS Globals
SPD
REST Endpoints
/wp-json/store-analytics-woo-lite/v1/metrics
FAQ

Frequently Asked Questions about Store Analytics Lite for WooCommerce (KPI Dashboard & Reports)