
Trackboxx Analytics Security & Risk Analysis
wordpress.org/plugins/trackboxx-analyticsA simple, GDPR compliant Google Analytics alternative.
Is Trackboxx Analytics Safe to Use in 2026?
Generally Safe
Score 100/100Trackboxx Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The trackboxx-analytics plugin version 1.4.0 demonstrates a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a clean vulnerability history is a significant positive indicator. Furthermore, the code exhibits excellent practices regarding SQL queries, exclusively using prepared statements, and a high percentage of properly escaped output, mitigating common injection and Cross-Site Scripting (XSS) risks.
The static analysis reveals a limited attack surface, with only two AJAX handlers and no REST API routes, shortcodes, or cron events. Crucially, none of these entry points appear to be unprotected, as indicated by the absence of unprotected AJAX handlers and permission callbacks for REST API routes.
While the plugin's security is robust, the presence of one external HTTP request warrants careful consideration. Although not inherently a vulnerability, such requests can sometimes be exploited if the remote endpoint is compromised or if the data sent/received is not properly validated or escaped. Overall, the plugin shows commendable attention to security best practices, with minimal identified risks.
Key Concerns
- One external HTTP request
Trackboxx Analytics Security Vulnerabilities
Trackboxx Analytics Code Analysis
Output Escaping
Data Flow Analysis
Trackboxx Analytics Attack Surface
AJAX Handlers 2
WordPress Hooks 17
Maintenance & Trust
Trackboxx Analytics Maintenance & Trust
Maintenance Signals
Community Trust
Trackboxx Analytics Alternatives
Plausible Analytics
plausible-analytics
Plausible Analytics is a privacy-friendly web analytics plugin for WordPress that is an easy-to-use, lightweight and more accurate alternative to Goo …
Usermaven
usermaven
Usermaven's web analytics product is a Google Analytics alternative that provides a real-time view of your website traffic metrics.
Koko Analytics – Privacy Friendly Statistics for WordPress
koko-analytics
Koko Analytics is a privacy-friendly statistics plugin for WordPress that is an easy to use alternative to Google Analytics.
Fathom Analytics for WP
fathom-analytics
Fathom is a simple, GDPR compliant Google Analytics alternative.
WP Statistics – Simple, privacy-friendly Google Analytics alternative
wp-statistics
Get website traffic insights with GDPR/CCPA compliant, privacy-friendly analytics. Includes visitor data, stunning graphs, and no data sharing.
Trackboxx Analytics Developer Profile
1 plugin · 70 total installs
How We Detect Trackboxx Analytics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/trackboxx-analytics/admin/css/trackboxx-admin.csstrackboxx-admin.css?ver=trackboxx-analytics/admin/css/trackboxx-admin.css?ver=HTML / DOM Fingerprints
tb-tracking-allowed<!-- trackboxx_analytics_tracking_code -->data-tb-tracking-iddata-tb-campaign-iddata-tb-sourcedata-tb-mediumdata-tb-contentdata-tb-termtrackboxxHelperTrackboxx/wp-json/trackboxx-analytics/v1/settings