
Usermaven Security & Risk Analysis
wordpress.org/plugins/usermavenUsermaven's web analytics product is a Google Analytics alternative that provides a real-time view of your website traffic metrics.
Is Usermaven Safe to Use in 2026?
Generally Safe
Score 99/100Usermaven has a strong security track record. Known vulnerabilities have been patched promptly.
The Usermaven v1.2.7 plugin exhibits a generally positive security posture with strong adherence to several best practices. The static analysis reveals a very limited attack surface with no unprotected AJAX handlers, REST API routes, or shortcodes. The plugin also demonstrates excellent SQL query handling, with 100% of queries using prepared statements, and a high rate of output escaping (97%). The absence of dangerous functions, file operations, and critical/high severity taint flows further indicates a commitment to secure coding. However, there are areas for improvement. The presence of 2 external HTTP requests warrants careful scrutiny to ensure they are not exploitable. More significantly, the plugin has a history of known vulnerabilities, including one CVE recorded. While currently unpatched CVEs are zero, the fact that a medium severity vulnerability has been recorded in the past, particularly of the Cross-Site Request Forgery (CSRF) type, suggests that past security oversights have occurred. This history, combined with a complete absence of capability checks, leaves room for concern regarding privilege escalation or unauthorized actions if other security mechanisms were to fail.
Key Concerns
- Medium severity vulnerability in history
- 2 external HTTP requests
- 0 capability checks found
Usermaven Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Usermaven <= 1.2.1 - Cross-Site Request Forgery
Usermaven Code Analysis
Output Escaping
Data Flow Analysis
Usermaven Attack Surface
WordPress Hooks 41
Scheduled Events 1
Maintenance & Trust
Usermaven Maintenance & Trust
Maintenance Signals
Community Trust
Usermaven Alternatives
Plausible Analytics
plausible-analytics
Plausible Analytics is a privacy-friendly web analytics plugin for WordPress that is an easy-to-use, lightweight and more accurate alternative to Goo …
Trackboxx Analytics
trackboxx-analytics
A simple, GDPR compliant Google Analytics alternative.
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)
burst-statistics
Analytics you'll actually use. Privacy-friendly, zero config, and designed to be actionable. Get insights, not just raw data.
Statify
statify
Visitor statistics for WordPress with focus on data protection, transparency and clarity. Perfect as a widget in your WordPress Dashboard.
Koko Analytics – Privacy Friendly Statistics for WordPress
koko-analytics
Koko Analytics is a privacy-friendly statistics plugin for WordPress that is an easy to use alternative to Google Analytics.
Usermaven Developer Profile
1 plugin · 1K total installs
How We Detect Usermaven
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/usermaven/admin/css/usermaven-admin.css/wp-content/plugins/usermaven/admin/js/usermaven-admin.js/wp-content/plugins/usermaven/public/js/usermaven-public.jsusermaven-admin.css?ver=usermaven-admin.js?ver=HTML / DOM Fingerprints
usermaven-notice-warningdata-um-eventusermaven_public