
Usermaven Security & Risk Analysis
wordpress.org/plugins/usermavenUsermaven's web analytics product is a Google Analytics alternative that provides a real-time view of your website traffic metrics.
Is Usermaven Safe to Use in 2026?
Generally Safe
Score 99/100Usermaven has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The Usermaven v1.2.7 plugin exhibits a generally positive security posture with strong adherence to several best practices. The static analysis reveals a very limited attack surface with no unprotected AJAX handlers, REST API routes, or shortcodes. The plugin also demonstrates excellent SQL query handling, with 100% of queries using prepared statements, and a high rate of output escaping (97%). The absence of dangerous functions, file operations, and critical/high severity taint flows further indicates a commitment to secure coding. However, there are areas for improvement. The presence of 2 external HTTP requests warrants careful scrutiny to ensure they are not exploitable. More significantly, the plugin has a history of known vulnerabilities, including one CVE recorded. While currently unpatched CVEs are zero, the fact that a medium severity vulnerability has been recorded in the past, particularly of the Cross-Site Request Forgery (CSRF) type, suggests that past security oversights have occurred. This history, combined with a complete absence of capability checks, leaves room for concern regarding privilege escalation or unauthorized actions if other security mechanisms were to fail.
Key Concerns
- Medium severity vulnerability in history
- 2 external HTTP requests
- 0 capability checks found
Usermaven Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Usermaven <= 1.2.1 - Cross-Site Request Forgery
Usermaven Release Timeline
Usermaven Code Analysis
Output Escaping
Data Flow Analysis
Usermaven Attack Surface
WordPress Hooks 41
Scheduled Events 1
Maintenance & Trust
Usermaven Maintenance & Trust
Maintenance Signals
Community Trust
Usermaven Alternatives
Plausible Analytics
plausible-analytics
Simple, lightweight, privacy-friendly Google Analytics alternative for WordPress with a clean dashboard.
Trackboxx Analytics
trackboxx-analytics
A simple, GDPR compliant Google Analytics alternative.
Reignat Analytics
reignat-analytics
Add privacy-friendly Reignat web analytics to your WordPress site. Paste your Project ID, save, and the lightweight tracker does the rest.
Vemetric
vemetric
Vemetric is a lightweight, privacy-first analytics tool that helps you understand how your users are interacting with your website.
Statify
statify
Visitor statistics for WordPress with focus on data protection, transparency and clarity. Perfect as a widget in your WordPress Dashboard.
Usermaven Developer Profile
1 plugin · 1K total installs
How We Detect Usermaven
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/usermaven/admin/css/usermaven-admin.css/wp-content/plugins/usermaven/admin/js/usermaven-admin.js/wp-content/plugins/usermaven/public/js/usermaven-public.jsusermaven-admin.css?ver=usermaven-admin.js?ver=HTML / DOM Fingerprints
usermaven-notice-warningdata-um-eventusermaven_public