Vemetric Security & Risk Analysis

wordpress.org/plugins/vemetric

Vemetric is a lightweight, privacy-first analytics tool that helps you understand how your users are interacting with your website.

0 active installs v1.0.5 PHP 8.1+ WP 6.4+ Updated Oct 8, 2025
analyticsprivacystatsvemetricweb-analytics
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Vemetric Safe to Use in 2026?

Generally Safe

Score 100/100

Vemetric has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "vemetric" plugin v1.0.5 exhibits a strong security posture. The plugin demonstrates excellent adherence to secure coding practices, with no identified dangerous functions, SQL queries executed via prepared statements, all output properly escaped, and no file operations or external HTTP requests. Crucially, the analysis found no taint flows, indicating no identifiable risks of unsanitized data leading to vulnerabilities.

The absence of any known CVEs, past or present, further reinforces this positive assessment. This suggests a mature development process where security is a priority. The plugin also shows no recorded common vulnerability types, and the last recorded vulnerability is non-existent, implying a consistent history of secure development.

While the plugin's attack surface is reported as zero entry points, this should be viewed with a slight caution. It's unusual for a plugin to have absolutely no interaction points. However, given the other strong indicators, it's likely that any potential interactions are internal or well-protected. Overall, "vemetric" v1.0.5 appears to be a very secure plugin, with no immediate security concerns identified from the provided data.

Vulnerabilities
None known

Vemetric Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Vemetric Release Timeline

v1.0.4
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Vemetric Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
31 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

100% escaped31 total outputs
Attack Surface

Vemetric Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menusrc/Admin/SettingsPage.php:9
actionadmin_initsrc/Admin/SettingsPage.php:10
actionwp_enqueue_scriptssrc/Frontend/ScriptLoader.php:9
filterscript_loader_tagsrc/Frontend/ScriptLoader.php:53
Maintenance & Trust

Vemetric Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 8, 2025
PHP min version8.1
Downloads420

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Vemetric Developer Profile

Vemetric

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Vemetric

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vemetric/src/Frontend/../vendor/js/vemetric.js
Script Paths
https://cdn.vemetric.com/main.js

HTML / DOM Fingerprints

Data Attributes
defer
JS Globals
window.vmtrcqwindow.vmtrcwindow.vmtrcOptions
FAQ

Frequently Asked Questions about Vemetric