
TWIPLA (Visitor Analytics IO) – Privacy-First Website Stats, Session Recordings, Heatmaps, Polls and Surveys Security & Risk Analysis
wordpress.org/plugins/visitor-analytics-io2.5M+ installs — #1 Web Analytics Tool on WIX, now on WordPress! 📈 Traffic Stats, Session Replays, Heatmaps.🔓 GDPR & CCPA Ready. 💵 Free Forever Plan.
Is TWIPLA (Visitor Analytics IO) – Privacy-First Website Stats, Session Recordings, Heatmaps, Polls and Surveys Safe to Use in 2026?
Generally Safe
Score 99/100TWIPLA (Visitor Analytics IO) – Privacy-First Website Stats, Session Recordings, Heatmaps, Polls and Surveys has a strong security track record. Known vulnerabilities have been patched promptly.
The visitor-analytics-io plugin version 1.3.0 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by not exposing direct entry points like AJAX handlers, REST API routes, or shortcodes, and it utilizes prepared statements for all its SQL queries, significantly mitigating SQL injection risks. The absence of bundled libraries also reduces the attack surface from outdated third-party components.
However, several concerning aspects are highlighted in the static analysis. A significant portion (93%) of its 55 output operations are not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis reveals one flow with an unsanitized path, although it is not classified as critical or high severity in this instance. The lack of nonce checks and capability checks on potential, albeit currently zero, entry points is also a weakness. The plugin's vulnerability history shows a past medium severity XSS vulnerability, which reinforces the concern about unescaped output.
In conclusion, while the plugin avoids common pitfalls like direct SQL injection and a large attack surface, the prevalent lack of output escaping is a major security concern that could lead to XSS attacks. The past vulnerability further underscores the need for rigorous output sanitization. The absence of any authenticated entry points in this version is a strength, but the underlying code should be thoroughly audited for proper output handling to ensure robust security.
Key Concerns
- High percentage of unescaped output
- Flow with unsanitized path detected
- No nonce checks implemented
- No capability checks implemented
- Past medium severity vulnerability (XSS)
TWIPLA (Visitor Analytics IO) – Privacy-First Website Stats, Session Recordings, Heatmaps, Polls and Surveys Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
TWIPLA (Visitor Analytics IO) <= 1.2.0 - Authenticated (Admin+) Stored Cross-Site Scripting
TWIPLA (Visitor Analytics IO) – Privacy-First Website Stats, Session Recordings, Heatmaps, Polls and Surveys Code Analysis
Output Escaping
Data Flow Analysis
TWIPLA (Visitor Analytics IO) – Privacy-First Website Stats, Session Recordings, Heatmaps, Polls and Surveys Attack Surface
WordPress Hooks 8
Maintenance & Trust
TWIPLA (Visitor Analytics IO) – Privacy-First Website Stats, Session Recordings, Heatmaps, Polls and Surveys Maintenance & Trust
Maintenance Signals
Community Trust
TWIPLA (Visitor Analytics IO) – Privacy-First Website Stats, Session Recordings, Heatmaps, Polls and Surveys Alternatives
Trace My IP – Visitor IP Tracker, Stats Analytics & Page Views Counter with Email Alerts
tracemyip-visitor-analytics-ip-tracking-control
Comprehensive visitor IP tracking and website analytics solution with real-time statistics, page view counting, and customizable email alerts.
AFS Analytics
addfreestats
Full featured Web Analytics solution. Easy to use, in addition or as an alternative to google analytics.
YooAnalytics – Privacy-Friendly Analytics for WordPress & WooCommerce (Google Analytics Alternative)
yooanalytics
Lightweight, self-hosted, privacy-friendly analytics for WordPress & WooCommerce. Track visitors, page views, real-time users, WooCommerce purchas …
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)
google-analytics-for-wordpress
The best free Google Analytics plugin for WordPress. See how visitors find and use your website so you can grow your business with powerful analytics.
GA Google Analytics – Connect Google Analytics to WordPress
ga-google-analytics
Adds Google Analytics tracking code to your WordPress site. Supports many tracking features.
TWIPLA (Visitor Analytics IO) – Privacy-First Website Stats, Session Recordings, Heatmaps, Polls and Surveys Developer Profile
1 plugin · 1K total installs
How We Detect TWIPLA (Visitor Analytics IO) – Privacy-First Website Stats, Session Recordings, Heatmaps, Polls and Surveys
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/visitor-analytics-io/admin/static/css/admin.cssHTML / DOM Fingerprints
START: VISA Tracking CodeEND: VISA Tracking Codewindow.va<!-- START: VISA Tracking Code --><script>(function(v,i,s,a,t){v[t]=v[t]||function(){(v[t].v=v[t].v||[]).push(arguments)};if(!v._visaSettings){v._visaSettings={}}v._visaSettings[a]={v:'1.0',s:a,a:'1',t:t};var b=i.getElementsByTagName('body')[0];var p=i.createElement('script');p.defer=1;p.async=1;p.src=s+'?s='+a;b.appendChild(p)})(window,document,'//app-worker.visitor-analytics.io/main.js','