
Web Vitals Security & Risk Analysis
wordpress.org/plugins/web-vitalsSend Web Vitals to Google Analytics.
Is Web Vitals Safe to Use in 2026?
Generally Safe
Score 85/100Web Vitals has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The web-vitals plugin v0.1.2 exhibits a strong security posture based on the provided static analysis. There are no identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that are exposed to potential attackers. Furthermore, the code signals are predominantly positive, with no dangerous functions or file operations detected. The absence of external HTTP requests and the exclusive use of prepared statements for SQL queries are excellent security practices.
However, there are a couple of areas that warrant attention. The output escaping rate, at 64%, indicates that a significant portion (36%) of the plugin's outputs are not properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed. The lack of nonce and capability checks across all entry points (even though there are none) is a general concern for future development or if new entry points are added without these security measures. The vulnerability history is clean, with no known CVEs, which is a positive indicator of the plugin's past security.
In conclusion, the web-vitals plugin v0.1.2 is generally secure due to its minimal attack surface and sound coding practices in areas like SQL handling. The primary weakness lies in the incomplete output escaping, which presents a potential XSS risk. The absence of any past vulnerabilities is a strong positive, but the plugin should be vigilant in maintaining these standards, particularly regarding output sanitization.
Key Concerns
- Low output escaping rate (64%)
- No nonce checks implemented
- No capability checks implemented
Web Vitals Security Vulnerabilities
Web Vitals Code Analysis
Output Escaping
Web Vitals Attack Surface
WordPress Hooks 4
Maintenance & Trust
Web Vitals Maintenance & Trust
Maintenance Signals
Community Trust
Web Vitals Alternatives
Local GAjs
local-gajs
Host the ga.js locally for improved load speed. Integrates with Analytics for WordPress by Joost de Valk.
Qualetics
qualetics
Qualetics - No Code Analytics & AI for your Wordpress Website
WPAC Integration for Google Analytics
wpac-integration-for-google-analytics
Simple and effective Google Analytics integration for WordPress with Universal Analytics, GA4, and flexible code placement.
WP ULike – Like & Dislike Buttons for Engagement and Feedback
wp-ulike
Voting buttons that let your visitors give instant feedback. See what your audience loves with no registration, no friction, just one click.
GTM Kit – Google Tag Manager & GA4 integration
gtm-kit
Google Tag Manager and GA4 integration. Including WooCommerce data for Google Analytics 4 and support for server side GTM.
Web Vitals Developer Profile
1 plugin · 20 total installs
How We Detect Web Vitals
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/web-vitals/public/js/web-vitals.0.2.1.es5.umd.min.jshttps://unpkg.com/web-vitals@0.2.1/dist/web-vitals.es5.umd.min.jsHTML / DOM Fingerprints
name="webvitals:sink"window.gawindow.gtagwindow.dataLayerwebVitals