
Webmetic Security & Risk Analysis
wordpress.org/plugins/webmeticEasily integrate Webmetic into your WordPress website by adding your Account ID.
Is Webmetic Safe to Use in 2026?
Generally Safe
Score 100/100Webmetic has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'webmetic' plugin v1.0.2 demonstrates a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any identified CVEs and a clean vulnerability history are significant strengths, suggesting a commitment to security by the developers or a lack of past exploitation. The code analysis reveals a remarkably small attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the code adheres to good practices by using prepared statements for all SQL queries and performing capability checks on the single identified entry point. The high percentage of properly escaped output is also a positive indicator, mitigating risks associated with cross-site scripting (XSS).
However, there are a couple of areas that warrant attention. The complete lack of nonce checks is a concern, especially if any of the identified entry points, despite not being explicitly listed as AJAX or REST, could potentially be triggered by user interaction without proper validation. While the capability check is present, the absence of nonces leaves open the possibility of CSRF (Cross-Site Request Forgery) vulnerabilities if these entry points handle sensitive operations. The taint analysis showing zero flows analyzed is also a weakness, as it implies incomplete or no dynamic analysis was performed, leaving potential vulnerabilities undiscovered. A more comprehensive dynamic analysis would be beneficial.
In conclusion, 'webmetic' v1.0.2 appears to be a relatively secure plugin with a minimal attack surface and good SQL hygiene. The primary weaknesses lie in the complete absence of nonce checks and the lack of taint flow analysis. While no past vulnerabilities have been recorded, the potential for CSRF and undiscovered issues due to limited dynamic analysis should be acknowledged. The plugin's strengths in preventing common web vulnerabilities like SQL injection and XSS are commendable.
Key Concerns
- Missing nonce checks on entry points
- No taint analysis performed
Webmetic Security Vulnerabilities
Webmetic Code Analysis
Output Escaping
Webmetic Attack Surface
WordPress Hooks 2
Maintenance & Trust
Webmetic Maintenance & Trust
Maintenance Signals
Community Trust
Webmetic Alternatives
Leadinfo
leadinfo
This plugin can be used to add the Leadinfo tracking code to a Wordpress site
Online Succes
online-succes
With this plugin you can easily add the Online Succes tracking code to your WordPress site.
Leadfeeder by Dealfront
dealfront
Turn page views into pipeline.
SiteGround Email Marketing
siteground-email-marketing
Lead generation plugin that will allow you to add subsription forms and use them for automatic lead submission to SiteGround Email Marketing service.
Happierleads – Identify your B2B website visitors even if they work remotely
happierleads
Identify your B2B website visitors that work remotely Generate 3X more leads than your competition by using your existing web traffic
Webmetic Developer Profile
1 plugin · 20 total installs
How We Detect Webmetic
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
https://t.webmetic.de/iav.js