
Website Analytics by YEB Security & Risk Analysis
wordpress.org/plugins/website-analytics-by-yebWordPress analytics: pageviews & sessions with interactions, verified bots, GeoIP, CSV export. Privacy-first.
Is Website Analytics by YEB Safe to Use in 2026?
Generally Safe
Score 100/100Website Analytics by YEB has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "website-analytics-by-yeb" plugin, version 1.0.2, exhibits a generally good security posture with several strong practices in place. The overwhelming majority of SQL queries utilize prepared statements, and output escaping is also handled well for most outputs. The absence of any known vulnerabilities (CVEs) or taint flow issues further indicates a commitment to security in its development. However, there are notable areas of concern that warrant attention.
The plugin presents a moderate attack surface with a significant portion of its entry points lacking proper authentication and permission checks. Specifically, one of the two REST API routes and one of the AJAX handlers are exposed without sufficient security controls. This could potentially allow unauthorized access or manipulation of plugin functionality. The presence of the `set_time_limit` function, while not inherently a vulnerability, is a dangerous function that can sometimes be exploited in specific contexts to prolong execution or impact server resources if not carefully managed.
While the plugin has no recorded vulnerability history, this is not a guarantee of future security. The current analysis reveals potential weaknesses in how certain entry points are protected. The strengths lie in its secure handling of database operations and output rendering. The key weaknesses are the exposed entry points, which present a clear risk that needs mitigation. Overall, while the plugin has a solid foundation, the unprotected entry points are a significant concern that needs to be addressed to improve its security.
Key Concerns
- AJAX handler without auth check
- REST API route without permission callback
- Dangerous function usage (set_time_limit)
Website Analytics by YEB Security Vulnerabilities
Website Analytics by YEB Release Timeline
Website Analytics by YEB Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Website Analytics by YEB Attack Surface
AJAX Handlers 1
REST API Routes 2
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Website Analytics by YEB Maintenance & Trust
Maintenance Signals
Community Trust
Website Analytics by YEB Alternatives
Post Views Counter
post-views-counter
Post Views Counter allows you to collect and display how many times a post, page, or other content has been viewed in a simple, fast and reliable way.
Statify
statify
Visitor statistics for WordPress with focus on data protection, transparency and clarity. Perfect as a widget in your WordPress Dashboard.
Trace My IP – Visitor IP Tracker, Stats Analytics & Page Views Counter with Email Alerts
tracemyip-visitor-analytics-ip-tracking-control
Comprehensive visitor IP tracking and website analytics solution with real-time statistics, page view counting, and customizable email alerts.
TWIPLA (Visitor Analytics IO) – Privacy-First Website Stats, Session Recordings, Heatmaps, Polls and Surveys
visitor-analytics-io
2.5M+ installs — #1 Web Analytics Tool on WIX, now on WordPress! 📈 Traffic Stats, Session Replays, Heatmaps.🔓 GDPR & CCPA Ready. 💵 Free Forever Plan.
Scoby Analytics
scoby-analytics
Privacy-focused analytics for WordPress — designed to minimize data protection risk under EU GDPR and ePrivacy.
Website Analytics by YEB Developer Profile
1 plugin · 0 total installs
How We Detect Website Analytics by YEB
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/website-analytics-by-yeb/public/css/waby-admin.css/wp-content/plugins/website-analytics-by-yeb/public/js/waby-admin.js/wp-content/plugins/website-analytics-by-yeb/public/js/waby-tracker.js/wp-content/plugins/website-analytics-by-yeb/public/js/waby-tracker.jswebsite-analytics-by-yeb/public/css/waby-admin.css?ver=website-analytics-by-yeb/public/js/waby-admin.js?ver=website-analytics-by-yeb/public/js/waby-tracker.js?ver=HTML / DOM Fingerprints
waby-dashboard-tabswaby-kpi-cardwaby-data-table-filter-toggle<!-- YEB-Analytics tracker script --><!-- YEB-Analytics admin CSS --><!-- YEB-Analytics admin JS --><!-- YEB-Analytics - Settings Link -->data-waby-trackerdata-waby-tracker-urlwabyTrackerConfigwindow.wabyTracker/wp-json/waby/v1/track/wp-json/waby/v1/admin[waby_visits_stats]