
Wise KPIs Security & Risk Analysis
wordpress.org/plugins/wise-kpisWise KPIs is a free plugin that displays almost 25 key performance indicators related to your WordPress website's performance.
Is Wise KPIs Safe to Use in 2026?
Generally Safe
Score 85/100Wise KPIs has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wise-kpis" plugin v2.5.1 demonstrates a strong security posture based on the provided static analysis. The plugin has a very small attack surface with only one AJAX handler, and crucially, this handler includes a nonce check. The code signals are also highly positive, with a very high percentage of SQL queries using prepared statements and output escaping. The absence of dangerous functions, file operations, and critical or high-severity taint flows further reinforces this good standing. The plugin also has no recorded vulnerability history, indicating a clean past and potentially robust development practices.
However, a minor concern arises from the lack of capability checks. While the nonce check is present, the absence of a capability check means that even authenticated users might be able to trigger the AJAX action, regardless of their WordPress role. This is a subtle but important distinction in WordPress security, as it assumes all authenticated users should have access to this functionality. Despite this, the overall picture is one of a well-secured plugin with a focus on preventing common vulnerabilities. The low number of potential entry points and the high rate of secure coding practices make it a relatively safe option, with the main area for potential improvement being the addition of role-based access control.
Key Concerns
- Missing capability checks on AJAX handler
Wise KPIs Security Vulnerabilities
Wise KPIs Release Timeline
Wise KPIs Code Analysis
SQL Query Safety
Output Escaping
Wise KPIs Attack Surface
AJAX Handlers 1
WordPress Hooks 9
Maintenance & Trust
Wise KPIs Maintenance & Trust
Maintenance Signals
Community Trust
Wise KPIs Alternatives
GA4WP – Analytics Dashboard for the Website
ga-for-wp
Google Analytics Dashboard for WordPress Plugin by GA4WP is Lightweight, Easy to connect and comes with plenty of great features.
YooAnalytics – Privacy-Friendly Analytics for WordPress & WooCommerce (Google Analytics Alternative)
yooanalytics
Lightweight, self-hosted, privacy-friendly analytics for WordPress & WooCommerce. Track visitors, page views, real-time users, WooCommerce purchas …
Sales Improver
sales-improver
WordPress plugin to improve sales using WooCommerce.
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)
google-analytics-for-wordpress
The best free Google Analytics plugin for WordPress. See how visitors find and use your website so you can grow your business with powerful analytics.
Google Analytics for WooCommerce
woocommerce-google-analytics-integration
Provides integration between Google Analytics and WooCommerce.
Wise KPIs Developer Profile
1 plugin · 10 total installs
How We Detect Wise KPIs
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wise-kpis/admin/css/tailwind.css/wp-content/plugins/wise-kpis/admin/css/wise-kpis.css/wp-content/plugins/wise-kpis/admin/js/apexcharts.js/wp-content/plugins/wise-kpis/admin/js/kpis-charts.js/wp-content/plugins/wise-kpis/admin/js/apexcharts.js/wp-content/plugins/wise-kpis/admin/js/kpis-charts.jswise-kpis/admin/css/tailwind.css?ver=wise-kpis/admin/css/wise-kpis.css?ver=wise-kpis/admin/js/apexcharts.js?ver=wise-kpis/admin/js/kpis-charts.js?ver=HTML / DOM Fingerprints
kpis_charts_obj/wp-json/codekamino/v1/news