
Connect Matomo – Analytics Dashboard for WordPress Security & Risk Analysis
wordpress.org/plugins/wp-piwikAdds Matomo (former Piwik) statistics to your WordPress dashboard and is also able to add the Matomo Tracking Code to your blog.
Is Connect Matomo – Analytics Dashboard for WordPress Safe to Use in 2026?
Generally Safe
Score 97/100Connect Matomo – Analytics Dashboard for WordPress has a strong security track record. Known vulnerabilities have been patched promptly.
The 'wp-piwik' plugin v1.1.1 exhibits a mixed security posture. While it has a small attack surface with no direct entry points requiring authentication, there are significant concerns in its code quality and vulnerability history. The static analysis reveals a concerningly low rate of proper output escaping (7%) and a substantial portion of SQL queries not using prepared statements (78% unescaped). Furthermore, the taint analysis indicates two high-severity flows with unsanitized paths, which could lead to serious vulnerabilities if exploited. The plugin's history of 5 known CVEs, including 2 high-severity ones, reinforces these concerns. The prevalence of Cross-Site Request Forgery and Cross-site Scripting vulnerabilities in the past suggests a pattern of insecure input handling. While the absence of currently unpatched CVEs is positive, the recurring nature of past vulnerabilities and the identified code quality issues point to potential risks if not addressed by developers. Overall, the plugin has weaknesses in secure coding practices that, coupled with its historical vulnerability record, warrant careful consideration.
Key Concerns
- High-severity taint flows found
- Low output escaping rate
- Significant percentage of raw SQL queries
- History of high-severity CVEs
- History of medium-severity CVEs
Connect Matomo – Analytics Dashboard for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
WP-Matomo Integration (WP-Piwik) <= 1.0.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
WP-Piwik <= 1.0.27 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Display Name
WP-Matomo Integration (WP-Piwik) <= 1.0.26 - Cross-Site Request Forgery
WP-Matomo Integration (WP-Piwik) < 1.0.11 - Unauthenticated Stored Cross-Site Scripting
WP-Matomo Integration (WP-Piwik) < 1.0.5 - Cross-Site Scripting
Connect Matomo – Analytics Dashboard for WordPress Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Connect Matomo – Analytics Dashboard for WordPress Attack Surface
Shortcodes 1
WordPress Hooks 28
Maintenance & Trust
Connect Matomo – Analytics Dashboard for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Connect Matomo – Analytics Dashboard for WordPress Alternatives
User Activity Tracking and Log
user-activity-tracking-and-log
Track time and monitor user activity & history on your website, LMS online learning system, membership or WooCommerce site.
Trace My IP – Visitor IP Tracker, Stats Analytics & Page Views Counter with Email Alerts
tracemyip-visitor-analytics-ip-tracking-control
Comprehensive visitor IP tracking and website analytics solution with real-time statistics, page view counting, and customizable email alerts.
Simple Matomo Tracking Code
simple-matomo-tracking-code
This unofficial plugin adds the Matomo Web Analytics javascript code into the footer of your website. It has several useful options.
Stetic
stetic
Web Analytics from Stetic including many features. Displays a widget, a complete analytics dashboard page and adds the tracking code to your site.
Simple Webstats
simple-webstats
Privacy-focused cookie-free web analytics for WordPress.
Connect Matomo – Analytics Dashboard for WordPress Developer Profile
2 plugins · 160K total installs
How We Detect Connect Matomo – Analytics Dashboard for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-piwik/js/wp-piwik.js/wp-content/plugins/wp-piwik/js/chartjs/chart.min.js/wp-content/plugins/wp-piwik/js/wp-piwik.js/wp-content/plugins/wp-piwik/js/chartjs/chart.min.jswp-piwik.js?ver=chart.min.js?ver=HTML / DOM Fingerprints
wp-piwik-formCopyright (C) 2009-today Andre Braekling (email: webmaster@braekling.de)Thanks for using WP-Matomo!wp-piwik[revision]