
Yandex.Metrica Security & Risk Analysis
wordpress.org/plugins/wp-yandex-metrikaThe free official Yandex.Metrica plugin for WordPress.
Is Yandex.Metrica Safe to Use in 2026?
Mostly Safe
Score 78/100Yandex.Metrica is generally safe to use. 1 past CVE were resolved. Keep it updated.
The wp-yandex-metrika plugin, version 1.2.2, exhibits a concerning security posture primarily due to its unprotected attack surface. All five identified AJAX handlers lack authorization checks, presenting a significant risk for unauthorized actions. While the static analysis shows no dangerous functions or raw SQL queries, and external HTTP requests are absent, the lack of basic security controls on entry points is a major weakness. The plugin's vulnerability history, including a known unpatched medium-severity vulnerability (dated in the future, likely a placeholder), indicates a recurring pattern of security oversights, specifically missing authorization. This suggests a need for more robust security practices during development and testing to prevent potential exploits targeting these unprotected AJAX endpoints. Despite the absence of critical taint flows and the proper use of prepared statements, the unprotected entry points and historical vulnerabilities create a notable risk.
Key Concerns
- AJAX handlers without auth checks
- Unprotected entry points (all AJAX)
- No nonce checks on AJAX handlers
- One unpatched medium severity CVE
- Missing capability checks
Yandex.Metrica Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Yandex.Metrica <= 1.2.2 - Missing Authorization
Yandex.Metrica Code Analysis
Output Escaping
Data Flow Analysis
Yandex.Metrica Attack Surface
AJAX Handlers 5
WordPress Hooks 43
Maintenance & Trust
Yandex.Metrica Maintenance & Trust
Maintenance Signals
Community Trust
Yandex.Metrica Alternatives
WT Yandex Metrika
wt-yandex-metrika
Простое добавление на сайт счетчика Яндекс.Метрика
Easy Yandex Metrica
easy-yandex-metrica
Easily add statistics display Yandex Metrica to the Wordpress admin panel.
Fast Yandex Metrika
fast-yandex-metrika
Plugin for configuring the counter and Yandex Metrica goals.
Simple Counter
abwp-simple-counter
The installation of the counter of Yandex.Metrics and Google Analytics on the website without editing the files of the selected theme.
Yandex Metrica
yandex-metrica
Easy way to use Yandex Metrica on your WordPress site.
Yandex.Metrica Developer Profile
1 plugin · 60K total installs
How We Detect Yandex.Metrica
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-yandex-metrika/assets/admin.min.css/wp-content/plugins/wp-yandex-metrika/assets/fonts/fonts.min.css/wp-content/plugins/wp-yandex-metrika/assets/admin.min.jshttps://cdn.jsdelivr.net/npm/select2@4.1.0-rc.0/dist/js/select2.min.jshttps://cdn.jsdelivr.net/npm/select2@4.1.0-rc.0/dist/js/i18n/ru.js/wp-content/plugins/wp-yandex-metrika/assets/admin.min.css?ver=/wp-content/plugins/wp-yandex-metrika/assets/fonts/fonts.min.css?ver=/wp-content/plugins/wp-yandex-metrika/assets/admin.min.js?ver=HTML / DOM Fingerprints
data-input-type="number"YAM_SLUGYAM_VER