WT Analytics Security & Risk Analysis

wordpress.org/plugins/wt-analytics

Add Webtrends Analytics tag to your website. Allows for set-up and configuration.

10 active installs v1.0 PHP + WP 3.7+ Updated Nov 1, 2016
analyticswebtrends
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WT Analytics Safe to Use in 2026?

Generally Safe

Score 85/100

WT Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "wt-analytics" plugin v1.0 exhibits a generally strong security posture based on the provided static analysis, with no identified attack surface, dangerous functions, or SQL injection vulnerabilities. The complete absence of file operations and external HTTP requests further mitigates common risk vectors. However, a significant concern arises from the 100% of output not being properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where user-supplied data could be injected into the page without sanitization, leading to potential unauthorized actions or information disclosure within the WordPress admin area or on the frontend, depending on where the output is rendered. The lack of vulnerability history suggests a clean track record, but this does not negate the immediate risks identified in the code itself.

While the plugin's minimal attack surface and secure SQL handling are positive indicators, the pervasive lack of output escaping represents a critical weakness that requires immediate attention. The absence of capability checks and nonce checks, while not directly exploitable due to the zero attack surface, leaves the plugin poorly fortified against potential future introductions of vulnerabilities in these areas. The overall assessment is that while the plugin avoids common pitfalls like SQL injection and a large attack surface, the severe oversight in output escaping renders it susceptible to XSS attacks, making it a moderate to high risk in its current state.

Key Concerns

  • 0% output properly escaped
Vulnerabilities
None known

WT Analytics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WT Analytics Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped17 total outputs
Attack Surface

WT Analytics Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_headaaww.php:41
actionwp_headaaww.php:42
actionadmin_menuaaww.php:44
actionadmin_initaaww.php:48
Maintenance & Trust

WT Analytics Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedNov 1, 2016
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WT Analytics Developer Profile

Just_acex3

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WT Analytics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wt-analytics/css/main.css/wp-content/plugins/wt-analytics/scripts/menu.js
Script Paths
/wp-content/plugins/wt-analytics/scripts/menu.js

HTML / DOM Fingerprints

CSS Classes
config-headingoption_label
Data Attributes
name="WT.z.wordpress_plugin"value="WordPress Admin Menu"value="WordPress Public Facing"
FAQ

Frequently Asked Questions about WT Analytics