
WT Analytics Security & Risk Analysis
wordpress.org/plugins/wt-analyticsAdd Webtrends Analytics tag to your website. Allows for set-up and configuration.
Is WT Analytics Safe to Use in 2026?
Generally Safe
Score 85/100WT Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wt-analytics" plugin v1.0 exhibits a generally strong security posture based on the provided static analysis, with no identified attack surface, dangerous functions, or SQL injection vulnerabilities. The complete absence of file operations and external HTTP requests further mitigates common risk vectors. However, a significant concern arises from the 100% of output not being properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where user-supplied data could be injected into the page without sanitization, leading to potential unauthorized actions or information disclosure within the WordPress admin area or on the frontend, depending on where the output is rendered. The lack of vulnerability history suggests a clean track record, but this does not negate the immediate risks identified in the code itself.
While the plugin's minimal attack surface and secure SQL handling are positive indicators, the pervasive lack of output escaping represents a critical weakness that requires immediate attention. The absence of capability checks and nonce checks, while not directly exploitable due to the zero attack surface, leaves the plugin poorly fortified against potential future introductions of vulnerabilities in these areas. The overall assessment is that while the plugin avoids common pitfalls like SQL injection and a large attack surface, the severe oversight in output escaping renders it susceptible to XSS attacks, making it a moderate to high risk in its current state.
Key Concerns
- 0% output properly escaped
WT Analytics Security Vulnerabilities
WT Analytics Code Analysis
Output Escaping
WT Analytics Attack Surface
WordPress Hooks 4
Maintenance & Trust
WT Analytics Maintenance & Trust
Maintenance Signals
Community Trust
WT Analytics Alternatives
Site Kit by Google – Analytics, Search Console, AdSense, Speed
google-site-kit
Site Kit is a one-stop solution for WordPress users to use everything Google has to offer to make them successful on the web.
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)
google-analytics-for-wordpress
The best free Google Analytics plugin for WordPress. See how visitors find and use your website so you can grow your business with powerful analytics.
GTM4WP – A Google Tag Manager (GTM) plugin for WordPress
duracelltomi-google-tag-manager
Advanced tag management for WordPress with Google Tag Manager
WP Statistics – Simple, privacy-friendly Google Analytics alternative
wp-statistics
Get website traffic insights with GDPR/CCPA compliant, privacy-friendly analytics. Includes visitor data, stunning graphs, and no data sharing.
PixelYourSite – Your smart PIXEL (TAG) & API Manager
pixelyoursite
Add Meta Pixel with Conversion API, Google Analytics (GA4) + Consent Mode, Google Tag Manager, and Head & Footer scripts.
WT Analytics Developer Profile
1 plugin · 10 total installs
How We Detect WT Analytics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wt-analytics/css/main.css/wp-content/plugins/wt-analytics/scripts/menu.js/wp-content/plugins/wt-analytics/scripts/menu.jsHTML / DOM Fingerprints
config-headingoption_labelname="WT.z.wordpress_plugin"value="WordPress Admin Menu"value="WordPress Public Facing"