
WT Yandex Metrika Security & Risk Analysis
wordpress.org/plugins/wt-yandex-metrikaПростое добавление на сайт счетчика Яндекс.Метрика
Is WT Yandex Metrika Safe to Use in 2026?
Generally Safe
Score 85/100WT Yandex Metrika has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wt-yandex-metrika" plugin v1.1 exhibits a generally strong security posture based on the provided static analysis. There are no identified dangerous functions, SQL queries are all prepared, and file operations and external HTTP requests are absent, which significantly reduces the attack surface. The lack of known CVEs and historical vulnerabilities further suggests a well-maintained and secure codebase.
However, a significant concern is the low percentage of properly escaped output (20%). This means that 80% of the plugin's output is not being sanitized, creating a risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data or dynamic content is rendered directly without proper escaping. Additionally, the absence of nonce checks across all potential entry points, though the entry point count is zero, is a missed opportunity for defense-in-depth, especially if the attack surface were to grow.
In conclusion, while the plugin benefits from a clean code base regarding dangerous functions and SQL injection risks, the prevalent lack of output escaping is a notable weakness. This presents a tangible XSS risk that should be addressed. The absence of historical vulnerabilities is a positive sign, but the current code analysis reveals a specific area requiring immediate attention to maintain a robust security profile.
Key Concerns
- Low output escaping percentage
- No nonce checks implemented
WT Yandex Metrika Security Vulnerabilities
WT Yandex Metrika Code Analysis
Output Escaping
WT Yandex Metrika Attack Surface
WordPress Hooks 7
Maintenance & Trust
WT Yandex Metrika Maintenance & Trust
Maintenance Signals
Community Trust
WT Yandex Metrika Alternatives
Easy Yandex Metrica
easy-yandex-metrica
Easily add statistics display Yandex Metrica to the Wordpress admin panel.
Yandex.Metrica
wp-yandex-metrika
The free official Yandex.Metrica plugin for WordPress.
Simple Counter
abwp-simple-counter
The installation of the counter of Yandex.Metrics and Google Analytics on the website without editing the files of the selected theme.
Fast Yandex Metrika
fast-yandex-metrika
Plugin for configuring the counter and Yandex Metrica goals.
YaMaps for WordPress Plugin
yamaps
The plugin allows you to add Yandex Maps (Яндекс Карты) to pages of your site using a WordPress visual editor.
WT Yandex Metrika Developer Profile
2 plugins · 7K total installs
How We Detect WT Yandex Metrika
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.