Xstream Google Analytics for WordPress Security & Risk Analysis

wordpress.org/plugins/xstream-google-analytics

Google Analytics for your Wordpress website with JS file completelly hosted locally for performance increase.

10 active installs v1.0.1 PHP + WP 3.7.0+ Updated Aug 5, 2017
freegoogle-analyticslight-weightsimpletracking
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Xstream Google Analytics for WordPress Safe to Use in 2026?

Generally Safe

Score 85/100

Xstream Google Analytics for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The xstream-google-analytics v1.0.1 plugin exhibits a generally good security posture based on the provided static analysis. It has no known vulnerabilities (CVEs), indicating a history of secure development or prompt patching. The code signals show an absence of dangerous functions and external HTTP requests, which are common sources of vulnerabilities. Crucially, all SQL queries utilize prepared statements, and there are no taint analysis findings of critical or high severity, suggesting a low risk of direct code injection or data manipulation through its core functionalities.

However, there are areas that warrant attention. The plugin has a limited number of output escaping instances, with only 57% being properly escaped. This could potentially leave the plugin susceptible to Cross-Site Scripting (XSS) vulnerabilities if the unescaped output is rendered in a way that an attacker can control. Additionally, the presence of file operations without any apparent nonce or capability checks on specific entry points (although none are explicitly listed as unprotected) introduces a potential risk if these operations can be triggered by unauthenticated users or without proper authorization.

While the plugin's attack surface is currently zero-attack-point based on the provided metrics, and it shows positive signs like prepared statements and no known CVEs, the imperfect output escaping and potential for unauthorized file operations are weaknesses. A comprehensive security audit would be beneficial to ensure all potential execution paths are secured and that output is consistently sanitized to prevent XSS.

Key Concerns

  • Insufficient output escaping
  • File operations without explicit security checks
Vulnerabilities
None known

Xstream Google Analytics for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Xstream Google Analytics for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
4 escaped
Nonce Checks
0
Capability Checks
2
File Operations
5
External Requests
0
Bundled Libraries
0

Output Escaping

57% escaped7 total outputs
Attack Surface

Xstream Google Analytics for WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuxstream-ga.php:15
actionadmin_initxstream-ga.php:24
actionupdate_xstream_gaxstream-ga.php:73
actionwp_footerxstream-ga.php:115

Scheduled Events 1

update_xstream_ga
Maintenance & Trust

Xstream Google Analytics for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedAug 5, 2017
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Xstream Google Analytics for WordPress Developer Profile

XstreamThemes

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Xstream Google Analytics for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/xstream-google-analytics/local/xstream-ga.js
Script Paths
/wp-content/plugins/xstream-google-analytics/local/xstream-ga.js

HTML / DOM Fingerprints

HTML Comments
<!-- Powered by Xstream Google Analytics for Wordpress --><!-- Xstream Google Analytics for Wordpress END -->
JS Globals
window.ga
FAQ

Frequently Asked Questions about Xstream Google Analytics for WordPress