Яндекс Метрика Security & Risk Analysis

wordpress.org/plugins/yandex-metrika

Яндекс Метрика для вашего сайта на WordPress.

10K active installs v0.8.4 PHP + WP 3.0+ Updated Nov 28, 2017
analyticsmetricametrikastatsyandex
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Яндекс Метрика Safe to Use in 2026?

Generally Safe

Score 85/100

Яндекс Метрика has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "yandex-metrika" plugin v0.8.4 demonstrates a strong security posture based on the provided static analysis. The absence of any identified attack surface (AJAX handlers, REST API routes, shortcodes, cron events) significantly reduces the potential for direct exploitation. Furthermore, the code analysis reveals no dangerous functions, raw SQL queries, file operations, or external HTTP requests, all of which are positive security indicators. The presence of a capability check, though only one, is a good practice for controlling access to plugin features.

The taint analysis showing zero flows with unsanitized paths, and no critical or high severity issues, further reinforces the plugin's apparent security. The vulnerability history being entirely clear, with no recorded CVEs of any severity, suggests a history of secure development or a lack of past discoveries. However, the low number of output escapes (4 total, 75% properly escaped) means there's a minor risk of cross-site scripting (XSS) if the unescaped outputs are user-controlled and displayed without further client-side sanitization.

In conclusion, the "yandex-metrika" plugin v0.8.4 appears to be developed with security in mind, exhibiting a very low risk profile. The strengths lie in its minimal attack surface and absence of critical code vulnerabilities. The sole area for minor concern is the potential for XSS due to a small percentage of unescaped output, though this is mitigated by the very limited attack surface. Given the lack of historical vulnerabilities and positive static analysis results, the plugin is generally considered secure.

Key Concerns

  • Some output is not properly escaped
Vulnerabilities
None known

Яндекс Метрика Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Яндекс Метрика Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
3 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

75% escaped4 total outputs
Attack Surface

Яндекс Метрика Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actioninityandex-metrika.php:14
actionadmin_menuyandex-metrika.php:15
actionadmin_inityandex-metrika.php:16
actionwp_footeryandex-metrika.php:17
Maintenance & Trust

Яндекс Метрика Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedNov 28, 2017
PHP min version
Downloads154K

Community Trust

Rating90/100
Number of ratings15
Active installs10K
Developer Profile

Яндекс Метрика Developer Profile

Konstantin Kovshenin

15 plugins · 19K total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Яндекс Метрика

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
large-text
Data Attributes
name="yandex-metrika[counter-code]"
FAQ

Frequently Asked Questions about Яндекс Метрика