
Яндекс Метрика Security & Risk Analysis
wordpress.org/plugins/yandex-metrikaЯндекс Метрика для вашего сайта на WordPress.
Is Яндекс Метрика Safe to Use in 2026?
Generally Safe
Score 85/100Яндекс Метрика has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "yandex-metrika" plugin v0.8.4 demonstrates a strong security posture based on the provided static analysis. The absence of any identified attack surface (AJAX handlers, REST API routes, shortcodes, cron events) significantly reduces the potential for direct exploitation. Furthermore, the code analysis reveals no dangerous functions, raw SQL queries, file operations, or external HTTP requests, all of which are positive security indicators. The presence of a capability check, though only one, is a good practice for controlling access to plugin features.
The taint analysis showing zero flows with unsanitized paths, and no critical or high severity issues, further reinforces the plugin's apparent security. The vulnerability history being entirely clear, with no recorded CVEs of any severity, suggests a history of secure development or a lack of past discoveries. However, the low number of output escapes (4 total, 75% properly escaped) means there's a minor risk of cross-site scripting (XSS) if the unescaped outputs are user-controlled and displayed without further client-side sanitization.
In conclusion, the "yandex-metrika" plugin v0.8.4 appears to be developed with security in mind, exhibiting a very low risk profile. The strengths lie in its minimal attack surface and absence of critical code vulnerabilities. The sole area for minor concern is the potential for XSS due to a small percentage of unescaped output, though this is mitigated by the very limited attack surface. Given the lack of historical vulnerabilities and positive static analysis results, the plugin is generally considered secure.
Key Concerns
- Some output is not properly escaped
Яндекс Метрика Security Vulnerabilities
Яндекс Метрика Code Analysis
Output Escaping
Яндекс Метрика Attack Surface
WordPress Hooks 4
Maintenance & Trust
Яндекс Метрика Maintenance & Trust
Maintenance Signals
Community Trust
Яндекс Метрика Alternatives
Yandex Metrica
yandex-metrica
Easy way to use Yandex Metrica on your WordPress site.
DCO Insert Analytics Code
dco-insert-analytics-code
Allows you to insert analytics code before </head> or after <body> or before </body>
Fast Yandex Metrika
fast-yandex-metrika
Plugin for configuring the counter and Yandex Metrica goals.
Komito Analytics
komito-analytics
Komito Analytics is a free, open-source enhancement for the most popular web analytics software.
JSON-LD Schema for Yandex Metrica
antoniolite-yandex-metrica-json-ld-schema
Insert the needed JSON-LD Schema in your post pages so you can use the content reports in Yandex Metrica
Яндекс Метрика Developer Profile
15 plugins · 19K total installs
How We Detect Яндекс Метрика
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
large-textname="yandex-metrika[counter-code]"