PLUGIN SECURITY
Is Wp Analytify safe?
Analytify is the must-have Plugin for Google Analytics 4 Integration, Tracking, & Reporting in WordPress. Enhanced eCommerce, Events, & Call Analytics
What this plugin does
- Slug:
wp-analytify - Author: Adnan
- 20000+ active installs
- 94/100 rating (487 reviews on wordpress.org)
- 2553138 all-time downloads
- On WordPress.org since 2015-01-01
analyticsgoogle analyticsgoogle analytics 4google analytics dashboardWordPress analytics
Maintenance status
- Latest known version: 9.1.1
- Last updated: 2026-08-17 12:17pm GMT
- Tested up to WordPress: 7.0.4
Known vulnerabilities
11 known CVEs on file for Wp Analytify. Reported between 2022 and 2025.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2025-30897 | Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 6.0.0 | Missing Authorization | Medium 4.3 | < 6.0.0 | 6.0.0 | 2025-03-27 | ✓ fixed in latest |
| CVE-2025-26773 | Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.5.1 | Missing Authorization | Medium 4.3 | < 5.5.1 | 5.5.1 | 2025-02-14 | ✓ fixed in latest |
| CVE-2024-53814 | Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.5.0 | Exposure of Sensitive System Information to an Unauthorized Control Sphere | Medium 6.5 | < 5.5.0 | 5.5.0 | 2024-12-02 | ✓ fixed in latest |
| CVE-2024-43265 | Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.4.0 | Cross-Site Request Forgery (CSRF) | Low 3.5 | < 5.4.0 | 5.4.0 | 2024-08-12 | ✓ fixed in latest |
| CVE-2024-35689 | Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.4 | Cross-Site Request Forgery (CSRF) | High 8.8 | < 5.2.4 | 5.2.4 | 2024-06-06 | ✓ fixed in latest |
| CVE-2024-1809 | Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.4 | Exposure of Sensitive System Information to an Unauthorized Control Sphere | Medium 5.4 | < 5.2.4 | 5.2.4 | 2024-04-29 | ✓ fixed in latest |
| CVE-2024-1584 | Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.4 | Improper Access Control | Medium 5.3 | < 5.2.4 | 5.2.4 | 2024-04-26 | ✓ fixed in latest |
| CVE-2023-47841 | Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.0 | Missing Authorization | Medium 4.3 | < 5.2.0 | 5.2.0 | 2023-11-20 | ✓ fixed in latest |
+ 10 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2023-41695 | Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.1.1 | Missing Authorization | Low 3.5 | < 5.1.1 | 5.1.1 | 2023-09-05 | ✓ fixed in latest |
| CVE-2022-45830 | Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.3.0 | Missing Authorization | Medium 6.5 | < 4.3.0 | 4.3.0 | 2022-12-29 | ✓ fixed in latest |
| CVE-2022-38137 | Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.3 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 4.2.3 | 4.2.3 | 2022-09-29 | ✓ fixed in latest |
| — | Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.3 | — | Unknown | < 4.2.3 | 4.2.3 | 2022-08-22 | ✓ fixed in latest |
| — | Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.1 | — | Unknown | < 4.2.1 | 4.2.1 | 2022-06-20 | ✓ fixed in latest |
| — | Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.1 | — | Unknown | < 4.2.1 | 4.2.1 | 2022-06-20 | ✓ fixed in latest |
| — | Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.1 | — | Unknown | < 4.2.1 | 4.2.1 | — | ✓ fixed in latest |
| — | Analytify < 4.2.1 - Reflected Cross-Site Scripting | — | Unknown | < 4.2.1 | 4.2.1 | — | ✓ fixed in latest |
| CVE-2023-41695 | Analytify Dashboard < 5.1.1 - Missing Authorization to Opt-In | — | Unknown | < 5.1.1 | 5.1.1 | — | ✓ fixed in latest |
| CVE-2023-47841 | Analytify Dashboard < 5.2.0 - Cross-Site Request Forgery | — | Unknown | < 5.2.0 | 5.2.0 | — | ✓ fixed in latest |
How to fix it
Keep Wp Analytify updated — 9.1.1 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Site Kit by Google – Analytics, Search Console, AdSense, Speed — 5000000+ active installs — 84/100 (1009)
- MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) — 2000000+ active installs — 90/100 (3148) — max PHP 8.4
- GTM4WP – A Google Tag Manager (GTM) plugin for WordPress — 700000+ active installs — 90/100 (154) — max PHP 8.4
- WP Statistics – Simple, privacy-friendly Google Analytics alternative — 600000+ active installs — 82/100 (757) — max PHP <8.0
- GA Google Analytics – Connect Google Analytics to WordPress — 400000+ active installs — 98/100 (158) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.