PLUGIN SECURITY

Is Wp Analytify safe?

Analytify is the must-have Plugin for Google Analytics 4 Integration, Tracking, & Reporting in WordPress. Enhanced eCommerce, Events, & Call Analytics

What this plugin does

  • Slug: wp-analytify
  • Author: Adnan
  • 20000+ active installs
  • 94/100 rating (487 reviews on wordpress.org)
  • 2553138 all-time downloads
  • On WordPress.org since 2015-01-01

analyticsgoogle analyticsgoogle analytics 4google analytics dashboardWordPress analytics

Maintenance status

  • Latest known version: 9.1.1
  • Last updated: 2026-08-17 12:17pm GMT
  • Tested up to WordPress: 7.0.4

Known vulnerabilities

11 known CVEs on file for Wp Analytify. Reported between 2022 and 2025.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-30897 Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 6.0.0 Missing Authorization Medium 4.3 < 6.0.0 6.0.0 2025-03-27 ✓ fixed in latest
CVE-2025-26773 Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.5.1 Missing Authorization Medium 4.3 < 5.5.1 5.5.1 2025-02-14 ✓ fixed in latest
CVE-2024-53814 Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.5.0 Exposure of Sensitive System Information to an Unauthorized Control Sphere Medium 6.5 < 5.5.0 5.5.0 2024-12-02 ✓ fixed in latest
CVE-2024-43265 Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.4.0 Cross-Site Request Forgery (CSRF) Low 3.5 < 5.4.0 5.4.0 2024-08-12 ✓ fixed in latest
CVE-2024-35689 Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.4 Cross-Site Request Forgery (CSRF) High 8.8 < 5.2.4 5.2.4 2024-06-06 ✓ fixed in latest
CVE-2024-1809 Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.4 Exposure of Sensitive System Information to an Unauthorized Control Sphere Medium 5.4 < 5.2.4 5.2.4 2024-04-29 ✓ fixed in latest
CVE-2024-1584 Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.4 Improper Access Control Medium 5.3 < 5.2.4 5.2.4 2024-04-26 ✓ fixed in latest
CVE-2023-47841 Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.0 Missing Authorization Medium 4.3 < 5.2.0 5.2.0 2023-11-20 ✓ fixed in latest
+ 10 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-41695 Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.1.1 Missing Authorization Low 3.5 < 5.1.1 5.1.1 2023-09-05 ✓ fixed in latest
CVE-2022-45830 Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.3.0 Missing Authorization Medium 6.5 < 4.3.0 4.3.0 2022-12-29 ✓ fixed in latest
CVE-2022-38137 Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.3 Cross-Site Request Forgery (CSRF) Medium 4.3 < 4.2.3 4.2.3 2022-09-29 ✓ fixed in latest
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.3 Unknown < 4.2.3 4.2.3 2022-08-22 ✓ fixed in latest
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.1 Unknown < 4.2.1 4.2.1 2022-06-20 ✓ fixed in latest
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.1 Unknown < 4.2.1 4.2.1 2022-06-20 ✓ fixed in latest
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.1 Unknown < 4.2.1 4.2.1 ✓ fixed in latest
Analytify < 4.2.1 - Reflected Cross-Site Scripting Unknown < 4.2.1 4.2.1 ✓ fixed in latest
CVE-2023-41695 Analytify Dashboard < 5.1.1 - Missing Authorization to Opt-In Unknown < 5.1.1 5.1.1 ✓ fixed in latest
CVE-2023-47841 Analytify Dashboard < 5.2.0 - Cross-Site Request Forgery Unknown < 5.2.0 5.2.0 ✓ fixed in latest

How to fix it

Keep Wp Analytify updated — 9.1.1 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.