Clicky by Yoast
Clicky by Yoast has one disclosed vulnerability in the WordSec catalog, all reported in 2016; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Clicky by Yoast has a vendor fix available, so running the current release closes it.
All of these findings were reported by Omar Kurt. Clicky by Yoast is installed on roughly 4,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.1.12.
Clicky by Yoast <= 1.5 - Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Clicky by Yoast
Author
Joost de Valk
Integrates the Clicky web analytics service into your blog. Automatically adding your Clicky tracking code everywhere. Option to ignore admins. Option to store names of commenters. Option to disable the use of cookies. Stores comments as an action using the Clicky internal data logging API. This requires a pro account to work. Option to track posts & pages as goals and assign a revenue to that page or post. An overview of your site’s statistics on your dashboard. Easily add outbound link pattern matching for affiliate links etc. Adds a small stats indicator of visitors in the last 48 to the WordPress toolbar. Read the authors review of Clicky Analytics if you want to see a bit more of the cool integration this plugin provides. Have you found an issue? If you have bugs to report, please go to the plugin’s GitHub repository. For security issues, please use our vulnerability disclosure program, which is managed by PatchStack. They will assist you with verification, CVE assignment, and, of course, notify us.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C