2M+ sites running the plugin
3M total installs claimed

What happened

On June 12, the website of MonsterInsights — the Google Analytics plugin running on more than 2 million WordPress sites, with the company claiming 3 million total installs — was compromised and taken offline. Fraudulent emails started going out from the company's own domain to users of the plugin.

The company's warning was blunt: do not install MonsterInsights from any third-party site while the phishing attempt is active. Its notice also stated that analytics and tracking were unaffected, and pointed users with questions to [email protected]. Multiple users publicly confirmed receiving the phishing emails.

Just as significant is what this is not: a disclosed vulnerability in the plugin itself. There is no patch to apply. The attack surface is the inbox of anyone who administers a WordPress site — and the download button on any site that isn't the official one.

Why this matters

Your store may run on BigCommerce, but your marketing stack almost certainly touches WordPress somewhere — a blog, landing pages, a legacy microsite nobody remembers building. Those properties share more with your store than teams admit: analytics accounts, passwords reused across systems, links that search engines trust. A compromise on the blog is a foothold, not a contained incident.

Phishing sent from a compromised legitimate domain defeats the standard training. "Check the sender" fails when the sender is real. The tell shifts to behavior — unexpected urgency, download links, demands to act now — and that's a harder standard your team only meets if someone tells them this specific campaign exists. Attackers picked an analytics plugin for a reason, too: the people who administer it hold exactly the credentials worth stealing.

Credit where it's due: MonsterInsights warned loudly and publicly instead of sitting on the incident. That transparency is exactly what makes a same-day internal warning possible — and it's the behavior you should hope for, and ask about, from every vendor whose code runs on your properties. Use the window it bought you.

What to do about it

Send the warning today

One message to everyone with WordPress admin access: unexpected MonsterInsights emails are hostile until verified. Verify directly with the vendor — its stated contact is [email protected] — never through links inside the email itself.

Lock plugin installs to official sources

Make it written policy that plugins come from the wordpress.org repository or the vendor's own site, nowhere else. The company's own warning names third-party downloads as the danger while this phishing attempt is active — and that risk will outlive this incident.

Audit what WordPress shares with your store

Reused passwords, shared analytics accounts, admin users who left the company months ago. A blog compromise becomes a store problem through exactly these seams — cut them now, while it's still someone else's incident.

Review recent plugin activity on your WP sites

Check the install and update history on every WordPress property you run for anything added since mid-June that didn't come from an official source. If someone on your team acted on one of these emails before the warning went out, you want to find that today, not during a traffic anomaly three months from now.