
Admins Post Statistics Security & Risk Analysis
wordpress.org/plugins/admins-post-statisticsThis plugin counts views of admin, editor and author posts' also creates sub menu Admin Statistics under Posts to see number of posts they' …
Is Admins Post Statistics Safe to Use in 2026?
Generally Safe
Score 85/100Admins Post Statistics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'admins-post-statistics' plugin, version 1.0.0, presents a mixed security picture. On the positive side, it exhibits strong adherence to secure coding practices by avoiding dangerous functions, performing all SQL queries using prepared statements, and having a negligible attack surface with no exposed AJAX, REST API, or shortcode entry points. The presence of nonce and capability checks, albeit only one each, indicates an awareness of WordPress security fundamentals.
However, a significant concern arises from the static analysis regarding output escaping. With 100% of its outputs unescaped, this leaves the plugin vulnerable to Cross-Site Scripting (XSS) attacks. Any data displayed to users without proper sanitization could be exploited. Additionally, the taint analysis revealed one flow with an unsanitized path, which, while not flagged as critical or high severity, still represents a potential security weakness that could be leveraged in conjunction with the unescaped output. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator but does not negate the risks identified in the static code analysis.
In conclusion, while the plugin has a small attack surface and uses prepared statements for database interactions, the lack of output escaping is a critical flaw that significantly undermines its security posture. The single unsanitized taint flow, though not critical, further highlights the need for more robust input validation and output sanitization. Users should be cautious until these issues are addressed.
Key Concerns
- Outputs are not properly escaped
- Taint flow with unsanitized path
Admins Post Statistics Security Vulnerabilities
Admins Post Statistics Code Analysis
Output Escaping
Data Flow Analysis
Admins Post Statistics Attack Surface
WordPress Hooks 9
Maintenance & Trust
Admins Post Statistics Maintenance & Trust
Maintenance Signals
Community Trust
Admins Post Statistics Alternatives
Views Counter – Pages/Posts
views-counter
Simple Plugin for showing the post or page view on Admin Column.no need to add code to theme file.just activate the plugin and enjoy.
Easy Post Views Count
easy-post-views-count
Add an easy post views count plugin into your site and get count views of your posts and custom post types posts like articles, news, movies etc.
Easy Post View Counter
easy-post-view-counter
With this plugin you can see how many views a single post has.
Wp Post Views Counter
wp-post-views-counter
Used to post views for a single post type in wordpress it collects both unique and all returning visits for a single post as a post meta .
Simple Post View Counter – Clean and Fast Post View Analytics
simple-post-view-counter
Lightweight post view counter with a widget and shortcodes. Track post views automatically, stop double-counting, and display popular content easily.
Admins Post Statistics Developer Profile
1 plugin · 0 total installs
How We Detect Admins Post Statistics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/admins-post-statistics/css/admin.css/wp-content/plugins/admins-post-statistics/css/localjquery.css/wp-content/plugins/admins-post-statistics/js/apsJS.js/wp-content/plugins/admins-post-statistics/css/smoothness/jquery-ui.min.css/wp-content/plugins/admins-post-statistics/js/apsJS.jsadmins-post-statistics/css/admin.css?ver=admins-post-statistics/css/localjquery.css?ver=admins-post-statistics/js/apsJS.js?ver=admins-post-statistics/css/smoothness/jquery-ui.min.css?ver=HTML / DOM Fingerprints
gridtable<!-- Exit if accessed directly --><!--Plugin Main CSS File.--><!--adds arrows to the calender style--><!--This hook ensures our scripts and styles are only loaded in the admin.-->+6 moreclass="datepicker"id="date-listed1"name="date_listed1"id="date-listed2"name="date_listed2"class="button-primary"