
AlexaRank Security & Risk Analysis
wordpress.org/plugins/alexarankDisplays the Alexa traffic rank in the sidebar of your blog via widget interface or anywhere else via function call.
Is AlexaRank Safe to Use in 2026?
Generally Safe
Score 85/100AlexaRank has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The alexarank plugin v0.2 exhibits a generally positive security posture with some notable concerns. On the positive side, the absence of known vulnerabilities and CVEs, coupled with a clean taint analysis, suggests a history of good security practices and thorough code review. The plugin also demonstrates strong adherence to secure database practices by exclusively using prepared statements for all SQL queries. However, the static analysis reveals critical areas for improvement. The presence of the `create_function` is a significant risk, as it can be exploited to execute arbitrary PHP code under certain conditions. Furthermore, the low percentage of properly escaped output (38%) indicates a high likelihood of cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website. The lack of nonce and capability checks on all entry points, while currently presenting a zero attack surface without authentication, leaves the plugin vulnerable if new entry points are added in the future without proper security measures. The file operation, though singular, also warrants careful review to ensure it's not exploited.
In conclusion, while the plugin benefits from a clean vulnerability history and secure database handling, the identified code signals present immediate and potentially severe risks. The `create_function` usage is a critical flaw that should be addressed urgently. The low output escaping rate also represents a significant XSS risk. While the current attack surface is small and seemingly protected by a lack of exposed endpoints, relying on this state is precarious. Addressing these issues will be crucial for improving the overall security of the alexarank plugin.
Key Concerns
- Use of dangerous function create_function
- Low output escaping (38%)
- No nonce checks on entry points
- No capability checks on entry points
- File operations detected
AlexaRank Security Vulnerabilities
AlexaRank Code Analysis
Dangerous Functions Found
Output Escaping
AlexaRank Attack Surface
WordPress Hooks 4
Maintenance & Trust
AlexaRank Maintenance & Trust
Maintenance Signals
Community Trust
AlexaRank Alternatives
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)
burst-statistics
Analytics you'll actually use. Privacy-friendly, zero config, and designed to be actionable. Get insights, not just raw data.
Statify
statify
Visitor statistics for WordPress with focus on data protection, transparency and clarity. Perfect as a widget in your WordPress Dashboard.
StatCounter – Free Real Time Visitor Stats
official-statcounter-plugin-for-wordpress
StatCounter.com powered real-time detailed stats about the visitors to your blog.
Koko Analytics – Privacy Friendly Statistics for WordPress
koko-analytics
Koko Analytics is a privacy-friendly statistics plugin for WordPress that is an easy to use alternative to Google Analytics.
Connect Matomo – Analytics Dashboard for WordPress
wp-piwik
Adds Matomo (former Piwik) statistics to your WordPress dashboard and is also able to add the Matomo Tracking Code to your blog.
AlexaRank Developer Profile
2 plugins · 40 total installs
How We Detect AlexaRank
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/alexarank/screenshot-1.gif/wp-content/plugins/alexarank/screenshot-2.gif/wp-content/plugins/alexarank/screenshot-3.gif/wp-content/plugins/alexarank/screenshot-4.gif/wp-content/plugins/alexarank/screenshot-5.gif/wp-content/plugins/alexarank/0.gif/wp-content/plugins/alexarank/1.gif/wp-content/plugins/alexarank/2.gif+2 morealexarank/alexarank.phpHTML / DOM Fingerprints
alexarankname="alexarank"id="alexarank"