
atec Stats Security & Risk Analysis
wordpress.org/plugins/atec-statsLightweight, beautiful and GDPR compliant WP statistics, including countries map (IPv4, IPv6, CDN & Multisite compatible).
Is atec Stats Safe to Use in 2026?
Generally Safe
Score 100/100atec Stats has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "atec-stats" plugin v1.1.34 exhibits a mixed security posture. On the positive side, the plugin demonstrates excellent practices in output escaping, with 99% of outputs being properly escaped, significantly mitigating the risk of cross-site scripting (XSS) vulnerabilities. It also has a clean vulnerability history, with no known CVEs, suggesting a generally robust development process or limited past exposure. The limited number of external HTTP requests and file operations also contributes to a smaller attack surface in these areas.
However, there are significant concerns regarding the plugin's attack surface. It exposes two AJAX handlers, and critically, both of them lack authentication checks. This means any unauthenticated user could potentially trigger these handlers, leading to unintended actions or information disclosure depending on their functionality. While taint analysis and SQL query practices are not explicitly flagged as problematic, the lack of proper authorization on entry points remains a substantial risk. The presence of nonces and capability checks on some functions is a good sign, but their absence on the exposed AJAX endpoints is a glaring omission that needs immediate attention.
In conclusion, while the plugin is strong in output sanitization and has a clean past, the unprotected AJAX endpoints represent a critical security weakness. This oversight introduces a direct path for attackers to interact with the plugin's core functionality without any form of validation. The lack of vulnerability history is positive but does not negate the immediate risks presented by the exposed, unauthenticated entry points. Addressing these unprotected AJAX handlers should be the top priority to improve the plugin's overall security.
Key Concerns
- AJAX handlers without auth checks
- AJAX handlers without auth checks
atec Stats Security Vulnerabilities
atec Stats Code Analysis
SQL Query Safety
Output Escaping
atec Stats Attack Surface
AJAX Handlers 2
WordPress Hooks 11
Maintenance & Trust
atec Stats Maintenance & Trust
Maintenance Signals
Community Trust
atec Stats Alternatives
Fast Smooth Scroll
fast-smooth-scroll
This lightweight plugin enhances user experience by enabling smooth scrolling for anchor links without the need for jQuery or other dependencies.
FrontBlocks for Gutenberg/GeneratePress
frontblocks
Plugin extending Gutenberg and GeneratePress with carousel, slider, animations, sticky columns, edge alignment and post insertion capabilities.
imageLightbox
imagelightbox
Image Lightbox, Responsive and Touch‑friendly.
SaFly Curl Patch
safly-curl-patch
A plug-in which helps you solve the problems like 'WordPress could not establish a secure connection to WordPress.org.' caused by PHP Curl.
Anchor smooth scroll
anchor-smooth-scroll
Аdds a smooth scroll to the anchors.
atec Stats Developer Profile
16 plugins · 3K total installs
How We Detect atec Stats
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/atec-stats/assets/js/atec-wps-ajax.min.js/wp-content/plugins/atec-stats/assets/js/atec-wps-ajax.min.jsHTML / DOM Fingerprints
atec_wps_ajax_objatec_wps_calledatec_wps_timeoutatec_wps_runatecAddListener