
BNS Site Data Security & Risk Analysis
wordpress.org/plugins/bns-site-dataDisplay various toggleable site statistics.
Is BNS Site Data Safe to Use in 2026?
Generally Safe
Score 85/100BNS Site Data has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bns-site-data" plugin v0.4.3 exhibits a generally positive security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and unpatched vulnerabilities is a significant strength, indicating a history of responsible development or a lack of discovered weaknesses. Furthermore, the complete absence of dangerous functions, raw SQL queries, and file operations are excellent security practices.
However, there are areas for concern. The plugin has a low percentage of properly escaped output (21%), which presents a risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is displayed without adequate sanitization. The presence of one external HTTP request could also be a potential vector if the target endpoint is compromised or the request is not properly secured. The lack of nonce checks and capability checks on its single entry point (a shortcode) is a notable omission, as it means that this entry point is not protected against unauthorized access or abuse.
Overall, while the plugin benefits from a clean vulnerability history and good practices in critical areas like SQL and function usage, the insufficient output escaping and the lack of authorization checks on its shortcode represent tangible security risks that should be addressed. The limited attack surface is a positive, but the vulnerabilities present, though potentially minor individually, can have cumulative effects.
Key Concerns
- Low output escaping percentage
- External HTTP request present
- Missing nonce checks on entry point
- Missing capability checks on entry point
BNS Site Data Security Vulnerabilities
BNS Site Data Code Analysis
Output Escaping
BNS Site Data Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
BNS Site Data Maintenance & Trust
Maintenance Signals
Community Trust
BNS Site Data Alternatives
Restrict Widgets
restrict-widgets
All in one widgets and sidebars management in WordPress. Allows you to hide or display widgets on specified pages and restrict access for users.
TWIPLA (Visitor Analytics IO) – Privacy-First Website Stats, Session Recordings, Heatmaps, Polls and Surveys
visitor-analytics-io
2.5M+ installs — #1 Web Analytics Tool on WIX, now on WordPress! 📈 Traffic Stats, Session Replays, Heatmaps.🔓 GDPR & CCPA Ready. 💵 Free Forever Plan.
Widget Icon
widget-icon
Enhance your website with 640+ icons designed for Twitter Bootstrap. Just select an icon and display it in any widget on your WordPress site.
AFS Analytics
addfreestats
Full featured Web Analytics solution. Easy to use, in addition or as an alternative to google analytics.
Display Authors Widget
display-authors-widget
Display authors by role.
BNS Site Data Developer Profile
18 plugins · 2K total installs
How We Detect BNS Site Data
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bns-site-data/bns-site-data.css/wp-content/plugins/bns-site-data/bns-site-data.jsbns-site-data/bns-site-data.css?ver=bns-site-data/bns-site-data.js?ver=HTML / DOM Fingerprints
bns-site-databns-site-data-listbns-site-data-postsbns-site-data-pagesbns-site-data-categoriesbns-site-data-tagsbns-site-data-commentsbns-site-data-attachments<li class="bns-site-data-posts"><li class="bns-site-data-pages"><li class="bns-site-data-categories"><li class="bns-site-data-tags">