
bStat Security & Risk Analysis
wordpress.org/plugins/bstatsLog and analyze activity.
Is bStat Safe to Use in 2026?
Generally Safe
Score 100/100bStat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bstats" v6.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and having no recorded vulnerabilities in its history, suggesting a generally secure development process or minimal exposure. However, the static analysis reveals significant security concerns, primarily related to its attack surface. All six identified AJAX handlers lack authentication checks, presenting a substantial risk for unauthorized actions. Furthermore, while most outputs are properly escaped, the presence of one flow with an unsanitized path flagged as high severity taint is a critical concern that could lead to various security issues if exploited. The lack of capability checks on AJAX handlers exacerbates these risks, allowing any authenticated user, regardless of their role, to potentially interact with these vulnerable endpoints.
Key Concerns
- AJAX handlers without authentication checks
- High severity unsanitized taint flow
- AJAX handlers without capability checks
- Outputs not properly escaped
bStat Security Vulnerabilities
bStat Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
bStat Attack Surface
AJAX Handlers 6
WordPress Hooks 21
Maintenance & Trust
bStat Maintenance & Trust
Maintenance Signals
Community Trust
bStat Alternatives
Disable User Gravatar
disable-user-gravatar
Stops WordPress from grabbing a user avatar using their registrated email from gravatar.com.
User Activity Tracking and Log
user-activity-tracking-and-log
Track time and monitor user activity & history on your website, LMS online learning system, membership or WooCommerce site.
Activity Plus Reloaded for BuddyPress
bp-activity-plus-reloaded
Note: This plugin will be discontinued by March 31st, 2025 in favor of BuddyPress Attachment plugin. Please migrate to the new plugin before that date …
BuddyKit – Additional features for BuddyPress
buddykit
BuddyKit adds several features like Live Notifications and Media Activities to your BuddyPress powered websites.
Simple Webstats
simple-webstats
Privacy-focused cookie-free web analytics for WordPress.
bStat Developer Profile
7 plugins · 290 total installs
How We Detect bStat
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bstats/css/bstat-report.css/wp-content/plugins/bstats/js/bstat-report.js/wp-content/plugins/bstats/js/bstat-report.jsbstats/css/bstat-report.css?ver=bstats/js/bstat-report.js?ver=HTML / DOM Fingerprints
bstats-reportcomment tracking is kept separate as an example of how to build other integrationsdata-role="goal-flow"bstats_report_vars/wp-json/bstats/v1/sessions/wp-json/bstats/v1/goals/wp-json/bstats/v1/goal