
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) Security & Risk Analysis
wordpress.org/plugins/burst-statisticsAnalytics you'll actually use. Privacy-friendly, zero config, and designed to be actionable. Get insights, not just raw data.
Is Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) Safe to Use in 2026?
Generally Safe
Score 96/100Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) has a strong security track record. Known vulnerabilities have been patched promptly.
The burst-statistics plugin, version 3.2.3, presents a mixed security posture. While it demonstrates good practices in areas like output escaping (96% properly escaped) and SQL prepared statements (78%), significant concerns arise from its attack surface. Specifically, four out of five AJAX handlers lack authentication checks, and one REST API route is missing permission callbacks. This creates potential entry points for unauthorized actions. The taint analysis, though limited in scope (2 flows analyzed), identified one flow with unsanitized paths, indicating a potential for vulnerabilities if such paths are exposed to user input without proper sanitization. The vulnerability history reveals a past pattern of high and medium severity issues, including CSRF, XSS, and SQL Injection. While no currently unpatched CVEs are reported, the historical prevalence of these common web vulnerability types suggests a need for ongoing vigilance and rigorous security testing. The presence of a bundled library (DataTables) also warrants attention for potential outdated versions, although this is not explicitly detailed in the provided data. Overall, while some security hygiene is evident, the unprotected entry points and historical vulnerability trends necessitate careful review and mitigation of identified risks.
Key Concerns
- AJAX handlers without auth checks
- REST API routes without permission callbacks
- Taint flow with unsanitized paths
- Past high severity CVEs
- Past medium severity CVEs
- Bundled DataTables library
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Burst Statistics <= 2.0.6 - Cross-Site Request Forgery
Burst Statistics – Privacy-Friendly Analytics for WordPress <= 1.5.6.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via burst_total_pageviews_count
Burst Statistics Really Simple Plugins <= 1.5.3 - Authenticated (Editor+) SQL Injection
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) Attack Surface
AJAX Handlers 5
REST API Routes 22
Shortcodes 2
WordPress Hooks 176
Scheduled Events 19
Maintenance & Trust
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) Maintenance & Trust
Maintenance Signals
Community Trust
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) Alternatives
Statify
statify
Visitor statistics for WordPress with focus on data protection, transparency and clarity. Perfect as a widget in your WordPress Dashboard.
Koko Analytics – Privacy Friendly Statistics for WordPress
koko-analytics
Koko Analytics is a privacy-friendly statistics plugin for WordPress that is an easy to use alternative to Google Analytics.
Statify – Extended Evaluation
extended-evaluation-for-statify
This plugin evaluates the data collected with the privacy-friendly Statify Plugin (data tables and diagrams). The evaluation can be downloaded as csv.
Simple Webstats
simple-webstats
Privacy-focused cookie-free web analytics for WordPress.
Scoby Analytics
scoby-analytics
Privacy-focused analytics for WordPress — designed to minimize data protection risk under EU GDPR and ePrivacy.
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) Developer Profile
1 plugin · 200K total installs
How We Detect Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/burst-statistics/assets/css/main.css/wp-content/plugins/burst-statistics/assets/js/chart.umd.js/wp-content/plugins/burst-statistics/assets/js/date-fns.js/wp-content/plugins/burst-statistics/assets/js/main.js/wp-content/plugins/burst-statistics/assets/js/vue.js/wp-content/plugins/burst-statistics/assets/js/vueRouter.js/wp-content/plugins/burst-statistics/assets/vendor/bootstrap/css/bootstrap.min.css/wp-content/plugins/burst-statistics/assets/vendor/bootstrap/js/bootstrap.bundle.min.js+3 more/wp-content/plugins/burst-statistics/assets/js/chart.umd.js/wp-content/plugins/burst-statistics/assets/js/date-fns.js/wp-content/plugins/burst-statistics/assets/js/main.js/wp-content/plugins/burst-statistics/assets/js/vue.js/wp-content/plugins/burst-statistics/assets/js/vueRouter.js/wp-content/plugins/burst-statistics/assets/vendor/bootstrap/js/bootstrap.bundle.min.js+1 more/wp-content/plugins/burst-statistics/assets/css/main.css?ver=/wp-content/plugins/burst-statistics/assets/js/chart.umd.js?ver=/wp-content/plugins/burst-statistics/assets/js/date-fns.js?ver=/wp-content/plugins/burst-statistics/assets/js/main.js?ver=/wp-content/plugins/burst-statistics/assets/js/vue.js?ver=/wp-content/plugins/burst-statistics/assets/js/vueRouter.js?ver=/wp-content/plugins/burst-statistics/assets/vendor/bootstrap/css/bootstrap.min.css?ver=/wp-content/plugins/burst-statistics/assets/vendor/bootstrap/js/bootstrap.bundle.min.js?ver=/wp-content/plugins/burst-statistics/assets/vendor/datatables/datatables.min.css?ver=/wp-content/plugins/burst-statistics/assets/vendor/datatables/datatables.min.js?ver=/wp-content/plugins/burst-statistics/assets/vendor/fontawesome/css/all.min.css?ver=HTML / DOM Fingerprints
burst-statistics<!-- @php use Burst\burst_loader; -->data-bs-toggledata-bs-targetaria-controlsaria-labelledbydata-bs-dismisswindow.burst_vars/wp-json/burst-statistics/v1/