CF LLMS Stats Tracker Security & Risk Analysis

wordpress.org/plugins/cf-llms-stats-tracker

Generates a dynamic llms.txt file for AI crawlers and tracks visitor statistics with detailed bot analysis.

10 active installs v1.3.2 PHP 7.4+ WP 5.0+ Updated Jan 8, 2026
aianalyticsbotsllms-txtstatistics
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CF LLMS Stats Tracker Safe to Use in 2026?

Generally Safe

Score 100/100

CF LLMS Stats Tracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "cf-llms-stats-tracker" plugin v1.3.2 exhibits a generally strong security posture, characterized by good implementation practices. The static analysis reveals a very limited attack surface, with no identified unprotected AJAX handlers, REST API routes, or shortcodes. The code signals also indicate a positive trend, with a high percentage of SQL queries using prepared statements and a similarly high rate of proper output escaping. The presence of nonce and capability checks, even if few, suggests an awareness of security best practices.

Despite these positive indicators, there are a few areas that warrant attention. The two cron events, while not explicitly stated as unprotected, represent potential entry points that should be scrutinized to ensure they have adequate authorization checks. The absence of any identified vulnerabilities in the plugin's history is a significant strength, suggesting a well-maintained codebase. However, it's important to note that the lack of historical vulnerabilities doesn't guarantee future immunity.

In conclusion, "cf-llms-stats-tracker" v1.3.2 appears to be a secure plugin with a robust foundation. Its minimal attack surface and adherence to prepared statements and output escaping are commendable. The primary recommendation for improvement would be to review the two identified cron events for proper authorization and to maintain the current diligence in development to continue this positive security track record.

Key Concerns

  • Cron events without explicit auth checks
Vulnerabilities
None known

CF LLMS Stats Tracker Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

CF LLMS Stats Tracker Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
22 prepared
Unescaped Output
7
85 escaped
Nonce Checks
3
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

96% prepared23 total queries

Output Escaping

92% escaped92 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<cf-llms-stats-tracker> (cf-llms-stats-tracker.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

CF LLMS Stats Tracker Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actioninitcf-llms-stats-tracker.php:32
actionadmin_menucf-llms-stats-tracker.php:33
actionwp_dashboard_setupcf-llms-stats-tracker.php:34
actionadmin_enqueue_scriptscf-llms-stats-tracker.php:35
actionadmin_initcf-llms-stats-tracker.php:37
actionllmssttr_refresh_cachecf-llms-stats-tracker.php:39
actionsave_postcf-llms-stats-tracker.php:40
actionadmin_post_llmssttr_download_statscf-llms-stats-tracker.php:42
actionadmin_post_llmssttr_reset_statscf-llms-stats-tracker.php:43
actionllmssttr_daily_cleanupcf-llms-stats-tracker.php:87
actionadmin_post_llmssttr_refresh_cachecf-llms-stats-tracker.php:1008
actionPlugins_Loadedcf-llms-stats-tracker.php:1024

Scheduled Events 2

llmssttr_daily_cleanup
llmssttr_refresh_cache
Maintenance & Trust

CF LLMS Stats Tracker Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 8, 2026
PHP min version7.4
Downloads176

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

CF LLMS Stats Tracker Developer Profile

carlosfabuel

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CF LLMS Stats Tracker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cf-llms-stats-tracker/css/dashboard.css/wp-content/plugins/cf-llms-stats-tracker/js/dashboard.js
Script Paths
/wp-content/plugins/cf-llms-stats-tracker/js/dashboard.js
Version Parameters
cf-llms-stats-tracker/css/dashboard.css?ver=cf-llms-stats-tracker/js/dashboard.js?ver=

HTML / DOM Fingerprints

CSS Classes
llmssttr-dashboard-widget
FAQ

Frequently Asked Questions about CF LLMS Stats Tracker