
Ciusan Simple Statistics Security & Risk Analysis
wordpress.org/plugins/ciusan-simple-statisticsShow simple statistics.
Is Ciusan Simple Statistics Safe to Use in 2026?
Generally Safe
Score 100/100Ciusan Simple Statistics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ciusan-simple-statistics" v1.0 plugin presents a mixed security posture. On the positive side, it has a small attack surface with no unprotected entry points and a clean vulnerability history with no known CVEs. There are also no external HTTP requests or file operations, which reduces certain classes of risks. However, the static analysis reveals significant concerns. The use of the `create_function` is a critical security anti-pattern that can lead to code injection vulnerabilities. Additionally, all SQL queries are executed without prepared statements, making the plugin susceptible to SQL injection. Furthermore, none of the outputs are properly escaped, posing a risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks on its entry points, though currently limited in scope due to no unprotected handlers, is a concerning practice that could be exploited if new entry points are added or existing ones modified without proper security considerations.
Key Concerns
- Use of create_function
- SQL queries not using prepared statements
- Output escaping not properly handled
- Missing nonce checks
- Missing capability checks
Ciusan Simple Statistics Security Vulnerabilities
Ciusan Simple Statistics Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Ciusan Simple Statistics Attack Surface
Shortcodes 3
WordPress Hooks 1
Maintenance & Trust
Ciusan Simple Statistics Maintenance & Trust
Maintenance Signals
Community Trust
Ciusan Simple Statistics Alternatives
WP-UserOnline
wp-useronline
Enable you to display how many users are online on your Wordpress blog with detailed statistics.
WP Register Profile With Shortcode
wp-register-profile-with-shortcode
This is a simple registration form in the widget. just install the plugin and add the register widget in the sidebar. Thats it. :)
Dashboard User profile Detais-(DUPD)
dashboard-user-profile-detais-dupd
A smart, easy way to add Dashboard User Profile Widget to your Wordpress Site.
Plugin
dashboard-user-profile-dup
A smart, easy way to add Dashboard User Profile Widget to your Wordpress Site.
Registered User Dashboard Widget
registered-user-dashboard-widget
Major features of this plugin include * Show bar chart user registered monthly * Show list number user registered monthly
Ciusan Simple Statistics Developer Profile
6 plugins · 60 total installs
How We Detect Ciusan Simple Statistics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.