
Display SQL Stats Security & Risk Analysis
wordpress.org/plugins/display-sql-stats! ! ! S T I L L B E T A ! ! !
Is Display SQL Stats Safe to Use in 2026?
Generally Safe
Score 85/100Display SQL Stats has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'display-sql-stats' plugin version 0.9.5.1 exhibits a generally good security posture with no recorded vulnerabilities or critical issues identified in the static analysis. The complete absence of dangerous functions, file operations, and external HTTP requests is a strong indicator of secure coding practices. Furthermore, all SQL queries utilize prepared statements, mitigating the risk of SQL injection. The plugin also demonstrates capability checks, which is a positive sign for authorization. However, a significant concern arises from the complete lack of output escaping for all 21 identified outputs. This presents a considerable risk of Cross-Site Scripting (XSS) vulnerabilities, as unescaped user-controlled input or dynamic content could be rendered directly in the browser. The absence of nonce checks on the single shortcode is also a potential weakness, although the overall attack surface is small and there are no AJAX handlers or REST API routes that would typically require more robust nonce protection. The plugin's history of zero known CVEs suggests a well-maintained codebase, but the identified output escaping flaw demands immediate attention to ensure user data is protected from potential XSS attacks.
Key Concerns
- All outputs are unescaped
- No nonce checks on shortcode
Display SQL Stats Security Vulnerabilities
Display SQL Stats Code Analysis
SQL Query Safety
Output Escaping
Display SQL Stats Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Display SQL Stats Maintenance & Trust
Maintenance Signals
Community Trust
Display SQL Stats Alternatives
SQL Chart Builder
sql-chart-builder
Turn Your SQL Queries to Beautiful Dynamic Charts- Pie, Line, Area, Donut, Bar Charts with date/input filters.
WP Business Intelligence Lite
wp-business-intelligence-lite
Dynamic web charts and tables for your site! Connect to your live WordPress instance DB to retrieve data in real-time and update charts and tables!
WP Google Charts
wp-google-charts
Easily integrate google charts, diagrams and tables based on your Google Spreadsheets.
MarketPress Statistics
marketpress-statistics
Display MarketPress statistics using google charts.
Visualizer: Tables and Charts Manager for WordPress
visualizer
A simple yet powerful WordPress chart plugin to effortlessly create and embed responsive charts & tables into your site, supporting multiple data …
Display SQL Stats Developer Profile
6 plugins · 1K total installs
How We Detect Display SQL Stats
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/display-sql-stats/js/chart.min.js/wp-content/plugins/display-sql-stats/js/google-charts.js/wp-content/plugins/display-sql-stats/js/dss-chart.js/wp-content/plugins/display-sql-stats/css/dss-style.css/wp-content/plugins/display-sql-stats/js/chart.min.js/wp-content/plugins/display-sql-stats/js/google-charts.js/wp-content/plugins/display-sql-stats/js/dss-chart.jsdisplay-sql-stats/css/dss-style.css?ver=display-sql-stats/js/chart.min.js?ver=display-sql-stats/js/google-charts.js?ver=display-sql-stats/js/dss-chart.js?ver=HTML / DOM Fingerprints
dss_chart_containerdss_chart_datadss_chart_options[display-sql-stats]