
Estadisticas Web Security & Risk Analysis
wordpress.org/plugins/estadisticas-webEnables google analytics on all pages.
Is Estadisticas Web Safe to Use in 2026?
Generally Safe
Score 85/100Estadisticas Web has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'estadisticas-web' v0.1.1 exhibits a very limited attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events. The static analysis indicates a lack of dangerous function usage and a complete absence of direct SQL queries in favor of prepared statements. File operations and external HTTP requests are also not present. However, a significant concern is the relatively low percentage of properly escaped output (57%), suggesting potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is displayed without adequate sanitization.
The plugin's vulnerability history is entirely clean, with no recorded CVEs. This, combined with the lack of identified taint flows and dangerous functions, suggests a generally secure codebase in its current state. The absence of nonce checks and capability checks is not a direct issue given the lack of identifiable entry points that would typically require such protections. The plugin's strengths lie in its minimal attack surface and absence of known vulnerabilities.
Despite the clean history and lack of critical code signals, the unescaped output presents a potential weakness that could be exploited if this plugin were to be extended or if new entry points were introduced without proper security considerations. The focus should be on improving output sanitization to mitigate potential XSS risks.
Key Concerns
- Unescaped output detected
Estadisticas Web Security Vulnerabilities
Estadisticas Web Code Analysis
Output Escaping
Estadisticas Web Attack Surface
WordPress Hooks 3
Maintenance & Trust
Estadisticas Web Maintenance & Trust
Maintenance Signals
Community Trust
Estadisticas Web Alternatives
Insert Headers and Footers Code – HT Script
insert-headers-and-footers-script
This plugin allows you to insert Google analytic code, Facebook pixel code, custom javascript, custom style in your website's header and footer.
Cache External Scripts
cache-external-scripts
Save the Google Analytics file (gtag.js / analytics.js) locally to be able to cache it for longer than 2 hours for a better PageSpeed score!
Universal Analytics
universal-analytics
A simple method to add Google's Universal Analytics JavaScript tracking code to your WordPress website.
Carolyn Google Analytics
carolyn-google-analytics
A (very) simple plugin for embedding a Google Analytics tracking code in your WordPress site.
Counters Integration
counters-integration
You can add both are Google Analytics and Yandex Metrika counter's codes on all pages.
Estadisticas Web Developer Profile
1 plugin · 100 total installs
How We Detect Estadisticas Web
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/estadisticas-web/options.php//www.google-analytics.com/analytics.jsHTML / DOM Fingerprints
Google Analytics End Google Analytics ga