
Statify – Extended Evaluation Security & Risk Analysis
wordpress.org/plugins/extended-evaluation-for-statifyThis plugin evaluates the data collected with the privacy-friendly Statify Plugin (data tables and diagrams). The evaluation can be downloaded as csv.
Is Statify – Extended Evaluation Safe to Use in 2026?
Generally Safe
Score 100/100Statify – Extended Evaluation has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The extended-evaluation-for-statify plugin v2.6.5 exhibits a mixed security posture. On the positive side, the plugin demonstrates strong adherence to secure coding practices by properly escaping all output and utilizing prepared statements for a significant majority of its SQL queries. The absence of direct file operations, external HTTP requests, and a large attack surface are also commendable. However, the taint analysis reveals three flows with unsanitized paths, all categorized as high severity. This is a significant concern, as it indicates potential avenues for attackers to inject malicious data that is not properly validated or neutralized. While there are no currently unpatched vulnerabilities, the plugin has a history of one medium-severity CVE related to improper CSV formula neutralization. This suggests a potential for specific types of vulnerabilities, and the presence of high-severity taint flows warrants further investigation into whether this historical pattern could be exploited through the identified unsanitized paths.
Key Concerns
- High severity taint flows with unsanitized paths
- History of one medium CVE
Statify – Extended Evaluation Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Statify – Extended Evaluation <= 2.6.3 - Authenticated (Admin+) CSV Injection
Statify – Extended Evaluation Release Timeline
Statify – Extended Evaluation Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Statify – Extended Evaluation Attack Surface
WordPress Hooks 4
Maintenance & Trust
Statify – Extended Evaluation Maintenance & Trust
Maintenance Signals
Community Trust
Statify – Extended Evaluation Alternatives
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)
burst-statistics
Analytics you'll actually use. Privacy-friendly, zero config, and designed to be actionable. Get insights, not just raw data.
Statify
statify
Visitor statistics for WordPress with focus on data protection, transparency and clarity. Perfect as a widget in your WordPress Dashboard.
Koko Analytics – Privacy Friendly Statistics for WordPress
koko-analytics
Koko Analytics is a privacy-friendly statistics plugin for WordPress that is an easy to use alternative to Google Analytics.
Simple Webstats
simple-webstats
Privacy-focused cookie-free web analytics for WordPress.
Helper for Cloudflare Web Analytics
helper-for-cloudflare-web-analytics
Allows use of Cloudflare Web Analytics.
Statify – Extended Evaluation Developer Profile
3 plugins · 21K total installs
How We Detect Statify – Extended Evaluation
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/extended-evaluation-for-statify/lib/chartist.min.css/wp-content/plugins/extended-evaluation-for-statify/css/style.min.css/wp-content/plugins/extended-evaluation-for-statify/lib/chartist.min.js/wp-content/plugins/extended-evaluation-for-statify/js/functions.min.jsextended-evaluation-for-statify/lib/chartist.min.css?ver=extended-evaluation-for-statify/css/style.min.css?ver=extended-evaluation-for-statify/lib/chartist.min.js?ver=extended-evaluation-for-statify/js/functions.min.js?ver=HTML / DOM Fingerprints
eefStatifyTranslations