Statify – Extended Evaluation Security & Risk Analysis

wordpress.org/plugins/extended-evaluation-for-statify

This plugin evaluates the data collected with the privacy-friendly Statify Plugin (data tables and diagrams). The evaluation can be downloaded as csv.

20K active installs v2.6.5 PHP 5.6+ WP 4.7+ Updated Feb 22, 2026
analyticsprivacystatisticsstats
100
A · Safe
CVEs total1
Unpatched0
Last CVESep 18, 2023
Safety Verdict

Is Statify – Extended Evaluation Safe to Use in 2026?

Generally Safe

Score 100/100

Statify – Extended Evaluation has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Sep 18, 2023Updated 2mo ago
Risk Assessment

The extended-evaluation-for-statify plugin v2.6.5 exhibits a mixed security posture. On the positive side, the plugin demonstrates strong adherence to secure coding practices by properly escaping all output and utilizing prepared statements for a significant majority of its SQL queries. The absence of direct file operations, external HTTP requests, and a large attack surface are also commendable. However, the taint analysis reveals three flows with unsanitized paths, all categorized as high severity. This is a significant concern, as it indicates potential avenues for attackers to inject malicious data that is not properly validated or neutralized. While there are no currently unpatched vulnerabilities, the plugin has a history of one medium-severity CVE related to improper CSV formula neutralization. This suggests a potential for specific types of vulnerabilities, and the presence of high-severity taint flows warrants further investigation into whether this historical pattern could be exploited through the identified unsanitized paths.

Key Concerns

  • High severity taint flows with unsanitized paths
  • History of one medium CVE
Vulnerabilities
1 published

Statify – Extended Evaluation Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

WF-35027df9-ae55-453f-bb42-4b2664d66293-extended-evaluation-for-statifymedium · 5.5Improper Neutralization of Formula Elements in a CSV File

Statify – Extended Evaluation <= 2.6.3 - Authenticated (Admin+) CSV Injection

Sep 18, 2023 Patched in 2.6.4 (127d)
Code Analysis
Analyzed Mar 16, 2026

Statify – Extended Evaluation Code Analysis

Dangerous Functions
0
Raw SQL Queries
7
18 prepared
Unescaped Output
0
116 escaped
Nonce Checks
4
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

72% prepared25 total queries

Output Escaping

100% escaped116 total outputs
Data Flows · Security
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
<content> (views\content.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Statify – Extended Evaluation Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_noticesextended-evaluation-for-statify.php:86
actioninitextended-evaluation-for-statify.php:105
actionadmin_menuextended-evaluation-for-statify.php:219
actionadmin_initextended-evaluation-for-statify.php:239
Maintenance & Trust

Statify – Extended Evaluation Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 22, 2026
PHP min version5.6
Downloads145K

Community Trust

Rating92/100
Number of ratings11
Active installs20K
Developer Profile

Statify – Extended Evaluation Developer Profile

Patrick Robrecht

3 plugins · 21K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
379 days
View full developer profile
Detection Fingerprints

How We Detect Statify – Extended Evaluation

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/extended-evaluation-for-statify/lib/chartist.min.css/wp-content/plugins/extended-evaluation-for-statify/css/style.min.css/wp-content/plugins/extended-evaluation-for-statify/lib/chartist.min.js/wp-content/plugins/extended-evaluation-for-statify/js/functions.min.js
Version Parameters
extended-evaluation-for-statify/lib/chartist.min.css?ver=extended-evaluation-for-statify/css/style.min.css?ver=extended-evaluation-for-statify/lib/chartist.min.js?ver=extended-evaluation-for-statify/js/functions.min.js?ver=

HTML / DOM Fingerprints

JS Globals
eefStatifyTranslations
FAQ

Frequently Asked Questions about Statify – Extended Evaluation