
Google Reader Stats Security & Risk Analysis
wordpress.org/plugins/google-reader-statsThis plugin adds the Google Reader Stats (+1 count/View count) to your blog posts.
Is Google Reader Stats Safe to Use in 2026?
Generally Safe
Score 85/100Google Reader Stats has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "google-reader-stats" plugin v1.4 exhibits a mixed security posture. While the absence of known CVEs and a lack of critical or high-severity taint flows are positive indicators, several code signals raise concerns. The extremely low percentage of properly escaped output (23%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data is likely being rendered without adequate sanitization. Furthermore, the complete absence of capability checks and nonce checks, combined with a significant number of SQL queries (10) where only 10% use prepared statements, points to potential SQL injection risks and privilege escalation vulnerabilities. The presence of file operations and external HTTP requests without proper authentication or sanitization also increases the attack surface. Despite the clean vulnerability history, the internal code analysis reveals significant potential weaknesses that could be exploited if an attacker can find an entry point. The plugin's strengths lie in its limited attack surface through traditional WordPress entry points, but its internal coding practices present substantial security risks.
Key Concerns
- Low output escaping percentage
- Low percentage of prepared statements for SQL
- No capability checks
- No nonce checks
- Unsanitized paths in taint analysis
Google Reader Stats Security Vulnerabilities
Google Reader Stats Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Google Reader Stats Attack Surface
WordPress Hooks 7
Maintenance & Trust
Google Reader Stats Maintenance & Trust
Maintenance Signals
Community Trust
Google Reader Stats Alternatives
Koko Analytics – Privacy Friendly Statistics for WordPress
koko-analytics
Koko Analytics is a privacy-friendly statistics plugin for WordPress that is an easy to use alternative to Google Analytics.
Multiple Google Analytics Trackers
multi-google-analytics
Add one or more Google Analytics trackers to your website.
Seoatl On Site Google Analytics
on-site-google-analytics
This plugin provides WP admin's valuable data from Google Analytics on site without having to login to Google Analytics to get the information.
Seoatl On Site Google Analytics
onsite-google-analytics-plugin
This plugin provides WP admin's valuable data from Google Analytics on site without having to login to Google Analytics to get the information.
PageRank
pagerank
Displays Google PageRank in the sidebar of your blog via widget interface or anywhere else via function call.
Google Reader Stats Developer Profile
6 plugins · 90 total installs
How We Detect Google Reader Stats
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/google-reader-stats/grs_plusone_small.png/wp-content/plugins/google-reader-stats/grs_view_small.pnggoogle-reader-stats/style.css?ver=google-reader-stats/script.js?ver=HTML / DOM Fingerprints
grs-plusonegrs-viewsgoogle-reader-stats<!-- Google Reader Stats --><!-- End Google Reader Stats -->data-grs-post-iddata-grs-plusone-countdata-grs-views-countgoogleReaderStatsgrs_update_options<span class="grs-plusone"><span class="grs-views">