
Humanized statistics Security & Risk Analysis
wordpress.org/plugins/humanized-statisticsRecolt datas by post and page with post_meta and display it with the Api Google chart on each post and page
Is Humanized statistics Safe to Use in 2026?
Generally Safe
Score 100/100Humanized statistics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The humanized-statistics plugin v0.7 exhibits a generally good security posture with a low attack surface and a strong adherence to best practices regarding SQL queries and nonce/capability checks. The static analysis reveals no direct vulnerabilities like dangerous functions, file operations, or external HTTP requests. The high percentage of prepared statements for SQL queries is a significant strength, mitigating common injection risks.
However, a critical concern arises from the taint analysis, which identified one flow with an unsanitized path. While the overall number of flows is small and no critical or high severity issues were flagged in the taint analysis, an unsanitized path presents a potential risk for directory traversal or other path manipulation vulnerabilities if not handled properly. Furthermore, the alarmingly low percentage (3%) of properly escaped outputs is a major weakness. This suggests a high likelihood of cross-site scripting (XSS) vulnerabilities, as user-supplied or dynamic data might be rendered directly in the output without adequate sanitization.
The vulnerability history is clean, with no recorded CVEs. This, combined with the absence of critical or high-severity taint flows, suggests that historically, the plugin has not been a significant target or source of major vulnerabilities. However, the lack of historical vulnerabilities should not overshadow the identified output escaping and taint analysis issues, which require immediate attention. The plugin's strengths lie in its limited attack surface and disciplined SQL handling, but the potential for XSS due to poor output escaping and the identified unsanitized path demand careful review and remediation.
Key Concerns
- Unsanitized path in taint flow
- Low percentage of properly escaped output
Humanized statistics Security Vulnerabilities
Humanized statistics Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Humanized statistics Attack Surface
WordPress Hooks 6
Maintenance & Trust
Humanized statistics Maintenance & Trust
Maintenance Signals
Community Trust
Humanized statistics Alternatives
GA Google Analytics – Connect Google Analytics to WordPress
ga-google-analytics
Adds Google Analytics tracking code to your WordPress site. Supports many tracking features.
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)
burst-statistics
Analytics you'll actually use. Privacy-friendly, zero config, and designed to be actionable. Get insights, not just raw data.
Post Views Counter
post-views-counter
Post Views Counter allows you to collect and display how many times a post, page, or other content has been viewed in a simple, fast and reliable way.
Independent Analytics – Google Analytics Alternative for WordPress
independent-analytics
A simple WordPress analytics plugin that is privacy-friendly, fast, and an alternative to Google Analytics.
Statify
statify
Visitor statistics for WordPress with focus on data protection, transparency and clarity. Perfect as a widget in your WordPress Dashboard.
Humanized statistics Developer Profile
7 plugins · 70 total installs
How We Detect Humanized statistics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/humanized-statistics/css/admin.css