
Just Writing Statistics Security & Risk Analysis
wordpress.org/plugins/just-writing-statisticsCalculate your writing statistics on your WordPress site.
Is Just Writing Statistics Safe to Use in 2026?
Generally Safe
Score 90/100Just Writing Statistics has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "just-writing-statistics" plugin v5.4 exhibits a mixed security posture. While it shows positive signs like a high percentage of SQL queries using prepared statements and the absence of dangerous functions or file operations, significant concerns remain. The presence of one AJAX handler without any authentication checks is a critical oversight, creating a direct entry point for potential attackers. Furthermore, the plugin has a history of three medium-severity vulnerabilities, including SQL injection and cross-site scripting, indicating a recurring pattern of input validation and authorization issues. Although these past vulnerabilities are currently patched, the historical data combined with the unauthenticated AJAX endpoint suggests a need for ongoing vigilance and improvement in the plugin's security practices.
Key Concerns
- AJAX handler without authentication check
- Historical medium severity vulnerabilities (x3)
- Output escaping concerns (only 38% properly escaped)
Just Writing Statistics Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Just Writing Statistics <= 5.3 - Missing Authorization
Just Writing Statistics <= 4.7 - Authenticated (Administrator+) SQL Injection
Just Writing Statistics <= 4.5 - Authenticated (Admin+) Stored Cross-Site Scripting
Just Writing Statistics Release Timeline
Just Writing Statistics Code Analysis
SQL Query Safety
Output Escaping
Just Writing Statistics Attack Surface
AJAX Handlers 1
Shortcodes 4
WordPress Hooks 11
Maintenance & Trust
Just Writing Statistics Maintenance & Trust
Maintenance Signals
Community Trust
Just Writing Statistics Alternatives
Word Counter
wordcounter
Show the reading time and number of words in your post.
SJ Reading Time
sj-reading-time
SJ Reading Time helps you to quickly estimate your content read time and insert using a shortcode.
Reading Time WP
reading-time-wp
Reading Time WP creates an estimated reading time of your posts that is inserted above the content or by using a shortcode.
Surfer – WordPress Plugin
surferseo
Connect Surfer's Content Editor to WordPress. Write and optimize your articles for SEO, find new keyword ideas and publish straight to WordPress.
Novelist
novelist
Easily organize and display your portfolio of books.
Just Writing Statistics Developer Profile
35 plugins · 8K total installs
How We Detect Just Writing Statistics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.