
MarketPress Statistics Security & Risk Analysis
wordpress.org/plugins/marketpress-statisticsDisplay MarketPress statistics using google charts.
Is MarketPress Statistics Safe to Use in 2026?
Generally Safe
Score 85/100MarketPress Statistics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "marketpress-statistics" plugin, at version 0.4.2, exhibits a generally positive security posture based on the static analysis. The absence of any recorded vulnerabilities (CVEs) and the minimal attack surface (zero AJAX handlers, REST API routes, shortcodes, and cron events without checks) are significant strengths. The presence of capability checks, even if only one, indicates some level of access control implementation. However, the analysis reveals critical areas for concern regarding data sanitization and secure coding practices. Specifically, the complete lack of prepared statements for all five SQL queries is a major risk, as it leaves the plugin highly susceptible to SQL injection attacks. Furthermore, the extremely low percentage (2%) of properly escaped output suggests that many data outputs are vulnerable to cross-site scripting (XSS) attacks. The absence of taint analysis results is unusual and might indicate that the analysis tool couldn't effectively trace data flows, which itself could be a hidden risk if critical data isn't being monitored. While the plugin appears to have no history of known vulnerabilities, the significant coding weaknesses in SQL and output handling present a substantial risk that could easily lead to future security incidents if not addressed.
Key Concerns
- Raw SQL queries without prepared statements
- Poor output escaping
- No taint flow analysis conducted
MarketPress Statistics Security Vulnerabilities
MarketPress Statistics Code Analysis
SQL Query Safety
Output Escaping
MarketPress Statistics Attack Surface
WordPress Hooks 1
Maintenance & Trust
MarketPress Statistics Maintenance & Trust
Maintenance Signals
Community Trust
MarketPress Statistics Alternatives
Enhanced Ecommerce Google Analytics for WooCommerce
woo-ecommerce-tracking-for-google-and-facebook
Track sales analytics, conversions and understand consumer behavior using google analytics (with ecommerce tracking).
WPMU MarketPress Allow Comments
wpmu-marketpress-allow-comments-addon
A simple addon that will allow comments to be added to product listing, to the MarketPress Ecommerce Plugin.
GA Google Analytics – Connect Google Analytics to WordPress
ga-google-analytics
Adds Google Analytics tracking code to your WordPress site. Supports many tracking features.
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)
burst-statistics
Analytics you'll actually use. Privacy-friendly, zero config, and designed to be actionable. Get insights, not just raw data.
Post Views Counter
post-views-counter
Post Views Counter allows you to collect and display how many times a post, page, or other content has been viewed in a simple, fast and reliable way.
MarketPress Statistics Developer Profile
6 plugins · 6K total installs
How We Detect MarketPress Statistics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/marketpress-statistics/bigtext.js/wp-content/plugins/marketpress-statistics/bigtext.jsHTML / DOM Fingerprints
wrapgoogle