
MCB – Stats Security & Risk Analysis
wordpress.org/plugins/mcb-statsMCB Stats collects statistics of users who access to the front part of wordpress, MCB Stast is capable of collecting the total amount of time a user s …
Is MCB – Stats Safe to Use in 2026?
Generally Safe
Score 85/100MCB – Stats has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mcb-stats" v1.0.0 plugin exhibits a concerning security posture primarily due to its unprotected AJAX endpoints. With 7 AJAX handlers identified, all lacking proper authentication or authorization checks, this presents a significant attack surface. Furthermore, the taint analysis reveals 3 flows with unsanitized paths, including 2 of high severity, indicating potential for attackers to inject malicious data that could be executed or lead to unintended consequences within the plugin. The complete absence of nonce checks and capability checks exacerbates these risks, as there are no built-in mechanisms to verify user intent or permissions for these sensitive actions.
While the plugin has no recorded vulnerability history, which is a positive indicator of past code quality, it does not mitigate the immediate risks identified in the static and taint analysis. The use of SQL queries without prepared statements is another critical weakness, increasing the likelihood of SQL injection vulnerabilities. The bundled DataTables library, while not inherently a vulnerability, should be monitored for known issues in its specific version. Overall, the plugin's strengths lie in its lack of direct file operations and external HTTP requests, and a moderate rate of proper output escaping. However, the severe lack of input validation and authentication on its AJAX endpoints and the presence of high-severity taint flows are major security concerns that require immediate attention.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows
- Raw SQL without prepared statements
- Missing nonce checks
- Missing capability checks
- Flows with unsanitized paths
- Bundled outdated library (DataTables v1.10.13)
MCB – Stats Security Vulnerabilities
MCB – Stats Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
MCB – Stats Attack Surface
AJAX Handlers 7
WordPress Hooks 5
Maintenance & Trust
MCB – Stats Maintenance & Trust
Maintenance Signals
Community Trust
MCB – Stats Alternatives
MWR Hit Counter
mwr-hit-counter
MWR Hit Counter is a simple and lightweight text-based counter for your website.
Timeline Widget For Elementor (Elementor Timeline, Vertical & Horizontal Timeline)
timeline-widget-addon-for-elementor
Highlight your company’s history, milestones, and key events directly inside Elementor using stunning vertical and horizontal timelines.
When Last Login
when-last-login
Show a users last login date by creating a sortable column in your WordPress users list.
Date Time Picker for Contact Form 7
date-time-picker-for-contact-form-7
This plugin enables Contact Form 7 text field into a Date picker, Time picker or Date Time picker by using CSS class.
Timetable and Event Schedule by MotoPress
mp-timetable
Smart event organizer and time-management tool with a clean minimalist design for featuring your timetables and upcoming events.
MCB – Stats Developer Profile
1 plugin · 10 total installs
How We Detect MCB – Stats
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mcb-stats/js/mcb_stats.js/wp-content/plugins/mcb-stats/js/mcb_stats_count.js/wp-content/plugins/mcb-stats/js/mcb_stats.js/wp-content/plugins/mcb-stats/js/mcb_stats_count.jsHTML / DOM Fingerprints
window.location.originwindow.location.protocolwindow.location.hostnamewindow.location.portwindow.location.pathnamewindow.Worker+1 more/wp-admin/admin-ajax.php