Multisite Plugin Stats Security & Risk Analysis

wordpress.org/plugins/multisite-plugin-stats

A multisite plugin to show plugin activations across all your sites.

40 active installs v1.1 PHP + WP 3.1+ Updated Jun 22, 2012
multisiteplugins
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Multisite Plugin Stats Safe to Use in 2026?

Generally Safe

Score 85/100

Multisite Plugin Stats has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "multisite-plugin-stats" v1.1 plugin exhibits a seemingly strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits the potential attack surface. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests is a positive sign. However, the analysis reveals critical weaknesses in how data is handled. The fact that 100% of SQL queries are not using prepared statements, combined with 100% of outputs not being properly escaped, presents a high risk of SQL injection and Cross-Site Scripting (XSS) vulnerabilities. Despite the clean vulnerability history, these code-level issues are substantial concerns that could be exploited if any of the entry points (even if currently zero) were to be introduced or become accessible.

While the plugin's limited attack surface and lack of known vulnerabilities are strengths, the complete disregard for prepared statements in SQL and proper output escaping are significant vulnerabilities. These fundamental security practices are missing, creating a substantial risk of data compromise and arbitrary code execution if any data processed by the plugin is ever user-supplied or exposed to the public web. The plugin's current state is precarious; it may be secure by obscurity due to its lack of exposed functionality, but the underlying code is insecure.

Key Concerns

  • SQL queries do not use prepared statements
  • Output not properly escaped
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Multisite Plugin Stats Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Multisite Plugin Stats Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
10
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

0% escaped10 total outputs
Attack Surface

Multisite Plugin Stats Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionnetwork_admin_menumultisite-plugin-stats.php:32
actionadmin_headmultisite-plugin-stats.php:33
actionadmin_enqueue_scriptsmultisite-plugin-stats.php:34
actionplugins_loadedmultisite-plugin-stats.php:35
Maintenance & Trust

Multisite Plugin Stats Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedJun 22, 2012
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings2
Active installs40
Developer Profile

Multisite Plugin Stats Developer Profile

ljg3

1 plugin · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Multisite Plugin Stats

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/multisite-plugin-stats/js/admin.js
Script Paths
/wp-content/plugins/multisite-plugin-stats/js/admin.js

HTML / DOM Fingerprints

CSS Classes
plugin_listplugin_countplugin_site_list
Data Attributes
id="plugin_count_"id="site_list_"
FAQ

Frequently Asked Questions about Multisite Plugin Stats