
mzz-stat Security & Risk Analysis
wordpress.org/plugins/mzz-statShows the WP site administrator how many visits per page per day to their WP site.
Is mzz-stat Safe to Use in 2026?
Generally Safe
Score 85/100mzz-stat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mzz-stat" plugin, version v20170304.1423, presents a mixed security posture. While the attack surface appears to be zero and there are no recorded CVEs or vulnerabilities, the static analysis reveals significant concerns within the codebase itself. The complete absence of prepared statements for all SQL queries and the lack of any output escaping are critical weaknesses that could lead to severe security issues like SQL injection and cross-site scripting (XSS) if the plugin were to interact with user-supplied data, even without obvious entry points exposed in the static analysis. The taint analysis also highlights two flows with unsanitized paths, indicating potential vulnerabilities that were not immediately apparent from the attack surface metrics.
Despite the clean vulnerability history, the internal code quality suggests a high potential for latent vulnerabilities. The lack of proper SQL sanitization and output escaping are fundamental security practices that are entirely missing. Therefore, while the plugin may appear secure on the surface due to a small attack surface and no historical CVEs, the underlying code is inherently risky and susceptible to exploitation if any data handling occurs. It is strongly recommended that this plugin undergo thorough code review and remediation for the identified SQL and output escaping issues before it is considered secure for production use.
Key Concerns
- SQL queries without prepared statements
- Output escaping is not implemented
- Taint flows with unsanitized paths
- No nonce checks
- No capability checks
mzz-stat Security Vulnerabilities
mzz-stat Release Timeline
mzz-stat Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
mzz-stat Attack Surface
WordPress Hooks 2
Maintenance & Trust
mzz-stat Maintenance & Trust
Maintenance Signals
Community Trust
mzz-stat Alternatives
WPS Visitor Counter
wps-visitor-counter
Display website visitor statistics with widget, shortcode, and Gutenberg block support.
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)
burst-statistics
Analytics you'll actually use. Privacy-friendly, zero config, and designed to be actionable. Get insights, not just raw data.
Statify
statify
Visitor statistics for WordPress with focus on data protection, transparency and clarity. Perfect as a widget in your WordPress Dashboard.
StatCounter – Free Real Time Visitor Stats
official-statcounter-plugin-for-wordpress
StatCounter.com powered real-time detailed stats about the visitors to your blog.
Koko Analytics – Privacy Friendly Statistics for WordPress
koko-analytics
Koko Analytics is a privacy-friendly statistics plugin for WordPress that is an easy to use alternative to Google Analytics.
mzz-stat Developer Profile
1 plugin · 100 total installs
How We Detect mzz-stat
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<!-- Utf-8 test -- two Utf-8 Chinese characters should appear at the beginning of this line. -->