
NewStatPress Security & Risk Analysis
wordpress.org/plugins/newstatpressNewStatPress (Statpress plugin fork) is a real-time plugin to manage the visits' statistics about your blog (without external web analytics).
Is NewStatPress Safe to Use in 2026?
Mostly Safe
Score 76/100NewStatPress is generally safe to use. 10 past CVEs were resolved. Keep it updated.
The security posture of the 'newstatpress' plugin v1.4.4 presents a mixed bag. On the positive side, the plugin demonstrates good practices by heavily utilizing prepared statements for its SQL queries (98%) and performing proper output escaping for a majority of its outputs (90%). It also incorporates a decent number of nonce and capability checks, indicating an awareness of common WordPress security mechanisms. However, significant concerns arise from the presence of four unprotected AJAX handlers, forming a substantial portion of its attack surface that is directly accessible to unauthenticated users. This is further amplified by a high severity taint flow indicating potential injection vulnerabilities that have not been adequately sanitized.
Key Concerns
- Unprotected AJAX handlers on attack surface
- High severity taint flow found
- 10 known CVEs, history of critical/high vulns
NewStatPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
10 total CVEs
NewStatPress <= 1.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
NewStatPress <= 1.3.5 - Reflected Cross-Site Scripting
NewStatPress < 1.2.5 - Unauthenticated Stored Cross-Site Scripting
NewStatPress < 1.0.6 - SQL Injection
NewStatPress < 1.0.6 - Reflected Cross-Site Scripting
NewStatPress <= 1.0.3 - Stored Cross-Site Scripting
NewStatPress <= 1.0.6 - Reflected Cross-Site Scripting
NewStatPress <= 1.0.0 - SQL Injection
NewStatPress <= 0.9.8 - Authenticated SQL Injection
NewStatPress <= 0.9.8 - Authenticated Cross-Site Scripting
NewStatPress Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
NewStatPress Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 17
Scheduled Events 4
Maintenance & Trust
NewStatPress Maintenance & Trust
Maintenance Signals
Community Trust
NewStatPress Alternatives
Kin Visitantes
kin-visitantes
Track visitors to your website easily and effectively.
GA Google Analytics – Connect Google Analytics to WordPress
ga-google-analytics
Adds Google Analytics tracking code to your WordPress site. Supports many tracking features.
Independent Analytics – Google Analytics Alternative for WordPress
independent-analytics
A simple WordPress analytics plugin that is privacy-friendly, fast, and an alternative to Google Analytics.
SlimStat Analytics
wp-slimstat
The leading web analytics plugin for WordPress
Connect Matomo – Analytics Dashboard for WordPress
wp-piwik
Adds Matomo (former Piwik) statistics to your WordPress dashboard and is also able to add the Matomo Tracking Code to your blog.
NewStatPress Developer Profile
1 plugin · 9K total installs
How We Detect NewStatPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/newstatpress/css/newstatpress-admin.css/wp-content/plugins/newstatpress/css/newstatpress-frontend.css/wp-content/plugins/newstatpress/js/newstatpress-admin.js/wp-content/plugins/newstatpress/js/newstatpress-frontend.js/wp-content/plugins/newstatpress/js/newstatpress-admin.js/wp-content/plugins/newstatpress/js/newstatpress-frontend.jsnewstatpress/css/newstatpress-admin.css?ver=newstatpress/css/newstatpress-frontend.css?ver=newstatpress/js/newstatpress-admin.js?ver=newstatpress/js/newstatpress-frontend.js?ver=HTML / DOM Fingerprints
newstatpressnsp_wrappernsp_contentnsp_sectiontitlensp_datansp_data_rownsp_data_labelnsp_data_value+40 more<!-- NEWSTATPRESS by stefanotognon --><!-- /NEWSTATPRESS --><!-- BEGIN NEWSTATPRESS WIDGET --><!-- END NEWSTATPRESS WIDGET -->+5 moredata-nsp-graph-labelsdata-nsp-graph-datadata-nsp-chart-typedata-nsp-chart-colorsdata-nsp-chart-legendnewstatpress_datansp_admin_varsnsp_frontend_vars/wp-json/newstatpress/v1/stats[newstatpress_overview][newstatpress_top_days][newstatpress_os][newstatpress_browser]