
Plugin Stats View Security & Risk Analysis
wordpress.org/plugins/plugin-stats-viewThe stats of plugin is displayed by block or shortcode.
Is Plugin Stats View Safe to Use in 2026?
Generally Safe
Score 100/100Plugin Stats View has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "plugin-stats-view" v3.14 presents a generally positive security posture based on the provided static analysis and vulnerability history. The absence of known vulnerabilities (CVEs) and the thorough nature of the code analysis, which identified no critical or high severity taint flows, are significant strengths. Furthermore, the plugin exhibits good practices by having no external HTTP requests, no file operations, and no shortcodes or cron events to exploit. This indicates a well-contained and potentially robust plugin.
However, there are notable areas of concern. The most significant is the single SQL query, which is not utilizing prepared statements. This presents a direct risk of SQL injection, a common and severe vulnerability. Additionally, the complete lack of nonce checks and capability checks is a substantial security weakness. While the attack surface for AJAX and REST API routes is reported as zero, this might be a misleading statistic if these entry points are not properly secured or if the analysis missed them. The low percentage of properly escaped output also raises a flag, potentially indicating a risk of Cross-Site Scripting (XSS) vulnerabilities, especially if sensitive data is being displayed.
In conclusion, while the plugin benefits from a clean vulnerability history and limited attack surface, the identified risks related to raw SQL queries and the complete absence of nonces and capability checks are serious and require immediate attention. The low output escaping rate also needs further investigation. It is recommended to address these specific issues to enhance the overall security of the plugin.
Key Concerns
- SQL query not using prepared statements
- No nonce checks implemented
- No capability checks implemented
- Low output escaping rate (18% unescaped)
Plugin Stats View Security Vulnerabilities
Plugin Stats View Release Timeline
Plugin Stats View Code Analysis
SQL Query Safety
Output Escaping
Plugin Stats View Attack Surface
Maintenance & Trust
Plugin Stats View Maintenance & Trust
Maintenance Signals
Community Trust
Plugin Stats View Alternatives
Counters Block – Animated Number Counters for Stats and Goals
counters-block
A great way to display numbers in a fun and interesting way.
Counter Block
counter-block
Show off numbers or stats on your website using animated Counter block for Gutenberg.
Manage Customized Plugin Updates
manage-customized-plugin-updates
Are you a web developer or website design company who has installed / customized plugins for your clients and you're having a hard time managing …
Restrict Country Access
restrict-country-access
Sometimes we need to block access of WordPress site in some Country.
AWStats Xtended Info
awstats-xtended-info
AWStats Xtended Info inserts the awstats_misc_tracker.js into each page WordPress serves, allowing you to track additional items including screen size …
Plugin Stats View Developer Profile
54 plugins · 56K total installs
How We Detect Plugin Stats View
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/plugin-stats-view/js/psv-editor.js/wp-content/plugins/plugin-stats-view/css/psv-editor.css/wp-content/plugins/plugin-stats-view/js/psv-stats.js/wp-content/plugins/plugin-stats-view/css/psv-stats.css/wp-content/plugins/plugin-stats-view/js/psv-admin.js/wp-content/plugins/plugin-stats-view/css/psv-admin.css/wp-content/plugins/plugin-stats-view/js/psv-editor.js/wp-content/plugins/plugin-stats-view/js/psv-stats.js/wp-content/plugins/plugin-stats-view/js/psv-admin.jsplugin-stats-view/js/psv-editor.js?ver=plugin-stats-view/css/psv-editor.css?ver=plugin-stats-view/js/psv-stats.js?ver=plugin-stats-view/css/psv-stats.css?ver=plugin-stats-view/js/psv-admin.js?ver=plugin-stats-view/css/psv-admin.css?ver=HTML / DOM Fingerprints
psv-settings-wrappsv-stats-wrappsv-admin-wrappsv-editor-wrapdata-psv-plugin-namedata-psv-versiondata-psv-stats-idpsv_settings_objectpsv_plugin_stats/wp-json/plugin-stats-view/v1/settings[plugin_stats_view][psv_stats]