
PopStats Security & Risk Analysis
wordpress.org/plugins/popstatsPopstats is a plugin to enhace statics of your blog, now you'll know more about your visitors.
Is PopStats Safe to Use in 2026?
Generally Safe
Score 85/100PopStats has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "popstats" v3.0 plugin reveals significant security concerns despite a lack of recorded historical vulnerabilities or a large attack surface. The most alarming findings are the extensive use of raw SQL queries without prepared statements and the complete absence of output escaping. This combination presents a high risk of SQL injection and Cross-Site Scripting (XSS) vulnerabilities, respectively. While the plugin has a single nonce check, it lacks capability checks, meaning any user, regardless of their WordPress role, could potentially interact with its functionalities if entry points existed. The taint analysis further corroborates these risks, indicating two flows with unsanitized paths, classified as high severity, directly stemming from the unescaped outputs or raw SQL queries.
Key Concerns
- All SQL queries use raw statements
- No output escaping found
- High severity taint flows found
- No capability checks on entry points
PopStats Security Vulnerabilities
PopStats Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
PopStats Attack Surface
WordPress Hooks 4
Maintenance & Trust
PopStats Maintenance & Trust
Maintenance Signals
Community Trust
PopStats Alternatives
Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)
burst-statistics
Analytics you'll actually use. Privacy-friendly, zero config, and designed to be actionable. Get insights, not just raw data.
Statify
statify
Visitor statistics for WordPress with focus on data protection, transparency and clarity. Perfect as a widget in your WordPress Dashboard.
StatCounter – Free Real Time Visitor Stats
official-statcounter-plugin-for-wordpress
StatCounter.com powered real-time detailed stats about the visitors to your blog.
Koko Analytics – Privacy Friendly Statistics for WordPress
koko-analytics
Koko Analytics is a privacy-friendly statistics plugin for WordPress that is an easy to use alternative to Google Analytics.
Connect Matomo – Analytics Dashboard for WordPress
wp-piwik
Adds Matomo (former Piwik) statistics to your WordPress dashboard and is also able to add the Matomo Tracking Code to your blog.
PopStats Developer Profile
1 plugin · 30 total installs
How We Detect PopStats
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/popstats/popstats.css/wp-content/plugins/popstats/popstats.js/wp-content/plugins/popstats/popstats.jspopstats/popstats.js?ver=popstats/popstats.css?ver=HTML / DOM Fingerprints
<!-- PopStats v3.0 -->ps_ajax_refresh_time