
Popularity Stats for WordPress Security & Risk Analysis
wordpress.org/plugins/popularity-statsThe Popularity Stats plugin is a handy plugin for WordPress which quickly reports the popularity of a website.
Is Popularity Stats for WordPress Safe to Use in 2026?
Generally Safe
Score 85/100Popularity Stats for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'popularity-stats' plugin v2017.08.13 exhibits a mixed security posture. On the positive side, the static analysis reveals an extremely small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the absence of any recorded vulnerabilities (CVEs) in its history suggests a generally stable and well-maintained codebase in terms of known security flaws. However, significant concerns arise from the code signals. The plugin utilizes SQL queries without prepared statements, which is a major risk for SQL injection vulnerabilities. Additionally, none of the identified output points are properly escaped, leaving it highly susceptible to Cross-Site Scripting (XSS) attacks. The complete lack of nonce and capability checks also contributes to a weak security posture, potentially allowing unauthorized actions if any entry points were to exist or be introduced.
The vulnerability history, while seemingly good due to zero recorded CVEs, could also indicate a lack of thorough security auditing or that the plugin hasn't been targeted. The code signals, particularly the unescaped outputs and raw SQL queries, are strong indicators of potential vulnerabilities that might not have been publicly disclosed. In conclusion, while the plugin benefits from a negligible attack surface and a clean vulnerability history, the presence of critical code-level security weaknesses like unescaped output and raw SQL queries present substantial risks that overshadow the positive aspects. Further investigation and remediation of these code-level issues are strongly recommended.
Key Concerns
- SQL queries not using prepared statements
- Output not properly escaped
- No nonce checks found
- No capability checks found
- Bundled outdated library (jQuery v1.3.2)
Popularity Stats for WordPress Security Vulnerabilities
Popularity Stats for WordPress Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Popularity Stats for WordPress Attack Surface
WordPress Hooks 4
Maintenance & Trust
Popularity Stats for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Popularity Stats for WordPress Alternatives
Share on Mastodon
share-on-mastodon
Automatically share WordPress posts on Mastodon.
WP REST Yoast Meta
wp-rest-yoast-meta
Adds meta tags as generated by Yoast SEO to the WP REST API. And adds a custom endpoint to retrieve all redirects as they are set in Yoast SEO Premium …
Divi Title Module
mc-divi-title-module
This plugin adds a new module to the Divi builder, it allows to easily insert titles without going through the text module.
Share on Pixelfed
share-on-pixelfed
Automatically share WordPress (image) posts on Pixelfed.
Add Image to RSS Feed
add-image-to-rss-feed
** this plugin is no longer being update. Please feel free to adopt me! **
Popularity Stats for WordPress Developer Profile
17 plugins · 130 total installs
How We Detect Popularity Stats for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/popularity-stats/jqplot/jquery.jqplot.js/wp-content/plugins/popularity-stats/jqplot/excanvas.js/wp-content/plugins/popularity-stats/jqplot/plugins/ jqplot.dateAxisRenderer.js/wp-content/plugins/popularity-stats/jqplot/plugins/jqplot.cursor.js/wp-content/plugins/popularity-stats/jqplot/plugins/jqplot.highlighter.js/wp-content/plugins/popularity-stats/jqplot/jquery.jqplot.csshttps://ajax.googleapis.com/ajax/libs/jquery/1.6.4/jquery.min.jsHTML / DOM Fingerprints
plotname="horshipsrectors_popularity_track_pagerank"id="horshipsrectors_popularity_track_pagerank"name="horshipsrectors_popularity_track_alexa"id="horshipsrectors_popularity_track_alexa"name="horshipsrectors_popularity_track_links"id="horshipsrectors_popularity_track_links"+4 more$.jqplot